Hackers exploit Ivanti SSRF flaw to deploy new DSLog backdoor
ID: de34b936-ea88-5a50-bb8d-9269d52dca1b
STIX ID: report--de34b936-ea88-5a50-bb8d-9269d52dca1b
Feed Name: Bleeping Computer
Threat Score
### Executive summary The report details active exploitation of an SSRF zero-day (CVE-2024-21893) in Ivanti Connect Secure/Policy Secure/ZTA appliances that allowed attackers to inject a DSLog backdoor enabling remote root command execution; Orange Cyberdefense found ~700 compromised servers, evidence of log tampering, and a per-device SHA256-based webshell authentication mechanism, and it references Ivanti patches and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
