Ivanti customers urged to patch vulnerabilities allegedly exploited by Chinese state hackers
ID: 50bc9f93-3be9-59b2-9a63-7ec00197cb2b
STIX ID: report--50bc9f93-3be9-59b2-9a63-7ec00197cb2b
Feed Name: The Record from Recorded Future News
CISA and Ivanti warned of active exploitation of two high-severity zero-day vulnerabilities in Ivanti Connect Secure and Policy Secure (CVE-2023-46805 and CVE-2024-21887) that permit authentication bypass and remote command execution; Volexity observed lateral movement beginning in early December and attributes activity to a suspected Chinese nation-state actor (UTA0178). Ivanti is releasing staged patches (Jan–Feb) and recommends immediate mitigations, log/network monitoring, and forensic support for affected customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
