VPN flaws allowed Chinese hackers to compromise dozens of Ivanti customers, says report
ID: 00ed4ba9-33fe-5f7f-8a3c-fb5484cfd5f9
STIX ID: report--00ed4ba9-33fe-5f7f-8a3c-fb5484cfd5f9
Feed Name: TechCrunch Security News
Bloomberg reporting alleges Chinese state-sponsored hackers exploited known vulnerabilities in Pulse Secure (Ivanti) VPN software to install a backdoor that enabled access to at least 119 organizations, including military contractors; Mandiant was reportedly aware and CISA previously ordered federal agencies to disconnect Ivanti appliances after active exploitation. The piece also links security degradation to post-acquisition staffing cuts at Ivanti and notes additional, separate Ivanti VPN flaws that were later exploited.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
