logo

MITRE Corporation Breached by Nation-State Hackers Exploiting Ivanti Flaws

ID: b69594c4-1bea-55b2-9c10-0731b2d25f54

STIX ID: report--b69594c4-1bea-55b2-9c10-0731b2d25f54

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-04-22

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

MITRE disclosed that beginning in January 2024 it was targeted by a nation-state actor that exploited two Ivanti Connect Secure zero-days (CVE-2023-46805 and CVE-2024-21887) to bypass authentication through session hijacking, gain access to its NERVE research network, move laterally into VMware using a compromised admin account, and deploy backdoors and web shells; Volexity attributes the initial exploitation to China-linked UTA0178 and other China-nexus groups have since exploited the same flaws, while MITRE says its core enterprise network and partners appear unaffected and containment and forensic response actions are underway.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.