Ivanti Connect Secure and Policy Secure Attack
ID: bace2f87-4393-5f7f-acf4-2109055d7229
STIX ID: report--bace2f87-4393-5f7f-acf4-2109055d7229
Feed Name: FortiGuard Labs | FortiGuard Center - Outbreak Alerts
Active, widespread exploitation of multiple severe vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893, CVE-2024-22024) has been observed; combined issues enable unauthenticated remote command execution and backdoor implant (DSLog), with documented use by malware (Skibidi Botnet) and mention of state-sponsored targeting and multiple advisories from CISA and vendors urging mitigation and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
