Brief

Summary:

A joint advisory has been released by the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and other international authorities to provide guidance on detecting exploitation activity, recommended actions, and mitigations related to the active exploitation of multiple vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. The advisory provides technical details on observed tactics used by threat actors and indicators of compromise to help organizations detect malicious activity. The vulnerabilities, including CVE-2023-46805, CVE-2024-21887, and CVE-2024-21893, can be used to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges, allowing lateral movement, data exfiltration, and persistent access on a target network. Organizations are urged to exercise due caution, patch, and take other recommended actions to address the vulnerability, especially those in critical infrastructure sectors.

February 29, 2024,   Advisory provides guidance for detecting exploitation activity, recommended actions and mitigations, and novel post-exploitation findings WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing & Analysis Center (MS-ISAC), Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), United Kingdom’s National Cyber Security Centre

This content is restricted.

Highlights content goes here...

February 29, 2024,   Advisory provides guidance for detecting exploitation activity, recommended actions and mitigations, and novel post-exploitation findings WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing & Analysis Center (MS-ISAC), Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), United Kingdom’s National Cyber Security Centre

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies