logo

Ivanti Connect Secure VPN Exploitation Goes Global

ID: 5aa372e9-faaf-58d1-aaa3-144862a19f96

STIX ID: report--5aa372e9-faaf-58d1-aaa3-144862a19f96

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2024-01-15

Date Updated: 2026-05-01

...
...

Volexity reports active and widespread exploitation of two chained zero-day vulnerabilities in Ivanti Connect Secure VPN appliances (CVE-2024-21887 and CVE-2023-46805), resulting in the deployment of a variant of the GIFTEDVISITOR webshell on more than 1,700 globally distributed devices across governments, telecoms, defense, finance and large enterprises; the activity is attributed with medium confidence to UTA0178, other actors have been observed attempting exploitation, and Volexity urges immediate application of Ivanti mitigations and integrity checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.