logo

Ivanti Connect Secure zero-days now under mass exploitation

ID: f71465e9-c046-579e-a72a-382183cef2cd

STIX ID: report--f71465e9-c046-579e-a72a-382183cef2cd

Feed Name: Bleeping Computer

Threat Score
92/100

Date Published: 2024-01-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Multiple threat groups, including a suspected Chinese state–linked actor, have been chaining two zero‑day vulnerabilities in Ivanti Connect Secure and Policy Secure appliances to run arbitrary commands, deploy the GIFTEDVISITOR webshell and several custom malware families (ZIPLINE, Thinspool, Wirefire, Lightwire, Warpwire, etc.), and compromise thousands of VPN/NAC appliances worldwide; vendors have issued mitigations and administrators are advised to treat appliance data as compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.