SEC seeks dismissal of SolarWinds cyber-disclosure case
Regulatory/Legal Action
Summary
Hide ▲
Show ▼
The SEC asked a New York federal court to voluntarily dismiss its SolarWinds enforcement case, moving to end a long-running fight tied to the 2020 supply-chain attack. The joint motion was filed on November 20, 2025 by the SEC, SolarWinds, and CISO Timothy G. Brown. The case had centered on allegations of misleading cybersecurity disclosures, fraud, and internal control failures after the compromise attributed to APT29.
Related Happenings
CISA orders FCEB remediation deadlines for KEV vulnerabilities
Public Sector Action
First: 10.03.2026 08:17
Last: 10.03.2026 08:17
Sources 1
About this happening:
CISA ordered **FCEB agencies** to patch **SolarWinds Web Help Desk** by **March 12, 2026** and to fix the other two KEV-listed flaws by **March 23, 2026**, tightening remediation...
CISA orders FCEB remediation deadlines for KEV vulnerabilities
Public Sector ActionAbout this happening: CISA ordered **FCEB agencies** to patch **SolarWinds Web Help Desk** by **March 12, 2026** and to fix the other two KEV-listed flaws by **March 23, 2026**, tightening remediation...
SolarWinds Web Help Desk untrusted data deserialization RCE (CVE-2025-40551)
Vulnerability
First: 03.02.2026 21:37
Last: 03.02.2026 21:37
Sources 1
About this happening:
**SolarWinds Web Help Desk** **CVE-2025-40551** is now confirmed **actively exploited**, putting unpatched systems at risk of **remote command execution**. The flaw is an **untrus...
SolarWinds Web Help Desk untrusted data deserialization RCE (CVE-2025-40551)
VulnerabilityAbout this happening: **SolarWinds Web Help Desk** **CVE-2025-40551** is now confirmed **actively exploited**, putting unpatched systems at risk of **remote command execution**. The flaw is an **untrus...
Timeline
-
21.11.2025 10:05 2 articles · 6mo ago
SEC, SolarWinds, and CISO seek voluntary dismissal
Legal Policy Action UpdateThe SEC, SolarWinds, and CISO Timothy G. Brown filed a joint motion on November 20, 2025 asking a New York federal court to voluntarily dismiss the enforcement case over SolarWinds' cybersecurity disclosures linked to the 2020 supply chain attack. The case began with SEC allegations in October 2023 that SolarWinds defrauded investors by overstating cybersecurity practices and understating known risks, and SDNY later threw out many of those allegations in July 2024.
Show sources
- SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny — thehackernews.com — 21.11.2025 10:05
- SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny — thehackernews.com — 21.11.2025 10:05