CISA orders federal agencies to disconnect Ivanti VPN appliances by Saturday
ID: f7d637dd-f7d8-530d-abbb-d43b822bea01
STIX ID: report--f7d637dd-f7d8-530d-abbb-d43b822bea01
Feed Name: Bleeping Computer
CISA has ordered U.S. federal agencies to disconnect all Ivanti Connect Secure and Ivanti Policy Secure VPN appliances by Feb 2 due to multiple actively exploited zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893). The report describes widespread exposure (Shodan: ~22,000; Shadowserver: ~21,400), evidence of compromised devices, Ivanti patches and mitigations, and guidance to factory reset, rebuild with patched software, revoke credentials, and assume linked accounts may be compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
