logo

'Magnet Goblin' Exploits Ivanti 1-Day Bug in Mere Hours

ID: 593f1a10-5019-5a74-b7cd-61f6edad1f0a

STIX ID: report--593f1a10-5019-5a74-b7cd-61f6edad1f0a

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-03-12

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

The report describes Magnet Goblin rapidly weaponizing a critical Ivanti command-injection vulnerability (CVE-2024-21887, CVSS 9.1) to deploy backdoors and credential-stealing tools (NerbianRAT, MiniNerbian, Warpwire) and sometimes RMM tools against public-facing edge devices—highlighting active in-the-wild exploitation and urging urgent patching and Linux endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.