Beware Ivanti mitigations breached by clever threat actors | IT World Canada News

1 min read

TLDR: Cyber authorities in the U.S. and Australia have issued warnings that threat actors are finding ways to get around some mitigations put in place by Ivanti for its Connect Secure and Policy Secure Gateways. Ivanti has also discovered two new vulnerabilities in these devices. The vulnerabilities are CVE-2024-21888, which affects Policy Secure, and CVE-2024-21893, which affects supported versions of Connect Secure and Policy Secure Gateways. Ivanti has released a patch to address these vulnerabilities and is recommending that customers factory reset their appliances before applying the patch as an extra precaution. Threat actors have reportedly developed workarounds to some mitigation and detection methods, leading to ongoing exploitation activities. Cyber authorities are advising organizations to investigate and monitor systems for potential compromise.

Previous Story

Hot off the press: CrowdStrike, At-Bay, N-able, Veeam, Vade dominate MSSP market

Next Story

Taming rising cyber costs amid relentless threats—your ultimate guide

Latest from News