logo

Ivanti VPN Flaw Exploited to Inject Novel Backdoor; Hundreds Pwned

ID: f8c3313c-705f-5e04-843e-8c59549ed672

STIX ID: report--f8c3313c-705f-5e04-843e-8c59549ed672

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-02-13

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Researchers observed a mass-exploitation campaign against recently disclosed Ivanti VPN vulnerabilities (notably CVE-2024-21893) resulting in a novel backdoor named "DSLog" being implanted in appliances and compromising over 670 IT infrastructures; the backdoor uses per-appliance hashes and an API-key control mechanism that makes detection difficult. Analysts recommend factory resets, full patching where available, and applying XML mitigations as a stopgap for unpatched appliance versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.