logo

Infoseccers think attackers backed by China are behind Ivanti zero-day exploits

ID: 72a84c0d-c136-540a-94d2-2d7546242d07

STIX ID: report--72a84c0d-c136-540a-94d2-2d7546242d07

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-01-11

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers and Volexity confirmed active exploitation of two zero-day vulnerabilities in Ivanti Connect Secure and Policy Secure (CVE-2023-46805 — auth bypass, and CVE-2024-21887 — command injection). An actor tracked as UTA0178 (believed to be China-linked) used the chain to backdoor appliances, steal credentials (via modified JS), delete logs, and pivot, while Ivanti provides staggered patches and CISA added the CVEs to its KEV catalog; mitigations and IOCs are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.