Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days

Industry news
Post Reply
rbc
President
Posts: 291
Joined: Mon Oct 30, 2023 1:32 am
Location: Vicksburg, MS
ISC2 Member Status: Yes
Contact:

Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days

Post by rbc »

Malware hunters at Volexity on Wednesday warned that suspected Chinese nation-state hackers are actively exploiting a pair of unauthenticated remote zero-day vulnerabilities in Ivanti Connect Secure VPN devices.

The vulnerabilities, tracked as CVE-2023-46805 and CVE-2024-21887, affect fully patched Internet-facing Ivanti Connect Secure VPN appliances (formerly known as Pulse Secure) and were caught during in-the-wild zero-day exploitation.

Ivanti, a company that has struggled with major security problems, released pre-patch mitigations for the new vulnerabilities but said comprehensive fixes will be released on a staggered schedule beginning on January 22.
[...]
Volexity Catches Chinese Hackers Exploiting Ivanti VPN Zero-Days
Robert B. Carleton + ISC2 Central Mississippi President
Post Reply