/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says the attacks targeting SolarWinds Serv-U software with a now-patched RCE exploit are the work of Chinese hacking group DEV-0322

Microsoft said today that the recent wave of attacks that have targeted SolarWinds file transfer servers are the work of a Chinese hacking group …

The Record Catalin Cimpanu

Context & Ripple Effects

The Serv-U flaw was patched after Microsoft reported active exploitation of the remote-code-execution bug to SolarWinds. Microsoft now attributes that activity to DEV-0322, turning a vendor advisory into a named threat-actor assessment.

The finding also follows reporting that a separate actor with apparent China links targeted SolarWinds Orion flaws, underscoring that SolarWinds products had drawn more than one intrusion campaign rather than a single incident.

First-order effects

  • SolarWinds Serv-U administrators have a patched vulnerability tied to a named alleged Chinese group, giving their incident-response teams a more specific basis for reviewing exposure and attack activity.
  • Microsoft publicly attaches DEV-0322 to the Serv-U exploitation, extending its role from notifying SolarWinds about the flaw to assigning responsibility for its use.

Second-order effects

  • Security teams and providers monitoring SolarWinds environments can distinguish the Serv-U campaign from the earlier Orion activity attributed to a different suspected China-linked actor, rather than treating all SolarWinds alerts as one operation.
  • The episode puts greater weight on rapid vendor patching and customer deployment when Microsoft identifies exploitation before a fix is available.

Third-order effects

  • The sequence points toward vulnerability disclosure, patching, and public attribution becoming a tighter operational loop for enterprise-software incidents, with Microsoft acting as both detector and attributing party.
  • Repeated reporting on China-linked exploitation of SolarWinds products may push defenders to organize response around product-specific exposure and actor tracking rather than the SolarWinds brand alone.

The trend: Enterprise vulnerability response is increasingly shaped by rapid coordination between vendors and major security researchers, followed by public attribution of active exploitation.

Discussion

  • @tomwarren Tom Warren on x
    attackers are exploiting another SolarWinds 0-day. It was patched on Friday, but Microsoft says there are “limited and targeted attacks” happening https://twitter.com/...
  • @mrbcyber Michael Ron Bowling on x
    China continues its aggressive hacking of the US defense industrial base https://therecord.media/...
  • @campuscodi Catalin Cimpanu on x
    NEW: Microsoft links recent Serv-U zero-day attacks to Chinese hacking group DEV-0322 Unclear who DEV-0322 had compromised now, but Microsoft said the group previously targeted the US Defense Industrial Base sector. https://therecord.media/... https://twitter.com/...
  • @jarwidmark Johan Arwidmark on x
    Solarwinds is not having a good year... https://twitter.com/...
  • @likethecoins Katie Nickels on x
    On the endpoint side - should MSHTA (pronounced MISH-ta 😉) be making external connections from your network? Should PowerShell be launching an unknown batch script? https://twitter.com/...
  • @likethecoins Katie Nickels on x
    Lots of actionable details in this, thanks @MsftSecIntel! https://twitter.com/...