CISA says crooks used Ivanti bugs to snoop around high-risk chemical facilities
ID: 4329de03-8aad-5b8d-a053-7bc6cf1ddcf5
STIX ID: report--4329de03-8aad-5b8d-a053-7bc6cf1ddcf5
Feed Name: The Register (Security)
CISA reported that attackers exploited critical Ivanti Connect Secure/Policy Secure vulnerabilities to install an advanced webshell on the CSAT appliance, accessing the device multiple times in January; while there is no evidence of data exfiltration beyond the Ivanti device and sensitive data was encrypted, potentially exposed items included Top-Screen survey data, security assessments, encrypted site security plans, Personnel Surety Program records, and CSAT user account details. CISA recommended patching the affected Ivanti products, rotating passwords, and is arranging identity protection for individuals vetted under the Personnel Surety Program.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
