"US Agencies Given 48 Hours to Disconnect Flawed Ivanti VPN Tech"

1 min read
Source: TechCrunch
"US Agencies Given 48 Hours to Disconnect Flawed Ivanti VPN Tech"
Photo: TechCrunch
TL;DR

The U.S. cybersecurity agency CISA has ordered federal agencies to disconnect all Ivanti VPN appliances within 48 hours due to the serious threat posed by multiple zero-day vulnerabilities being actively exploited by malicious hackers. This directive comes after Ivanti uncovered a third zero-day flaw and security researchers identified Chinese state-backed hackers exploiting at least two of the vulnerabilities. CISA has instructed agencies to disconnect the affected products, continue threat hunting, and monitor authentication services, while providing instructions for restoring Ivanti appliances to online operation. Ivanti has made patches available for some affected software versions and urged customers to factory reset appliances before patching to prevent hackers from gaining persistence on their network.

Share this article

Want the full story? Read the original reporting

Read on TechCrunch