"Ivanti Security Alert: New Malware Exploits VPN Flaws"

1 min read
Source: CISA
TL;DR Summary

The Cybersecurity and Infrastructure Security Agency (CISA) and its partners have issued a joint advisory warning that cyber threat actors are actively exploiting multiple vulnerabilities in Ivanti Connect Secure and Policy Secure gateways, allowing them to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges. These vulnerabilities impact all supported versions and can enable threat actors to maintain root-level persistence despite factory resets. Organizations are urged to assume compromised credentials, hunt for malicious activity, run Ivanti’s external Integrity Checker Tool, apply patching guidance, and report potential compromises to relevant authorities. Additionally, the advisory provides technical details, indicators of compromise, detection methods, incident response recommendations, mitigations, and reporting instructions.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

26 min

vs 27 min read

Condensed

98%

5,239111 words

Want the full story? Read the original article

Read on CISA