Two zero-days in Ivanti products actively exploited by threat actor
Two vulnerabilities in Ivanti Connect Secure VPN devices can be chained together by a threat actor to craft malicious requests and execute arbitrary commands on the system.
Stay updated with breaking news from Policy Secure. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Two vulnerabilities in Ivanti Connect Secure VPN devices can be chained together by a threat actor to craft malicious requests and execute arbitrary commands on the system.
Volexity researchers attribute attacks to Chinese actors.
Ivanti has disclosed two Connect Secure (ICS) and Policy Secure zero-days exploited in the wild that can let remote attackers execute arbitrary commands on…
Security experts believe Chinese nation-state attackers are actively exploiting two zero-day vulnerabilities in security products made by Ivanti. If you're an…
IT administrators with Ivanti's Connect Secure/Pulse Secure VPNs and Policy Secure gateways are urged to install mitigations immediately. The mitigations are to temporarily deal with two vulnerabilities (CVE-2023-46805, an authentication bypass and CVE-2024-21887, a command injection) that impact all supported versions of these products. If they are chained together, "exploitation does not require authentication and