Ivanti VPN Flaws Exploited by DSLog Backdoor and Crypto Miners
ID: 1539a618-f196-5fa2-97c5-3f5a39767926
STIX ID: report--1539a618-f196-5fa2-97c5-3f5a39767926
Feed Name: HackRead
Ivanti released patches on January 31 and early February 2024 to fix multiple critical vulnerabilities in Ivanti Connect Secure and Policy Secure appliances after zero-day flaws were exploited in the wild; attackers leveraged SAML and command-injection issues to obtain root, install a DSLog backdoor that logs requests and executes commands, and deploy KrustyLoader and crypto miners, with Orange Cyberdefense identifying roughly 700 compromised appliances and advising patching, factory resets, and additional updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
