iTWire - Volexity finds two zero-days being exploited in Ivanti Connect Secure VPN
Security firm Volexity says it has discovered active exploitation of two zero-day vulnerabilities in Ivanti Connect Secure VPN, with the two flaws bei...
Stay updated with breaking news from Pulse Secure. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Security firm Volexity says it has discovered active exploitation of two zero-day vulnerabilities in Ivanti Connect Secure VPN, with the two flaws bei...
Hackers possibly connected to the Chinese government since December have exploited two zero-days in a VPN from software developer Ivanti that is widely used by
IT administrators with Ivanti's Connect Secure/Pulse Secure VPNs and Policy Secure gateways are urged to install mitigations immediately. The mitigations are to temporarily deal with two vulnerabilities (CVE-2023-46805, an authentication bypass and CVE-2024-21887, a command injection) that impact all supported versions of these products. If they are chained together, "exploitation does not require authentication and
Hackers possibly connected to the Chinese government since December have exploited two zero-days in a VPN from software developer Ivanti that is widely used by
Federal regulators accused SolarWinds and CISO Tim Brown of fraud and internal control failures for misleading investors about the company's cybersecurity practices