Mandiant and national defenders reported active exploitation of two zero-day flaws in Ivanti Connect Secure and Ivanti Policy Secure gateways, identified as CVE-2023-46805 and CVE-2024-21887. The bugs allow an authentication bypass and command injection, and were used together in intrusions targeting internet-facing VPN appliances. Reporting linked the activity to a suspected China-nexus threat actor targeting Ivanti devices as an initial access vector.
Attackers used the exploit chain to steal configuration data, modify files, establish a remote tunnel from compromised VPN devices, evade integrity checks, and deploy a backdoor by altering a legitimate CGI file. Affected versions included 9.x and 22.x releases of the Ivanti products, and Ivanti issued a mitigation file, mitigation.release.20240107.1.xml, as a recommended defensive measure while organizations worked to contain compromised gateways and assess follow-on access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Ivanti provided the mitigation file mitigation.release.20240107.1.xml as a recommended defensive measure for affected Ivanti Connect Secure and Policy Secure versions 9.x and 22.x. The mitigation was offered in response to the active exploitation of the two zero-days.
The exploitation activity described in the reporting was attributed to a China-linked threat actor. This attribution accompanied reporting on the zero-day exploitation against Ivanti devices.
Ivanti disclosed CVE-2023-46805, an authentication bypass, and CVE-2024-21887, a command injection flaw, affecting Ivanti Connect Secure and Ivanti Policy Secure gateways. The disclosure stated the vulnerabilities were being actively exploited in the wild.
Attackers were reported to chain the two Ivanti vulnerabilities to steal configuration data, modify files, create a remote tunnel from VPN devices, evade integrity checks, and implant a backdoor in a legitimate CGI file. Mandiant described the activity as suspected APT exploitation targeting Ivanti Connect Secure VPN appliances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.