Ivanti Connect Secure zero-days now under mass exploitation
ID: f71465e9-c046-579e-a72a-382183cef2cd
STIX ID: report--f71465e9-c046-579e-a72a-382183cef2cd
Feed Name: Bleeping Computer
Multiple threat groups, including a suspected Chinese state–linked actor, have been chaining two zero‑day vulnerabilities in Ivanti Connect Secure and Policy Secure appliances to run arbitrary commands, deploy the GIFTEDVISITOR webshell and several custom malware families (ZIPLINE, Thinspool, Wirefire, Lightwire, Warpwire, etc.), and compromise thousands of VPN/NAC appliances worldwide; vendors have issued mitigations and administrators are advised to treat appliance data as compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
