Ivanti Zero-Day Patches Delayed as 'KrustyLoader' Attacks Mount
The RCE/auth bypass bugs in Connect Secure VPNs have gone unpatched for 20 days as state-sponsored groups continue to backdoor Ivanti gear.
Stay updated with breaking news from Connect Secure. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
The RCE/auth bypass bugs in Connect Secure VPNs have gone unpatched for 20 days as state-sponsored groups continue to backdoor Ivanti gear.
Attackers have found workarounds to current mitigations for widely exploited vulnerabilities in Ivanti Connect Secure VPN devices, CISA said.
Germany's cybersecurity authority said the new two flaws — one of them a zero-day — "put all previously mitigated systems at risk again."
Ivanti VPN tools are being abused to drop malware
Ivanti has finally released the first round of patches for vulnerability-stricken Connect Secure and Policy Secure gateways, but in doing so has also found…