Signal

Warlock-linked SmarterMail breach and active SolarWinds WHD exploitation reported

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-02-09 12:02 UTCUpdated 2026-02-10 10:24 UTC
rss
exploitationransomwarebreachvulnerabilityinitial_accesspost_exploitation
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Warlock Gang Breaches SmarterTools Via SmarterMail Bugs
Dark Reading · News · darkreading.com · 2026-02-09 21:59 UTC
Overview

Two separate intrusion threads highlight how attackers are leveraging exposed or unpatched enterprise software: a ransomware-linked breach at SmarterTools tied to its SmarterMail product, and active exploitation of SolarWinds Web Help Desk (WHD) vulnerabilities to gain code execution and deploy legitimate tooling for persistence and remote control.

Entities
SmarterToolsSolarWindsMicrosoftSmarterMailSolarWinds Web Help Desk (WHD)VelociraptorDerek Curtis
Score total
1.57
Momentum 24h
5
Posts
5
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • SmarterTools breach details were confirmed in reporting over the past week
  • Reporting indicates active exploitation of SolarWinds WHD vulnerabilities in the wild
  • Multiple outlets are converging on the same intrusion themes, increasing confidence
Why it matters
  • Unpatched email infrastructure can become a direct path to ransomware-linked network compromise
  • WHD exploitation shows attackers using legitimate tools (Velociraptor) for persistence/control
  • Credential theft from IT environments can enable lateral movement and broader compromise
LLM analysis
Topic mix: mediumPromo risk: lowSource quality: high
Recurring claims
  • Warlock ransomware actors breached SmarterTools by compromising an unpatched SmarterMail instance.
  • Threat actors are exploiting SolarWinds Web Help Desk (WHD) vulnerabilities to gain code execution and deploy legitimate tools such as Velociraptor.
How sources frame it
  • BleepingComputer: neutral
  • Dark Reading: neutral
  • The Hacker News: neutral
All evidence
All evidence
Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server
thehackernews · thehackernews.com · 2026-02-10 10:24 UTC
Warlock Gang Breaches SmarterTools Via SmarterMail Bugs
Dark Reading · darkreading.com · 2026-02-09 21:59 UTC
Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks
bleepingcomputer_all · bleepingcomputer.com · 2026-02-09 20:28 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 5
Top publishers (this list)
  • thehackernews (1)
  • Dark Reading (1)
  • The Register Security (1)
  • bleepingcomputer_all (1)
Top origin domains (this list)
  • thehackernews.com (1)
  • darkreading.com (1)
  • go.theregister.com (1)
  • bleepingcomputer.com (1)