MITRE Corporation Breached by Nation-State Hackers Exploiting Ivanti Flaws
ID: b69594c4-1bea-55b2-9c10-0731b2d25f54
STIX ID: report--b69594c4-1bea-55b2-9c10-0731b2d25f54
Feed Name: The Hacker News
MITRE disclosed that beginning in January 2024 it was targeted by a nation-state actor that exploited two Ivanti Connect Secure zero-days (CVE-2023-46805 and CVE-2024-21887) to bypass authentication through session hijacking, gain access to its NERVE research network, move laterally into VMware using a compromised admin account, and deploy backdoors and web shells; Volexity attributes the initial exploitation to China-linked UTA0178 and other China-nexus groups have since exploited the same flaws, while MITRE says its core enterprise network and partners appear unaffected and containment and forensic response actions are underway.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
