Cyble Sensors Detect Exploitation Of Ivanti Vulnerabilities
ID: 500396c3-8b45-5ec5-8077-afdd817cadab
STIX ID: report--500396c3-8b45-5ec5-8077-afdd817cadab
Feed Name: Cyble Blog
Cyble Global Sensor Intelligence reports ongoing, real-world exploitation of two high-severity Ivanti Connect Secure vulnerabilities (an authentication bypass CVE-2023-46805 and a command-injection RCE CVE-2024-21887). The advisory describes how attackers enumerate unauthenticated REST endpoints, leverage path traversal and a vulnerable license API to inject commands, and have been observed exfiltrating data and establishing reverse tunnels; tens of thousands of internet-exposed instances increase the scale and urgency, with vendor mitigations and staged patches forthcoming.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
