Investigations into SolarWinds-related compromises have highlighted two distinct but high-impact intrusion paths: the SUNBURST supply-chain compromise affecting SolarWinds Orion customers and a later path traversal flaw in SolarWinds Serv-U tracked as CVE-2024-28995. Fidelis reported on incident response and forensic analysis tied to the Orion compromise, where attackers leveraged trojanized software updates to gain footholds in victim environments, while Censys documented internet-exposed Serv-U systems affected by the traversal vulnerability and the resulting urgency around patching and exposure reduction.
Threat reporting has also linked SolarWinds activity to broader nation-state tradecraft. Dragos has tracked ALLANITE, an activity group associated with espionage against critical infrastructure, in the wider context of campaigns involving trusted third-party relationships and stealthy post-compromise operations. Together, the reporting shows SolarWinds remaining a recurring focal point for defenders, both as a victim of supply-chain abuse and as a vendor whose products have presented exploitable attack surface requiring rapid mitigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
SolarWinds published an advisory for a path traversal vulnerability in Serv-U, tracked as CVE-2024-28995. The advisory date is explicitly referenced as July 17, 2024.
Fidelis Security published analysis of the SolarWinds attack, describing the ongoing investigation, impact, and response to the Orion supply-chain compromise. This reflects the public disclosure and active incident-response phase surrounding the campaign.
Dragos published a profile on ALLANITE, documenting the threat actor and its activity. The reference indicates public attribution and technical characterization of the group.
3 references tracked. Mallory keeps watching after this page renders.
dragos.com
Open sourcecensys.com
Open sourcefidelissecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.