This content is restricted.
Brief
Summary:
The Cybersecurity Advisory (CSA) was released by CISA and its partners to alert organizations about the exploitation of multiple vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways by threat actors. The advisory highlights that these vulnerabilities, including CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893, can be exploited to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges. CISA has issued Emergency Directive 24-01 and Supplemental Direction, urging organizations to review the advisory and consider the significant risk of cyber threat actor access and persistence on these devices. The advisory provides detection methods, IOCs, and mitigation guidance to help defend against this activity. It is recommended to assume a threat actor is maintaining persistence and lying dormant before conducting malicious actions.
Highlights content goes here...
This content is restricted.