Update from the Trenches
ID: c97f49dc-e995-5eef-bf66-4c158ecf6a78
STIX ID: report--c97f49dc-e995-5eef-bf66-4c158ecf6a78
Feed Name: Security Boulevard
GuidePoint Security reports active exploitation of multiple high- and critical-severity Ivanti CSA vulnerabilities (including a critical path traversal CVE-2024-8963 and public POC for CVE-2024-8190) since early September 2024; attackers have uploaded webshells, executed native tools (nc, curl), performed tunneling and scanning, and achieved lateral movement into Windows hosts using DLL side-loading, services, and scheduled tasks. The report documents approximately 379 potentially vulnerable public appliances and 88 appliances with at least one webshell, provides IOCs and audit/log triage commands, and recommends preserving forensic artifacts and rebuilding appliances from patched images.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
