logo

CISA orders Ivanti devices targeted by Chinese hackers be disconnected

ID: 27401a13-bea6-550a-a5ba-a1d2d86e2de6

STIX ID: report--27401a13-bea6-550a-a5ba-a1d2d86e2de6

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2024-02-01

Date Updated: 2026-04-21

Author: AJ Vicens

...
...

CISA ordered federal agencies to disconnect Ivanti Connect Secure and Ivanti Policy Secure devices after researchers and vendors reported broad, active exploitation of multiple zero-day vulnerabilities by suspected Chinese-linked espionage actors (tracked as UNC5221 and others). The exploited flaws reportedly allow trivial command execution and internal network pivoting on internet-facing VPN appliances; Ivanti and security researchers published remediation steps but CISA recommended taking devices offline, factory resetting, patching, and only returning them to service after validated remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.