Rackspace say there is a zero day in ScienceLogic EM7, which has been exploited inside Rackspace.
https://x.com/ynezzor/status/1839931641172467907
Rackspace outage report from 24th September 2024 (doesn't mention a security incident): https://rackspace.service-now.com/system_status?id=detailed_status&service=4dafca5a87f41610568b206f8bbb35a6
ScienceLogic haven't got anything on their support site about a new vulnerability.
The Register has picked up this story.
Sciencelogic say the vulnerability is in a third party software library and no CVE has been issued, and they’re declining to name the library.
One to watch. Smells of dead bodies in cupboards. https://www.theregister.com/2024/09/30/rackspace_zero_day_attack/
@GossiTheDog why do i have the feeling it is either python or javascript?