Supply chain β›“ Supply Chain

Rackspace Third-Party Breach (October 2024)

πŸ“… 2024-10-01 🏒 ScienceLogic
Primary Source β†—

Incident Details

Rackspace monitoring data stolen in ScienceLogic zero-day attack. Cloud hosting provider Rackspace suffered a data breach exposing “limited” customer monitoring data after threat actors exploited a zero-day vulnerability in a third-party tool used by the ScienceLogic SL1 platform. ScienceLogic confirmed to BleepingComputer that they quickly developed a patch to address the risk and distributed it to all impacted customers while still providing assistance where needed. “We identified a zero-day remote code execution vulnerability within a non-ScienceLogic third-party utility that is delivered with the SL1 package,” explained a statement from Jessica Lindberg, Vice President at ScienceLogic. Third-party company: ScienceLogic.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
ScienceLogic
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-10-01 Breach occurred
  2. 2024-10-01 Publicly disclosed