U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability
ID: 6c151fd2-a6f9-5476-98dc-64c9076aa18c
STIX ID: report--6c151fd2-a6f9-5476-98dc-64c9076aa18c
Feed Name: The Hacker News
The report describes active exploitation of critical Ivanti vulnerabilities (notably CVE-2023-35082 and high‑severity VPN flaws) that allow authentication bypass and remote code execution; attackers have used these to drop web shells and backdoors across many sectors worldwide, with over 2,100 devices observed compromised and a suspected Chinese actor (UTA0178) implicated. Rapid7, Volexity, Assetnote and others documented chaining and evasive modifications, while Ivanti and CISA have issued mitigations and advisories—organizations are urged to apply vendor fixes and rotate secrets after rebuilds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
