Microsoft says the attacks targeting SolarWinds Serv-U software with a now-patched RCE exploit are the work of Chinese hacking group DEV-0322
Microsoft said today that the recent wave of attacks that have targeted SolarWinds file transfer servers are the work of a Chinese hacking group …
Context & Ripple Effects
The Serv-U flaw was patched after Microsoft reported active exploitation of the remote-code-execution bug to SolarWinds. Microsoft now attributes that activity to DEV-0322, turning a vendor advisory into a named threat-actor assessment.
The finding also follows reporting that a separate actor with apparent China links targeted SolarWinds Orion flaws, underscoring that SolarWinds products had drawn more than one intrusion campaign rather than a single incident.
First-order effects
- SolarWinds Serv-U administrators have a patched vulnerability tied to a named alleged Chinese group, giving their incident-response teams a more specific basis for reviewing exposure and attack activity.
- Microsoft publicly attaches DEV-0322 to the Serv-U exploitation, extending its role from notifying SolarWinds about the flaw to assigning responsibility for its use.
Second-order effects
- Security teams and providers monitoring SolarWinds environments can distinguish the Serv-U campaign from the earlier Orion activity attributed to a different suspected China-linked actor, rather than treating all SolarWinds alerts as one operation.
- The episode puts greater weight on rapid vendor patching and customer deployment when Microsoft identifies exploitation before a fix is available.
Third-order effects
- The sequence points toward vulnerability disclosure, patching, and public attribution becoming a tighter operational loop for enterprise-software incidents, with Microsoft acting as both detector and attributing party.
- Repeated reporting on China-linked exploitation of SolarWinds products may push defenders to organize response around product-specific exposure and actor tracking rather than the SolarWinds brand alone.
The trend: Enterprise vulnerability response is increasingly shaped by rapid coordination between vendors and major security researchers, followed by public attribution of active exploitation.