logo

Ivanti CSA Attacks: CISA & FBI Expose Exploit Chain

ID: f3f0bb0a-9f78-5e60-ba2c-15590492987e

STIX ID: report--f3f0bb0a-9f78-5e60-ba2c-15590492987e

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-10-17

Date Updated: 2026-07-16

...
...

The FBI and CISA advisory describes confirmed attacks in which threat actors chained four Ivanti Cloud Service Appliance vulnerabilities (including zero-days) to achieve RCE, exfiltrate admin credentials, and install web shells across multiple organizations; it details two exploit chains (CVE-2024-8963 with CVE-2024-8190/9380 and with CVE-2024-9379), provides IoCs and detection notes, and urges immediate patching and mitigation measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.