There's a "reasonable chance" that Ivanti Connect Secure (ICS) VPN users are already compromised if they didn't apply the vulnerability mitigation released last week, experts say. The latest data from Volexity shows that successful exploits of two Ivanti zero-days have accelerated sharply to more than 1,700 devices. Citing the new figures, Christopher Glyer, principal security researcher at Microsoft Threat Intelligence Center, said: "If you didn't apply Ivanti Connect Secure VPN mitigation on January 10, reasonable chance you were exploited – mass exploitation by same actor started on January 11 and compromised at least 1,700 devices." Mandiant's report on January 11, a day after the initial disclosure, noted that fewer than 20 devices were compromised at the time, which underlines how quickly the attacks have escalated. There's also evidence to suggest that attackers beyond the group responsible now have their hands on a working exploit, which might offer a partial explanation for the shift toward mass exploitation. The new wave of attacks are against everything from small businesses to some of the largest in the world, including multiple Fortune 500 companies, according to Volexity. Victims range from governments, militaries, telcos, tech companies, financial services firms, and aerospace, among others. The vast majority of the successful compromises are being pinned to UTA0178 – a group Volexity believes to have a nexus in China, although Mandiant has said there isn't eno...
Ivanti 0-day exploits pwn Fortune 500 firms, thousands more
The Register
·Connor Jones
·Published Jan 16, 2024
·Updated
Affected Software
1 affected component
Ivanti Connect Secure (ICS) VPN
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses recent zero-day exploits targeting Ivanti Connect Secure (ICS) VPN that have affected numerous Fortune 500 companies.
2
What security implications are discussed?
Experts warn that there is a significant likelihood that Ivanti Connect Secure VPN users are already compromised if they have not applied the recent vulnerability mitigation.
3
What products or software are affected?
The affected software is Ivanti Connect Secure (ICS) VPN.
4
What actions should users take to protect themselves?
Users are advised to apply the recently released vulnerability mitigation to safeguard against these exploits.
5
How widespread is the impact of these exploits?
The exploits have impacted Fortune 500 firms and potentially thousands of other organizations using the Ivanti Connect Secure VPN.