Ivanti: VPN appliances vulnerable if pushing configs after mitigation
ID: b8c621cd-7e25-5920-8d9d-0b57a0a31026
STIX ID: report--b8c621cd-7e25-5920-8d9d-0b57a0a31026
Feed Name: Bleeping Computer
Threat Score
Ivanti warned that two actively exploited zero-days in Connect Secure and Policy Secure (an authentication bypass and a command-injection flaw) are being chained in large-scale attacks; thousands of appliances are internet-exposed, hundreds have been compromised, and at least one suspected state-backed group (UTA0178/UNC5221) has backdoored over 2,100 devices with webshells and deployed miners and custom malware, prompting mitigations and a CISA emergency directive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
