Ivanti zero-day exploits explode as bevy of attackers get in on the act
ID: 91da1c9b-2161-5544-94d6-07c60d7e5af4
STIX ID: report--91da1c9b-2161-5544-94d6-07c60d7e5af4
Feed Name: The Register (Security)
Researchers report rapid, in-the-wild mass exploitation of Ivanti Connect Secure VPN zero-days beginning after public disclosure, with Volexity and Microsoft reporting at least ~1,700 compromised devices (predominantly attributed to UTA0178) across governments, large enterprises, and critical sectors; attackers deployed a modified GIFTEDVISITOR webshell, and organizations are urged to run Ivanti's Integrity Checker, collect forensic artifacts, and hunt for lateral movement and credential compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
