Rackspace-Überwachungsdaten bei ScienceLogic-Zero-Day-Angriff gestohlen

Teilen:

Cloud hosting provider Rackspace suffered a data breach exposing “limited” customer monitoring data after threat actors exploited a zero-day vulnerability in a third-party tool used by the ScienceLogic SL1 platform.

ScienceLogic confirmed to BleepingComputer that they quickly developed a patch to address the risk and distributed it to all impacted customers while still providing assistance where needed.

“We identified a zero-day remote code execution vulnerability within a non-ScienceLogic third-party utility that is delivered with the SL1 package,” explained a statement from Jessica Lindberg, Vice President at ScienceLogic.

Upon identification, we rapidly developed a patch to remediate the incident and have made it available to all customers globally.”

ScienceLogic declined to name the third-party utility to avoid providing hints to other hackers, as it might be used on several other products.

The attack was first disclosed by a user on X who warned that a Rackspace outage from September 24 was due to active exploitation in the hosting provider’s ScienceLogic EM7.

“Oopsie, a zero-day remote code execution vulnerability was exploited … third-party ScienceLogic application used by Rackspace,” an account named ynezz shared on X.

“We have confirmed that the exploit of this third-party application resulted in access to three internal Rackspace monitoring webservers.”

ScienceLogic SL1 (formerly EM7) is an IT operations platform for monitoring, analyzing, and automating an organization’s infrastructure, including cloud, networks, and applications.

It provides real-time visibility, event correlation, and automated workflows to help manage and optimize IT environments efficiently.

Rackspace, a managed cloud computing (hosting, storage, IT support) company, uses ScienceLogic SL1 to monitor its IT infrastructure and services.

In response to the discovery of the malicious activity, Rackspace disabled monitoring graphs on its MyRack portal until they could push an update to remediate the risk.

However, the situation was worse than what a short Rackspace service status update reflected.

As first reported by The Register, Rackspace’s SL1 solution was hacked via the zero-day and some customer information was stolen.

In an email sent to customers and seen by The Register, Rackspace warned that the hackers exploited the zero-day to gain access to web servers and steal limited customer monitoring data, including customer account names and numbers, customer usernames, Rackspace internally generated device IDs, device name and information, IP addresses, and AES256 encrypted Rackspace internal device agent credentials.

Rackspace rotated those credentials as a precaution, despite them being strongly encrypted, and informed customers they needed to take no further action to protect from the malicious activity, which had been stopped.

While the data is limited, it is common for companies to hide their devices’ IP addresses behind content delivery systems and DDoS mitigation platforms. Threat actors could use the exposed IP addresses to target company’s devices in DDoS attacks or further exploitation attempts.

It is unknown how many customers have been impacted by this breach.

Update 10/2 – A RackSpace spokesperson has sent BleepingComputer the following information:

On September 24th, 2024, Rackspace discovered a zero-day remote code execution vulnerability in a non-Rackspace utility that is packaged and delivered by the third-party ScienceLogic application (known as SL1).  This was not a Rackspace vulnerability. Rackspace utilizes the ScienceLogic application internally to provide system monitoring of some (but not all) Rackspace services.

The system improperly accessed, as a result of exploitation of the SL1 vulnerability, is a Rackspace system used for generating internal performance reporting and is internal to Rackspace. Our forensic investigation identified no access to customer configurations, or their hosted data.

Rackspace immediately notified ScienceLogic of their vulnerability. Rackspace worked with ScienceLogic to ensure development of a patch to remediate their vulnerability, and ScienceLogic has now made it available to all of their customers globally.

Limited performance monitoring information of low-security sensitivity was improperly accessed. Out of an abundance of caution, all impacted customers have been notified. No remediation steps are required from customers.

Rackspace’s monitoring functionality is not dependent on the ScienceLogic dashboard, and our Rackspace customer performance monitoring was not impacted by this event.  There was no interruption to our monitoring and alerting services for our customers.

The only service impact to customers was the inability to access their associated ScienceLogic monitoring dashboard, which is an optional service feature infrequently utilized by some customers. – Rackspace spokesperson

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
5:49 am, Jan. 31, 2025
Wetter-Symbol 5°C
L: 4° | H: 5°
light rain
Luftfeuchtigkeit: 91 %
Druck: 1023 mb
Wind: 7 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0.87 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:40 am
Sonnenuntergang: 4:47 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
4° | 5°°C 1 mm 100% 8 mph 98 % 1028 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
5° | 7°°C 0 mm 0% 8 mph 94 % 1029 mb 0 mm/h
So. Feb. 02 9:00 pm
Wetter-Symbol
2° | 8°°C 0 mm 0% 6 mph 78 % 1026 mb 0 mm/h
Mo. Feb. 03 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 8 mph 86 % 1027 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
6° | 10°°C 0 mm 0% 12 mph 94 % 1028 mb 0 mm/h
Today 6:00 am
Wetter-Symbol
5° | 5°°C 1 mm 100% 8 mph 91 % 1023 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
5° | 5°°C 1 mm 100% 6 mph 91 % 1023 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
5° | 6°°C 0.8 mm 80% 2 mph 90 % 1023 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
7° | 7°°C 0 mm 0% 4 mph 86 % 1024 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 3 mph 93 % 1026 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 98 % 1028 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 5 mph 94 % 1028 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 94 % 1029 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,461.79
-0.76%
Ethereum(ETH)
€3,117.70
1.81%
XRP(XRP)
€2.96
-0.76%
Fesseln(USDT)
€0.96
0.00%
Solana(SOL)
€228.08
-1.14%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.315195
-1.20%
Shiba Inu(SHIB)
€0.000018
0.24%
Pepe(PEPE)
€0.000013
1.09%
Nach oben scrollen