logo

VPN flaws allowed Chinese hackers to compromise dozens of Ivanti customers, says report

ID: 00ed4ba9-33fe-5f7f-8a3c-fb5484cfd5f9

STIX ID: report--00ed4ba9-33fe-5f7f-8a3c-fb5484cfd5f9

Feed Name: TechCrunch Security News

Threat Score
88/100

Date Published: 2026-02-23

Date Updated: 2026-04-23

Author: Lorenzo Franceschi-Bicchierai

...
...

Bloomberg reporting alleges Chinese state-sponsored hackers exploited known vulnerabilities in Pulse Secure (Ivanti) VPN software to install a backdoor that enabled access to at least 119 organizations, including military contractors; Mandiant was reportedly aware and CISA previously ordered federal agencies to disconnect Ivanti appliances after active exploitation. The piece also links security degradation to post-acquisition staffing cuts at Ivanti and notes additional, separate Ivanti VPN flaws that were later exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.