Chained Exploits, Stolen VPN Access: Hackers Target Ivanti Users Despite Patches
ID: 3b29e32a-72e1-5b6e-89f3-283095d1d790
STIX ID: report--3b29e32a-72e1-5b6e-89f3-283095d1d790
Feed Name: HackRead
Threat Score
Shadowserver, Rapid7 and other firms report active exploitation of Ivanti SAML zero-day CVE-2024-21893 (CVSS 8.2) impacting Ivanti Connect Secure, Policy Secure and Neurons for ZTA; attackers have used chains involving CVE-2023-46805 and CVE-2024-21887, with evidence of many attacker IPs, at least dozens of compromised organizations, linkage to APT UTA0178 and use of KrustyLoader, while Ivanti has issued patches and additional mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
