CISA: Disconnect vulnerable Ivanti products TODAY
ID: 43f7034f-bfb9-50ae-b77d-90f34053f6d2
STIX ID: report--43f7034f-bfb9-50ae-b77d-90f34053f6d2
Feed Name: Malwarebytes Blog
CISA issued an emergency directive requiring federal agencies to disconnect all Ivanti Connect Secure and Ivanti Policy Secure instances by Feb 2, 2024, after multiple high-severity vulnerabilities (including CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893) were actively exploited—reports cite thousands of vulnerable or compromised devices and at least one Chinese APT bypassing mitigations; successful exploitation can enable lateral movement, data exfiltration, persistent access, and full compromise, so agencies are required to assume domain accounts are compromised, conduct threat hunting, factory reset affected devices, and apply vendor mitigations/patches before reconnecting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
