logo

Chinese Hackers Exploit Zero-Day Flaws in Ivanti Connect Secure and Policy Secure

ID: 75a58956-7a75-5aad-bdd5-18e5b7b81ffd

STIX ID: report--75a58956-7a75-5aad-bdd5-18e5b7b81ffd

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-01-11

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Volexity and Ivanti reported that two zero-day vulnerabilities in Ivanti Connect Secure and Policy Secure (CVE-2023-46805 and CVE-2024-21887) were chained and exploited in the wild by a suspected China-linked actor (UTA0178) to gain unauthenticated command execution, steal credentials, modify appliance files (including compcheck.cgi), deploy a GLASSTOKEN web shell for persistence, and pivot to internal networks; CISA added the vulnerabilities to its KEV catalog and Ivanti advised mitigations pending patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.