-1.2 C
London
Friday, January 10, 2025
HomeTechnologyCyber SecurityIvanti VPN Zero-Day Exploited in Global Attacks

Ivanti VPN Zero-Day Exploited in Global Attacks

Date:

Related stories

15 CES 2025 Devices Already Available For Purchase

CES 2025 is almost over, and in the last...

VLC Media Player Hits 6 Billion Downloads, Unveils AI-Powered Subtitle Feature

VLC media player, a popular open-source software, has achieved...

Elon Musk’s xAI Tests Standalone Grok Chatbot App

Elon Musk's artificial intelligence company, xAI, is venturing into...

Google Deep Research: What Sets It Apart From Other AI Research Tools

In recent weeks, there has been a flurry of...

CES Products Raise Privacy and Waste Concerns

Privacy advocates criticize CES products for data risks and waste concerns, urging better consumer protection and sustainability.
spot_imgspot_img

Ivanti, a prominent U.S. software provider, has issued a critical warning regarding a zero-day vulnerability in its widely used enterprise VPN appliances.This vulnerability tracked as CVE-2025-0282, has been actively exploited by threat actors to compromise the networks of numerous corporate customers.

The vulnerability, residing within Ivanti’s Connect Secure, Policy Secure, and ZTA Gateways products, allows attackers to remotely execute malicious code without requiring authentication.Ivanti emphasizes that Connect Secure, its remote-access VPN solution, boasts widespread adoption across various industries and organizations of all sizes.

This incident marks the latest security breach targeting Ivanti’s products in recent years. Following a series of mass hack incidents in 2024, Ivanti committed to overhauling its security processes. However, this recent exploitation underscores the company’s ongoing challenges in safeguarding its customers.

“This vulnerability is of significant concern as the attacks have ‘all the hallmarks of [an advanced persistent threat] usage of a zero-day against a mission-critical appliance,'”

stated Ben Harris, CEO of security research firm watchTowr Labs, in an email to TechCrunch.

“We urge everyone to take this seriously.”

The U.K.’s National Cyber Security Centre has confirmed active exploitation within U.K. networks, while the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its catalogue of known-exploited vulnerabilities.Ivanti has released a patch for Connect Secure, with patches for Policy Secure and ZTA Gateways scheduled for January 21st.

This incident highlights the critical importance of robust cybersecurity measures and the ongoing threat posed by sophisticated cyberattacks targeting critical infrastructure.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here