"Urgent: CISA Mandates Immediate Closure of Exploited Ivanti VPN Backdoor"

1 min read
Source: BleepingComputer
"Urgent: CISA Mandates Immediate Closure of Exploited Ivanti VPN Backdoor"
Photo: BleepingComputer
TL;DR Summary

Ivanti warns administrators to refrain from pushing new device configurations to their appliances after applying mitigations for two zero-day vulnerabilities, as doing so could leave them vulnerable to ongoing attacks. The company's Connect Secure and Policy Secure appliances have been targeted in widespread attacks exploiting authentication bypass and command injection bugs, with thousands of exposed appliances and hundreds already compromised. Threat actors, including a suspected Chinese state-backed group, have backdoored appliances, deployed cryptocurrency miners and malware, and stolen data from various organizations worldwide.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

83%

49383 words

Want the full story? Read the original article

Read on BleepingComputer