logo

Chained Exploits, Stolen VPN Access: Hackers Target Ivanti Users Despite Patches

ID: 3b29e32a-72e1-5b6e-89f3-283095d1d790

STIX ID: report--3b29e32a-72e1-5b6e-89f3-283095d1d790

Feed Name: HackRead

Threat Score
85/100

Date Published: 2024-02-06

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Shadowserver, Rapid7 and other firms report active exploitation of Ivanti SAML zero-day CVE-2024-21893 (CVSS 8.2) impacting Ivanti Connect Secure, Policy Secure and Neurons for ZTA; attackers have used chains involving CVE-2023-46805 and CVE-2024-21887, with evidence of many attacker IPs, at least dozens of compromised organizations, linkage to APT UTA0178 and use of KrustyLoader, while Ivanti has issued patches and additional mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.