Chinese Hackers Exploit Zero-Day Flaws in Ivanti Connect Secure and Policy Secure
ID: 75a58956-7a75-5aad-bdd5-18e5b7b81ffd
STIX ID: report--75a58956-7a75-5aad-bdd5-18e5b7b81ffd
Feed Name: The Hacker News
Volexity and Ivanti reported that two zero-day vulnerabilities in Ivanti Connect Secure and Policy Secure (CVE-2023-46805 and CVE-2024-21887) were chained and exploited in the wild by a suspected China-linked actor (UTA0178) to gain unauthenticated command execution, steal credentials, modify appliance files (including compcheck.cgi), deploy a GLASSTOKEN web shell for persistence, and pivot to internal networks; CISA added the vulnerabilities to its KEV catalog and Ivanti advised mitigations pending patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
