logo

CISA says crooks used Ivanti bugs to snoop around high-risk chemical facilities

ID: 4329de03-8aad-5b8d-a053-7bc6cf1ddcf5

STIX ID: report--4329de03-8aad-5b8d-a053-7bc6cf1ddcf5

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-06-25

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CISA reported that attackers exploited critical Ivanti Connect Secure/Policy Secure vulnerabilities to install an advanced webshell on the CSAT appliance, accessing the device multiple times in January; while there is no evidence of data exfiltration beyond the Ivanti device and sensitive data was encrypted, potentially exposed items included Top-Screen survey data, security assessments, encrypted site security plans, Personnel Surety Program records, and CSAT user account details. CISA recommended patching the affected Ivanti products, rotating passwords, and is arranging identity protection for individuals vetted under the Personnel Surety Program.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.