logo

Update from the Trenches

ID: c97f49dc-e995-5eef-bf66-4c158ecf6a78

STIX ID: report--c97f49dc-e995-5eef-bf66-4c158ecf6a78

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2024-10-09

Date Updated: 2026-04-22

Author: Hermes Bojaxhi

...
...

GuidePoint Security reports active exploitation of multiple high- and critical-severity Ivanti CSA vulnerabilities (including a critical path traversal CVE-2024-8963 and public POC for CVE-2024-8190) since early September 2024; attackers have uploaded webshells, executed native tools (nc, curl), performed tunneling and scanning, and achieved lateral movement into Windows hosts using DLL side-loading, services, and scheduled tasks. The report documents approximately 379 potentially vulnerable public appliances and 88 appliances with at least one webshell, provides IOCs and audit/log triage commands, and recommends preserving forensic artifacts and rebuilding appliances from patched images.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.