JDMeister
Forum Moderator
- May 1, 2021
- 49,695
- 25,881
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Federal cybersecurity authorities are worried about several zero-day vulnerabilities in gateways from IT company Ivanti.
An investigation by Ivanti has verified the issues, the company said, and it is working to release patches and mitigations. Hackers can exploit two newly found flaws to take over affected systems, warned the Cybersecurity and Infrastructure Security Agency (CISA). Threat actors have also been exploiting flaws to steal credentials or drop webshells that set them up to conduct further compromises.
CISA has ordered federal civilian executive branch agencies to disconnect all the effected Ivanti solutions from their networks. It has also told agencies to search and monitor for potential malicious activity related to the vulnerabilities and apply upgrades, among other response efforts. And while CISA cannot extend its emergency order to all users, the federal cybersecurity agency said it “strongly encourages all organizations” to review that guidance and follow the parts relevant to them.