logo

Serious Adversaries Circle Ivanti CSA Zero-Day Flaws

ID: cd7cbf9c-7661-5c95-92cf-1f8c3951291f

STIX ID: report--cd7cbf9c-7661-5c95-92cf-1f8c3951291f

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-10-14

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Fortinet observed a suspected nation-state actor chaining three zero-day Ivanti CSA vulnerabilities (CVE-2024-8190, CVE-2024-8963, CVE-2024-9380) to gain foothold, drop a web shell, exploit a backend SQL server (CVE-2024-29824) for remote execution, and deploy DNS tunneling and a Linux kernel object rootkit for persistent, kernel-level access; the actor also patched exploited files to block other intruders. Organizations running Ivanti CSA 4.6 and earlier should apply vendor patches and mitigations immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.