CISA Urges Immediate Mitigation of Ivanti Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 24-01 to address vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure solutions, which have been actively exploited by threat actors. Federal agencies are required to immediately implement Ivanti's published mitigation, run the External Integrity Checker Tool, and report any indications of compromise to CISA. Agencies must also take additional steps if compromise is detected and provide a complete inventory of affected products. CISA will provide technical assistance and issue further guidance, with the Directive remaining in effect until all required actions are completed.
- ED 24-01: Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities CISA
- CISA mandates agencies close 2 cyber vulnerabilities immediately Federal News Network
- CISA emergency directive: Mitigate Ivanti zero-days immediately BleepingComputer
- Ivanti vulnerabilities are being exploited widely, CISA says in emergency directive The Record from Recorded Future News
- Ivanti EPMM Vulnerability Targeted in Attacks as Exploitation of VPN Flaws Increases SecurityWeek
Reading Insights
0
1
6 min
vs 7 min read
92%
1,210 → 94 words
Want the full story? Read the original article
Read on CISA