More Ivanti VPN Zero-Days Fuel Attack Frenzy as Patches Finally Roll
ID: d97c0045-52d2-52e1-a03a-264e2757f5b6
STIX ID: report--d97c0045-52d2-52e1-a03a-264e2757f5b6
Feed Name: Dark Reading
Date Published: 2024-01-31
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Ivanti has released staggered patches and mitigations for multiple zero-day vulnerabilities in Connect Secure and Policy Secure appliances after active exploitation was observed; Mandiant attributes many attacks to China-backed APT UNC5221 while noting other actors have adopted the tools. The report details deployed implants — including multiple web shells (LightWire variant, ChainLine, FrameSting, Bushwalk), the ZipLine passive backdoor, WarpWire credential-stealers, and various post-exploitation tools — and warns of targeted and mass exploitation, supply-chain risks, and recommends immediate application of mitigations and patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
