"Risks of Hacked Ivanti Devices and Chinese Cyberespionage"

1 min read
Source: BleepingComputer
"Risks of Hacked Ivanti Devices and Chinese Cyberespionage"
Photo: BleepingComputer
TL;DR Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers may maintain root persistence on hacked Ivanti VPN gateways even after factory resets, evading detection by Ivanti's Integrity Checker Tool. Four vulnerabilities, ranging from high to critical severity, can be exploited for authentication bypass and arbitrary command execution. CISA advises federal agencies to assume compromised credentials, hunt for malicious activity, run Ivanti's updated scanner, and apply patching guidance. Despite Ivanti's assurances, CISA urges caution and warns that it may still not be safe to use previously compromised Ivanti Connect Secure and Ivanti Policy Secure devices even after cleaning and performing a factory reset.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

3 min

vs 4 min read

Condensed

87%

777104 words

Want the full story? Read the original article

Read on BleepingComputer