logo

Ivanti commits to secure-by-design overhaul after vulnerability nightmare

ID: 1b6c45da-86b6-554d-9163-ace661ecb3d3

STIX ID: report--1b6c45da-86b6-554d-9163-ace661ecb3d3

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-04-04

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Ivanti disclosed multiple high‑severity vulnerabilities in Connect Secure and Policy Secure that were exploited in the wild as zero‑days by several groups (including UNC5221 and China-linked espionage teams), causing widespread compromise risk and prompting CISA to order federal agencies to disconnect affected devices; the vendor faced delayed patching and unreliable integrity checks and has announced a security-by-design overhaul, faster patching, enhanced monitoring, and improved transparency to address the incidents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.