logo

Ivanti zero-day exploits explode as bevy of attackers get in on the act

ID: 91da1c9b-2161-5544-94d6-07c60d7e5af4

STIX ID: report--91da1c9b-2161-5544-94d6-07c60d7e5af4

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-01-16

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers report rapid, in-the-wild mass exploitation of Ivanti Connect Secure VPN zero-days beginning after public disclosure, with Volexity and Microsoft reporting at least ~1,700 compromised devices (predominantly attributed to UTA0178) across governments, large enterprises, and critical sectors; attackers deployed a modified GIFTEDVISITOR webshell, and organizations are urged to run Ivanti's Integrity Checker, collect forensic artifacts, and hunt for lateral movement and credential compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.