logo

THREAT ALERT: Ivanti Connect Secure VPN Zero-Day Exploitation

ID: 29780c58-5fff-53fd-af1f-5c90eb3cca64

STIX ID: report--29780c58-5fff-53fd-af1f-5c90eb3cca64

Feed Name: Cybereason Blog

Threat Score
90/100

Date Published: 2024-02-06

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

Cybereason reports active exploitation of multiple Ivanti Connect Secure/Policy Secure zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887, and later CVEs) that enable unauthenticated authentication bypass, RCE, privilege escalation and SSRF on Internet-facing VPN appliances; observed post-exploitation includes webshells (LIGHTWIRE, WIREFIRE, CHAINLINE, etc.), the WARPWIRE JavaScript credential harvester, coinminers, credential dumping and lateral movement, with attribution to suspected UNC5221 and widespread automated abuse — the report also provides IOCs and mitigation/hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.