NSA says it’s tracking Ivanti cyberattacks as hackers hit US defense sector
ID: e6eb7ba1-15eb-5605-ab7f-78ca095fb2b6
STIX ID: report--e6eb7ba1-15eb-5605-ab7f-78ca095fb2b6
Feed Name: TechCrunch Security News
Threat Score
The report details mass exploitation of Ivanti Connect Secure VPN vulnerabilities by a suspected China-backed APT (UNC5325) targeting the U.S. defense sector and other industries; NSA and CISA confirm tracking and warn of root-level persistence techniques that may survive factory resets, while Mandiant and Akamai report widespread active exploitation and high volumes of attack attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
