Ivanti discloses fifth vulnerability, doesn't credit researchers who found it
ID: 9682b9c2-84e3-54da-82e8-926640667900
STIX ID: report--9682b9c2-84e3-54da-82e8-926640667900
Feed Name: The Register (Security)
**Executive summary:** The article details a string of vulnerabilities in Ivanti Connect Secure, Policy Secure, and ZTA gateways—including CVE-2024-22024 and multiple earlier zero-days—that have prompted mitigations, staged patching, reports of active exploitation and mass exploitation concerns (with estimates of devices potentially backdoored), and emergency advisories from CISA and the UK's NCSC; it also notes a dispute between Ivanti and external researchers over discovery credit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
