Leadership1 distinct publisher3 min readPublished
Microsoft's Defender team cannot say which of three SolarWinds flaws opened the door, because the December hosts were vulnerable to all of them, which makes the exposure list more useful than the patch list.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The forensic gap is the most useful part of Microsoft's write-up. Its researchers name three candidate vulnerabilities and confirm none of them, because the affected hosts carried both the older and the newer flaws at the same time when the activity ran [22][4]. This is what investigating a long-exposed application looks like when the patch backlog is deeper than one cycle.
The dates decide how much a patch programme could have helped. The newest flaws were disclosed on January 28, 2026, and the intrusion ran during December 2025 [3][4]. Counting back from the disclosure, that is 28 days if the activity ended on December 31 and 58 if it began on December 1 [21]. So either an older flaw sat open for months, or the newer ones were in use before anyone published them. A service-level agreement measured in days from disclosure does not cover either case.
The detection argument follows from the toolchain rather than from the entry point. Microsoft says the attackers leaned on living-off-the-land techniques, legitimate administrative software and quiet persistence [6], and it makes the evasion explicit in one step: sideloading a malicious DLL through wab.exe reduces detections that key on well-known dumping tools or direct-handle patterns [14]. Its own recommendation is behaviour-based detection across identity, endpoint and network [7]. Read that as a budget statement: coverage built on named-bad-binary lists was the control that did not fire here.
The virtual machine deserves attention for what it does to visibility. The alert that fired was on the creation of the scheduled task itself [12], and the task was named TPMProfiler and forwarded host TCP 22022 to port 22 inside the guest [13]. An agent running on the host can see a task being registered under SYSTEM and an unusual listening port. The activity inside the guest itself falls outside that view.
This is a vendor blog that ends by pointing customers at Microsoft's own vulnerability management to find unpatched instances [20]. The load-bearing detail works against that pitch, since an inconclusive attribution is a poor advertisement, and most of the hardening list is unbranded labour: remove public access to admin paths and raise logging on the Ajax Proxy [16], hunt for RMM artefacts such as ToolsIQ.exe left behind after exploitation [17], rotate the service and admin credentials reachable from the helpdesk host and isolate what was touched [18].
The board-deck version reads: three CVEs, patch them, close the item. It is incomplete on its own terms, because the vendor cannot say which one mattered [4] and because the intrusion did not stop at the application, moving from domain group enumeration through reverse SSH and RDP to a password-data request against a domain controller [10][11][15]. The tradeoff worth naming is where the next dollar of assurance goes. Patch velocity is measurable and comforting; an accurate inventory of internet-facing applications that hold domain-joined service accounts is tedious and tells you which compromises are survivable. Microsoft's own framing is that a single exposed application can reach full domain compromise when it is unpatched or insufficiently monitored [5], and the second clause is the one most organisations cannot evidence.
The decision this quarter is which of those two lists a security review is built on. The consequence next quarter arrives with the update Microsoft has promised [19]: if it names one CVE, patch timing becomes the story again, and if it does not, the exposure list is all anyone has to reason with.
Ranked by verification strength, evidence, and original report placement.
Successful exploitation allowed attackers unauthenticated remote code execution on internet-facing SolarWinds Web Help Desk deployments, letting an external attacker run arbitrary commands in the application context.
The Microsoft Defender Research Team observed a multi-stage intrusion in which threat actors exploited internet-exposed SolarWinds Web Help Desk instances for an initial foothold and then moved laterally towards other high-value assets in the organisation.
Microsoft has not confirmed whether the attacks relate to the Web Help Desk vulnerabilities disclosed on January 28, 2026, such as CVE-2025-40551 (critical untrusted data deserialization) and CVE-2025-40536 (security control bypass), or to previously disclosed flaws such as CVE-2025-26399.
Because the attacks occurred in December 2025 on machines vulnerable to both the old and new sets of CVEs at the same time, Microsoft says it cannot reliably confirm the exact CVE used to gain the initial foothold.
Microsoft describes the activity as a common but high-impact pattern in which a single exposed application can provide a path to full domain compromise when vulnerabilities are unpatched or insufficiently monitored.
In this intrusion the attackers relied heavily on living-off-the-land techniques, legitimate administrative tools and low-noise persistence mechanisms.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Rillet's $100M reads as proof mid-market ERP is rip-and-replace, mostly at the cheap end1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
product
Nebius funds $4.5bn of AI capacity on terms that pay lenders mostly in stock2 distinct publishers
product
The cheapest part in the car is now the one that stops the line1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Rich forensics, one witness
The artefacts are specific enough to hunt with tonight — a named scheduled task, a quoted QEMU command line with its port forward, a sideloaded DLL paired to wab.exe, a leftover ToolsIQ.exe. All of it is Microsoft's own Defender telemetry, and no second party has published a word. The one thing a defender most wants nailed down, which flaw opened the door, Microsoft says outright it cannot nail down, and the post is presented as initial observations from an investigation still running.
Live in the wild, size unknown
"Several hosts", "some environments", "in at least one case" is the most precise the reporting ever gets. That is plenty to establish real exploitation reaching domain-controller credentials, and nowhere near enough to size the exposed population: no victim tally, no sectors, no regions, no dwell time. Set against a disclosure dated 28 January 2026 for flaws whose possible use predates it, the honest reading is confirmed activity of unmeasured breadth.
Understated by its own author
Unusually, the writeup claims less than its evidence would allow. There is no actor name, no campaign branding, no assertion of a zero-day, and Microsoft declines to attach the intrusions to the fresh CVEs it could easily have headlined — while the same page documents SYSTEM-level persistence inside a virtual machine and password replication from a domain controller. The mild pull in the other direction is commercial: the piece ends on Defender coverage and a vulnerability-management lookup.
Investigator sells the remedy
The party that found this intrusion also sells the detection, the vulnerability-management scan and the hunting platform the reader is steered toward, and the guidance section doubles as a feature list. The products that fail in the story belong to others: SolarWinds' helpdesk is the entry point and Zoho's ManageEngine agent becomes the attacker's remote control, with neither company given space to answer. None of that makes the telemetry wrong, but the selection of what got measured and published sits entirely with one interested party.
Trust the artefacts, not the scope
Two different confidences are in play. The indicators are concrete, internally consistent and come from the platform that generated the alerts, so acting on them is low-regret. Everything about magnitude, attribution and cause is either absent or explicitly unresolved, and the author promises revisions. Hunt on this now; do not yet build a narrative about how widespread it is.