CISA Issues Emergency Directive to Federal Agencies on Ivanti Zero-Day Exploits
ID: a1843dab-a365-554a-8c36-fec089005c8f
STIX ID: report--a1843dab-a365-554a-8c36-fec089005c8f
Feed Name: The Hacker News
CISA issued an emergency directive after two zero-day flaws in Ivanti Connect Secure and Ivanti Policy Secure (an authentication bypass and a code injection bug) were widely exploited in the wild; attackers — including a Chinese nation-state-linked cluster and opportunistic actors — have used the bugs to deploy web shells, persistent backdoors and XMRig miners, with thousands of exposed hosts and hundreds of confirmed compromises, and Ivanti providing temporary XML mitigations until patches are released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
