Ivanti VPN Flaw Exploited to Inject Novel Backdoor; Hundreds Pwned
ID: f8c3313c-705f-5e04-843e-8c59549ed672
STIX ID: report--f8c3313c-705f-5e04-843e-8c59549ed672
Feed Name: Dark Reading
Researchers observed a mass-exploitation campaign against recently disclosed Ivanti VPN vulnerabilities (notably CVE-2024-21893) resulting in a novel backdoor named "DSLog" being implanted in appliances and compromising over 670 IT infrastructures; the backdoor uses per-appliance hashes and an API-key control mechanism that makes detection difficult. Analysts recommend factory resets, full patching where available, and applying XML mitigations as a stopgap for unpatched appliance versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
