Quick Summary
The Securityish Brief
Researchers from Microsoft and Huntress have reported that unpatched SolarWinds Web Help Desk (WHD) instances are currently under attack by threat actors. The attacks began in mid-January 2026 and are exploiting known vulnerabilities in WHD, although the specific CVE being targeted remains unclear. The attackers have successfully compromised at least three out of 78 customers using the WHD solution.
Once inside the networks, the attackers utilize legitimate remote access tools such as Zoho Assist to perform their activities. They also deploy the Velociraptor digital forensics and incident response tool, which, while intended for monitoring, can be misused for command and control operations. This dual-use capability allows attackers to execute commands, retrieve files, and disable security controls.
The attackers have been observed using a reverse SSH shell and establishing additional command and control channels. They have also modified system registries to disable security features like Windows Defender and have created scheduled tasks to maintain persistence on compromised systems.
Given the nature of these attacks, it remains uncertain whether they are part of a broader cyber espionage effort or financially motivated. However, the implications for organizations are significant, as unauthorized access can lead to data breaches and further exploitation.
Implications for Organizations
Organizations using SolarWinds WHD should take immediate action to mitigate risks. Applying the latest patches, specifically version 2026.1 or later, is crucial to closing known vulnerabilities. Additionally, rotating credentials for service and admin accounts that can be accessed through WHD is recommended.
It is also essential to review WHD hosts for any unauthorized remote access tools, unexpected services, or suspicious activities. Monitoring for encoded PowerShell execution and silent installations can help identify potential compromises early.
As these attacks highlight the ongoing risks associated with unpatched software, organizations must prioritize timely updates and robust security practices to protect their networks from similar threats in the future.
Key Takeaways
- Apply the latest SolarWinds WHD patch (version 2026.1 or later) to address vulnerabilities.
- Rotate credentials for service and admin accounts that can be accessed from WHD.
- Remove public internet access to admin paths for WHD to reduce exposure.
- Review WHD hosts for unauthorized remote access tools and unexpected services.
- Monitor for encoded PowerShell execution and silent installations related to WHD processes.
Key Terms & Concepts
- SolarWinds Web Help Desk (WHD): In this article, SolarWinds WHD refers to a software solution used for managing IT service requests that is currently facing exploitation due to vulnerabilities.
- CVE: CVE stands for Common Vulnerabilities and Exposures, a list of publicly disclosed cybersecurity vulnerabilities.
- Zoho Assist: Zoho Assist is a remote access and support tool that attackers have used to gain control over compromised systems.
- Velociraptor: Velociraptor is a digital forensics and incident response tool that can be misused for command and control operations by attackers.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.