MITRE says state hackers breached its network via Ivanti zero-days
ID: 1bacebc2-e82b-53d2-a86b-f68d89231752
STIX ID: report--1bacebc2-e82b-53d2-a86b-f68d89231752
Feed Name: Bleeping Computer
Threat Score
MITRE disclosed that a state-backed actor exploited two Ivanti Connect Secure zero-days in January 2024 to breach its NERVE R&D network; the attackers chained CVE-2023-46805 and CVE-2024-21887, bypassed MFA via session hijacking, moved laterally using a hijacked admin account, and used webshells/backdoors to maintain access and harvest credentials—similar exploitation impacted thousands of Ivanti appliances worldwide and prompted a CISA emergency directive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
