logo

MITRE says state hackers breached its network via Ivanti zero-days

ID: 1bacebc2-e82b-53d2-a86b-f68d89231752

STIX ID: report--1bacebc2-e82b-53d2-a86b-f68d89231752

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-04-19

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

MITRE disclosed that a state-backed actor exploited two Ivanti Connect Secure zero-days in January 2024 to breach its NERVE R&D network; the attackers chained CVE-2023-46805 and CVE-2024-21887, bypassed MFA via session hijacking, moved laterally using a hijacked admin account, and used webshells/backdoors to maintain access and harvest credentials—similar exploitation impacted thousands of Ivanti appliances worldwide and prompted a CISA emergency directive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.