"Ivanti Security Alert: New Malware Exploits VPN Flaws"
The Cybersecurity and Infrastructure Security Agency (CISA) and its partners have issued a joint advisory warning that cyber threat actors are actively exploiting multiple vulnerabilities in Ivanti Connect Secure and Policy Secure gateways, allowing them to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges. These vulnerabilities impact all supported versions and can enable threat actors to maintain root-level persistence despite factory resets. Organizations are urged to assume compromised credentials, hunt for malicious activity, run Ivanti’s external Integrity Checker Tool, apply patching guidance, and report potential compromises to relevant authorities. Additionally, the advisory provides technical details, indicators of compromise, detection methods, incident response recommendations, mitigations, and reporting instructions.
- Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways CISA
- Chinese Cyberspies Use New Malware in Ivanti VPN Attacks SecurityWeek
- CISA warns against using hacked Ivanti devices even after factory resets BleepingComputer
- Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New Malware The Hacker News
- Cutting Edge, Part 3: Investigating Ivanti Connect Secure VPN Exploitation and Persistence Attempts Mandiant
Reading Insights
0
1
26 min
vs 27 min read
98%
5,239 → 111 words
Want the full story? Read the original article
Read on CISA