Newest Ivanti SSRF zero-day now under mass exploitation
ID: 085d5ee7-8456-5377-a863-44f35f1b732f
STIX ID: report--085d5ee7-8456-5377-a863-44f35f1b732f
Feed Name: Bleeping Computer
An actively exploited SSRF zero-day (CVE-2024-21893) in Ivanti Connect Secure and Policy Secure is being used in mass attacks, with Shadowserver observing numerous attacker IPs and Rapid7 publishing a PoC; related zero-days were previously exploited by the espionage group UTA0178/UNC5221 to deploy webshells and backdoors. The scale of exposed devices and lack of comprehensive patches prompted CISA to order federal agencies to disconnect impacted VPN appliances until they are factory-reset and updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
