#Solarwinds
Like during his first term we had SolarWinds.
September 24, 2026 at 1:41 AM
I've been The Solarwinds Dude at %dayjob% for 13 years so yeah, same...
September 24, 2026 at 5:13 AM
I remember the SolarWinds hack quite well as had dealt with the fallout when working as a federal contractor.
September 24, 2026 at 4:28 AM
The SEC just let SolarWinds off the hook for allegedly hiding vulnerabilities that were exploited in a major 2020 hack: www.reuters.com/legal/govern...

Read @kimzetter.bsky.social's deep dive for @wired.com on the SolarWinds breach here: www.wired.com/story/the-un...
The Untold Story of the Boldest Supply-Chain Hack Ever
The attackers were in thousands of corporate and government networks. They might still be there now. Behind the scenes of the SolarWinds investigation.
www.wired.com
November 20, 2025 at 10:30 PM
NEW FOIA Files newsletter is out!

There's been a ton of news the past week so I'm offering up a palette cleanser. I finally got my hands on the once-secret internal reports from the Treasury Dept’s IG about its investigation into the SolarWinds hack in 2020
www.bloomberg.com/news/newslet...
Once-Secret Treasury Memos Detail Agency Response to SolarWinds Hack
The Treasury Department’s inspector general released dozens of pages of internal investigative memos to FOIA Files about its probe into the SolarWinds hack in December 2020, which compromised the emai...
www.bloomberg.com
January 31, 2025 at 3:33 PM
omg TIL i'm getting rid of node-gyp asap
github.com/solarwinds/zig…
GitHub - solarwinds/zig-build: Node.js native addon build and cross-compile library using Zig
Node.js native addon build and cross-compile library using Zig - solarwinds/zig-build
github.com
March 10, 2026 at 12:22 AM
Solarwinds are trying to patch a critical vulnerability that was introduced by a patch that had a critical vulnerability that patched another critical vulnerability that came from a patch that had a critical vulnerability meant to patch q critical vulnerability.

www.securityweek.com/solarwinds-m...
SolarWinds Makes Third Attempt at Patching Exploited Vulnerability
SolarWinds announced a hotfix for RCE vulnerability in Web Help Desk, and this is the third time it attempts to address the issue.
www.securityweek.com
September 24, 2025 at 6:09 AM
Plus: The SEC lets SolarWinds off the hook, Microsoft stops a historic DDoS attack, and FBI documents reveal the agency spied on an immigration activist Signal group in New York City. www.wired.com/story/securi...
US Border Patrol Is Spying on Millions of American Drivers
Plus: The SEC lets SolarWinds off the hook, Microsoft stops a historic DDoS attack, and FBI documents reveal the agency spied on an immigration activist Signal group in New York City.
www.wired.com
November 22, 2025 at 11:35 AM
Know I understand why Solarwinds don’t have a Bug Bounty program.
Solarwinds are trying to patch a critical vulnerability that was introduced by a patch that had a critical vulnerability that patched another critical vulnerability that came from a patch that had a critical vulnerability meant to patch q critical vulnerability.

www.securityweek.com/solarwinds-m...
SolarWinds Makes Third Attempt at Patching Exploited Vulnerability
SolarWinds announced a hotfix for RCE vulnerability in Web Help Desk, and this is the third time it attempts to address the issue.
www.securityweek.com
September 24, 2025 at 6:40 AM
“volume of security issues being identified over the last month have [sic] outstripped the capacity of Engineering teams to resolve.”

Most orgs are like this.

Didn’t expect to see CISO liability before software liability, but here we are.

#solarwinds

therecord.media/solarwinds-c...
SEC charges SolarWinds CISO with fraud for misleading investors before major cyberattack
The Securities and Exchange Commission (SEC) announced on Monday evening that it plans to charge SolarWinds Chief Information Security Officer Timothy Brown with fraud for his role in allegedly lying ...
therecord.media
October 31, 2023 at 2:39 AM
Big news on the corporate accountability (or lack thereof) front: The SEC just dropped its case against SolarWinds and its former CISO for allegedly defrauding investors about the company's cybersecurity posture prior to its major hack. www.sec.gov/enforcement-...
SEC.gov | SolarWinds Corp. and Timothy G. Brown
www.sec.gov
November 20, 2025 at 10:23 PM
Die Monitoring-Lösung für IT-Infrastrukturen SolarWinds Observability Self-Hosted ist unter bestimmten Voraussetzungen verwundbar. #Security
Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted
Die Monitoring-Lösung für IT-Infrastrukturen SolarWinds Observability Self-Hosted ist unter bestimmten Voraussetzungen verwundbar.
www.heise.de
September 24, 2026 at 8:26 AM
SolarWinds – yes, that SolarWinds – left hardcoded credentials in its Web Help Desk product that can be used by remote, unauthenticated attackers to log into vulnerable instances, access internal functionality, and modify sensitive data

Hotfix to install... www.theregister.com/2024/08/22/h...
SolarWinds left hardcoded credentials in helpdesk product
Why go to the effort of backdooring code when devs will basically do it for you accidentally anyway
www.theregister.com
August 23, 2024 at 12:08 AM
January 30, 2025 at 1:03 PM
Shortly after the 2020 Solarwinds breach I was taken on a tour to check out a certain company's network infrastructure and the breach got brought up and the company rep said to us, with his whole chest, "Oh, yeah, our solarwinds deployment was so out of date that we weren't impacted"
the password to the louvre surveillance server was "louvre"

www.thesocialpost.it/2025/11/02/f...
November 3, 2025 at 8:48 PM
perhaps, but i think of stuff like solarwinds.

let's get in the w-w-wayback machine. remember solarwinds123?

edition.cnn.com/2021/02/26/p...

can't blame the intern for doing it again with CVE-2026-28326
Former SolarWinds CEO blames intern for ‘solarwinds123’ password leak | CNN Politics
Current and former top executives at SolarWinds are blaming a company intern for a critical lapse in password security that apparently went undiagnosed for years.
edition.cnn.com
September 26, 2026 at 7:18 AM
The President Ordered a Board to Probe a Massive Russian Cyberattack. It Never Did.

By not investigating the underlying weakness in Microsoft software that was key to the SolarWinds hack, the Cyber Safety Review Board missed an opportunity to prevent future attacks, experts say.
The President Ordered a Board to Probe a Massive Russian Cyberattack. It Never Did.
By not investigating the underlying weakness in Microsoft software that was key to the SolarWinds hack, the Cyber Safety Review Board missed an opportunity to prevent future attacks, experts say.
www.propublica.org
July 8, 2024 at 12:31 PM
Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look 'insignificant'
Abandoned AWS S3 buckets can be reused in supply-chain attacks that would make SolarWinds look 'insignificant'
When cloud customers don't clean up after themselves, part 97 Abandoned AWS S3 buckets could be reused to hijack the global software supply chain in an attack that would make Russia's "SolarWinds adventures look amateurish and insignificant,"…
dlvr.it
February 4, 2025 at 11:06 AM
Enjoying the sun in Marrakech for the #SolarWindsEMEAPartnerSummit! #SolarWinds #Database
February 11, 2025 at 4:35 PM
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
Master Key Included: Detecting SolarWinds ARM CVE-2026-28326
bishopfox.com
September 26, 2026 at 7:39 PM
Nearly four and a half years after the SolarWinds breach, the core policy change by the Biden administration to prevent a future breach from happening has not been implemented. Nick Leiserson discusses what may be causing this failure to change acquisition regulations.
F5, SolarWinds, and the Lethargy of the FAR Council
Stopping procurement regulation vaporware is key for the U.S. government to see meaningful gains from security-by-demand.
www.lawfaremedia.org
December 4, 2025 at 4:04 PM
SEC fines four companies $7 million for ‘misleading cyber disclosures’ regarding SolarWinds hack
SEC fines four companies $7 million for ‘misleading cyber disclosures’ regarding SolarWinds hack
The SEC concluded that four tech companies misled investors and minimized the damage they suffered from the SolarWinds supply chain hack. © 2024 TechCrunch. All rights reserved. For personal use only.
tcrn.ch
October 22, 2024 at 4:52 PM