Serious Adversaries Circle Ivanti CSA Zero-Day Flaws
ID: cd7cbf9c-7661-5c95-92cf-1f8c3951291f
STIX ID: report--cd7cbf9c-7661-5c95-92cf-1f8c3951291f
Feed Name: Dark Reading
Fortinet observed a suspected nation-state actor chaining three zero-day Ivanti CSA vulnerabilities (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) to gain foothold, drop a web shell, exploit a backend SQL server (CVE-2024-29824) for remote execution, and deploy DNS tunneling and a Linux kernel object rootkit for persistent, kernel-level access; the actor also patched exploited files to block other intruders. Organizations running Ivanti CSA 4.6 and earlier should apply vendor patches and mitigations immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
