1. A Crash, Not a Shell: SolarWinds Serv-U CVE-2026-28318 vulnerability | High | Actively exploited | 2026-06-16 00:00 | CVE-2026-28318 | bishopfox.com | original ↗ | #active-exploitation | #rce | #vulnerability-research
2. Trick or treat: 5 spooky phishing stories blog | 2025-10-30 12:00 | bugcrowd.com | original ↗ | #supply-chain | #phishing | #bugcrowd
3. Partial SolarWinds reprieve, CrowdStrike lessons, LLM kryptonite – OffSec roundup for CISOs blog | 2024-10-16 15:00 | yeswehack.com | original ↗ | #ai-security | #bug-bounty | #supply-chain
4. Takeaways from the Dismissal of Most of the Government’s Case Against the SolarWinds CISO blog | 2024-08-15 21:50 | hackerone.com | original ↗ | #regulation | #solarwinds | #legal
5. US SEC cyber rules, SolarWinds CISO charges: How a unified OffSec strategy can enhance your SEC disclosures blog | 2024-02-08 09:14 | yeswehack.com | original ↗ | #compliance | #offsec | #regulation
6. Fortifying Assets for SEC Compliance with HackerOne blog | 2023-11-16 17:08 | hackerone.com | original ↗ | #bug-bounty | #vulnerability-management | #compliance
7. EMA Report: Unknown Vulnerabilities Emerge as Top Active Directory Security Concern blog | 2022-01-26 00:25 | semperis.com | original ↗ | #vulnerability-management | #active-directory | #solarwinds
8. Creating an Exploit: SolarWinds Vulnerability CVE-2021-35211 vulnerability | 2022-01-13 00:00 | CVE-2021-35211 | bishopfox.com | original ↗ | #vulnerability | #solarwinds | #rop
9. Securing the Supply Chain by Working With Ethical Hackers blog | 2021-11-30 17:50 | hackerone.com | original ↗ | #bug-bounty | #supply-chain | #open-source
10. Now’s the Time to Rethink Active Directory Security blog | 2021-08-04 16:13 | semperis.com | original ↗ | #active-directory | #identity-security | #security-strategy
11. Time to Leave ADFS Behind for Authenticating in Hybrid Environments? blog | 2021-07-08 19:28 | semperis.com | original ↗ | #cloud | #active-directory | #authentication
12. New Insights on Supply Chain and Ransomware Attacks From Our Chat With Alex Stamos and Charles Carmakal incident | 2021-06-10 00:00 | bishopfox.com | original ↗ | #supply-chain | #incident-response | #threat-intelligence
13. MICROSOFT SAYS: RUSSIAN SOLARWINDS HACKERS HIT U.S. GOVERNMENT AGENCIES AGAIN blog | 2021-06-02 15:44 | hackerone.com | original ↗ | #supply-chain | #phishing | #apt
14. Identity Attack Watch: May 2021 blog | 2021-05-28 15:53 | semperis.com | original ↗ | #active-directory | #solarwinds | #news-roundup
15. Identity Attack Watch: March 2021 blog | 2021-03-26 18:58 | semperis.com | original ↗ | #active-directory | #ransomware | #solarwinds
16. The Rise of Misconfiguration and Supply Chain Vulnerabilities vulnerability | 2021-02-26 04:51 | hackerone.com | original ↗ | #supply-chain | #cloud-security | #solarwinds
17. Semperis Identity Attack Watch: February 2021 blog | 2021-02-26 18:28 | semperis.com | original ↗ | #active-directory | #ransomware | #solarwinds
18. Semperis Expert: SolarWinds Attack Highlights Need to Secure AD incident | 2021-02-02 16:02 | semperis.com | original ↗ | #cloud | #supply-chain | #active-directory
19. 5 Learnings From A Conversation With OP Financial Group's CISO And @mrtuxracer blog | 2021-01-27 18:59 | hackerone.com | original ↗ | #phishing | #webinar | #ciso
20. What We Know (And Don’t) About The SolarWinds Orion Hack So Far blog | 2020-12-15 00:00 | bishopfox.com | original ↗ | #supply-chain | #nation-state | #solarwinds
21. NotPetya Flashback: The Latest Supply-Chain Attack Puts Active Directory at Risk of Compromise blog | 2020-12-15 14:33 | semperis.com | original ↗ | #supply-chain | #active-directory | #solarwinds
22. SolarWinds Serv-U Managed File Transfer – Insufficient Session ID Entropy advisory | 2018-05-14 00:00 | CVE-2018-10240 | bishopfox.com | original ↗ | #brute-force | #solarwinds | #session-hijacking
23. SolarWinds Serv-U Managed File Transfer – Denial of Service advisory | 2018-05-11 00:00 | CVE-2018-10241 | bishopfox.com | original ↗ | #denial-of-service | #solarwinds | #serv-u
24. SolarWinds Log & Event Manager - Improper Access Control vulnerability | 2017-05-12 00:00 | CVE-2017-7646 | bishopfox.com | original ↗ | #access-control | #advisory | #solarwinds
25. SolarWinds Log & Event Manager - Arbitrary Command Injection vulnerability | 2017-05-12 00:00 | CVE-2017-7647 | bishopfox.com | original ↗ | #advisory | #solarwinds | #command-injection