CISA Orders Ivanti VPN Appliances Disconnected: What to Do
ID: 1bb3cd14-24c1-5d4a-b49a-0f886472085e
STIX ID: report--1bb3cd14-24c1-5d4a-b49a-0f886472085e
Feed Name: Dark Reading
Date Published: 2024-02-01
Date Updated: 2026-04-21
Author: Fahmida Y. Rashid, Managing Editor, Features, Dark Reading
CISA ordered all federal civilian executive branch agencies to immediately disconnect Ivanti Connect Secure and Ivanti Policy Secure appliances after multiple zero-day vulnerabilities were actively exploited (notably by UNC5221), instructing agencies to rebuild devices, revoke and replace certificates and credentials, assume compromise of connected systems, perform aggressive threat hunting, and report remediation status to CISA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
