logo

Number of orgs compromised via Ivanti VPN zero-days grows as Mandiant weighs in

ID: 345d1f90-e4c0-57c8-a6bd-15ce06f0f461

STIX ID: report--345d1f90-e4c0-57c8-a6bd-15ce06f0f461

Feed Name: The Register (Security)

Threat Score
92/100

Date Published: 2024-01-13

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

Two unpatched zero-day vulnerabilities in Ivanti Connect Secure and Policy Secure appliances are being actively exploited (CVE-2023-46805 and CVE-2024-21887), enabling unauthenticated RCE; Mandiant links the intrusions to suspected espionage group UNC5221, which used hijacked Cyberoam appliances for C2 and deployed multiple custom malware families (Zipline, Thinspool, Wirefire, Warpwire). Ivanti has reported fewer than 20 confirmed victims so far but expects discoveries to grow as organizations run integrity checks; mitigations and forthcoming patches are strongly urged.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.