"Ivanti's Battle Against Zero-Day Exploits: Updates, Mitigations, and Delays"

1 min read
Source: CISA
TL;DR Summary

CISA has issued an alert urging organizations to follow updated guidance and software updates from Ivanti to defend against vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways. The vulnerabilities, including privilege escalation and server-side request forgery, could be exploited by threat actors to take control of affected systems. CISA recommends continuous threat hunting, monitoring of authentication and account usage, and isolation of affected systems. Organizations are advised to apply patches when available and continue network hunting to detect any compromise that may have occurred before patches were implemented. This guidance supplements previous mitigation and detection advice from CISA.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

79%

46799 words

Want the full story? Read the original article

Read on CISA