logo

Active Exploitation of Two Zero-Day Vulnerabilities in Ivanti Connect Secure VPN

ID: b168d45e-d417-527d-bff4-00536e2c4484

STIX ID: report--b168d45e-d417-527d-bff4-00536e2c4484

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2024-01-10

Date Updated: 2026-05-01

...
...

Volexity describes active exploitation of two chained zero-day vulnerabilities in Ivanti Connect Secure appliances (an authentication bypass and a command-injection) enabling unauthenticated RCE; a suspected Chinese nation-state actor (UTA0178) used these to install backdoors, deploy GLASSTOKEN webshells, harvest credentials via modified JavaScript, and lateralize across networks. The report provides forensic findings, IoCs (IPs/domains), detection guidance (network/log/Integrity Checker methods), and remediation/response recommendations including applying Ivanti mitigations and collecting forensic artifacts before rebooting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.