Infoseccers think attackers backed by China are behind Ivanti zero-day exploits
ID: 72a84c0d-c136-540a-94d2-2d7546242d07
STIX ID: report--72a84c0d-c136-540a-94d2-2d7546242d07
Feed Name: The Register (Security)
Security researchers and Volexity confirmed active exploitation of two zero-day vulnerabilities in Ivanti Connect Secure and Policy Secure (CVE-2023-46805 — auth bypass, and CVE-2024-21887 — command injection). An actor tracked as UTA0178 (believed to be China-linked) used the chain to backdoor appliances, steal credentials (via modified JS), delete logs, and pivot, while Ivanti provides staggered patches and CISA added the CVEs to its KEV catalog; mitigations and IOCs are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
