Get the latest tech news

Ivanti patches two zero-days under attack, but finds another


Germany's cybersecurity authority said the new two flaws — one of them a zero-day — "put all previously mitigated systems at risk again."

Ivanti warned on Wednesday that hackers are exploiting another previously undisclosed zero-day vulnerability affecting its widely used corporate VPN appliance. Cybersecurity companies Volexity and Mandiant previously attributed the exploitation of the initial round of Connect Secure bugs to a China government-backed hacking group motivated by espionage. Ivanti is now advising that customers “factory reset their appliance before applying the patch to prevent the threat actor from gaining upgrade persistence in your environment.”

Get the Android app

Or read this on TechCrunch

Read more on:

Photo of Days

Days

Photo of attack

attack

Photo of Ivanti

Ivanti

Related news:

News photo

Ivanti warns of new Connect Secure zero-day exploited in attacks

News photo

AI poisoning tool Nightshade received 250,000 downloads in 5 days: ‘beyond anything we imagined’

News photo

Microsoft Teams hit by second outage in three days