logo

Hackers exploit Ivanti SSRF flaw to deploy new DSLog backdoor

ID: de34b936-ea88-5a50-bb8d-9269d52dca1b

STIX ID: report--de34b936-ea88-5a50-bb8d-9269d52dca1b

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

### Executive summary The report details active exploitation of an SSRF zero-day (CVE-2024-21893) in Ivanti Connect Secure/Policy Secure/ZTA appliances that allowed attackers to inject a DSLog backdoor enabling remote root command execution; Orange Cyberdefense found ~700 compromised servers, evidence of log tampering, and a per-device SHA256-based webshell authentication mechanism, and it references Ivanti patches and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.