• News/
  • https://www.theregister.com/2024/01/16/ivanti_zeroday_exploits_explode_into/

Ivanti 0-day exploits pwn Fortune 500 firms, thousands more

The Register
·
Connor Jones
·
Published Jan 16, 2024
·
Updated

There's a "reasonable chance" that Ivanti Connect Secure (ICS) VPN users are already compromised if they didn't apply the vulnerability mitigation released last week, experts say. The latest data from Volexity shows that successful exploits of two Ivanti zero-days have accelerated sharply to more than 1,700 devices. Citing the new figures, Christopher Glyer, principal security researcher at Microsoft Threat Intelligence Center, said: "If you didn't apply Ivanti Connect Secure VPN mitigation on January 10, reasonable chance you were exploited – mass exploitation by same actor started on January 11 and compromised at least 1,700 devices." Mandiant's report on January 11, a day after the initial disclosure, noted that fewer than 20 devices were compromised at the time, which underlines how quickly the attacks have escalated. There's also evidence to suggest that attackers beyond the group responsible now have their hands on a working exploit, which might offer a partial explanation for the shift toward mass exploitation. The new wave of attacks are against everything from small businesses to some of the largest in the world, including multiple Fortune 500 companies, according to Volexity. Victims range from governments, militaries, telcos, tech companies, financial services firms, and aerospace, among others. The vast majority of the successful compromises are being pinned to UTA0178 – a group Volexity believes to have a nexus in China, although Mandiant has said there isn't eno...

Read full article

Affected Software

1 affected component
Ivanti Connect Secure (ICS) VPN
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses recent zero-day exploits targeting Ivanti Connect Secure (ICS) VPN that have affected numerous Fortune 500 companies.

2

What security implications are discussed?

Experts warn that there is a significant likelihood that Ivanti Connect Secure VPN users are already compromised if they have not applied the recent vulnerability mitigation.

3

What products or software are affected?

The affected software is Ivanti Connect Secure (ICS) VPN.

4

What actions should users take to protect themselves?

Users are advised to apply the recently released vulnerability mitigation to safeguard against these exploits.

5

How widespread is the impact of these exploits?

The exploits have impacted Fortune 500 firms and potentially thousands of other organizations using the Ivanti Connect Secure VPN.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203