- CISA and FBI emit new warning about old Ivanti -deficiencies
- They claim the deficiencies are abused in coordinated attacks
- Bugs were patched in September and October 2024, so update now
Security error in Ivanti Cloud Service Appliance (CSA), discovered and patched in September and October 2024, is still used to violate Networks, a new security advice from US cyber security and infrastructure security agency (CISA), and the FBI has warned.
In the advisory, the two agencies claim threat actors, who link four vulnerabilities to a chain: CVE-2024-8963 and CVE-2024-8190 and two in another: CVE-2024-9379 and CVE-20124- 9380.
“The threat actors link the vulnerabilities to gain initial access, carry out Remote Code Execution (RCE), get credentials and implant webshells on sacrificial networks,” the two agencies said.
Compromised credentials
All of these deficiencies were abused while zero -days – and at that time Cisa added them to his catalog of exploited vulnerabilities (KEV), forcing federal agencies to patch up within three weeks. Therefore, it is safe to assume that most of the newer victims are in the private sector.
The agencies have once again repeated their previous calls for upgrades and called for network administrators to be looking for signs of compromise.
“Legitimation information and sensitive data stored in the affected Ivanti appliances must be considered compromised,” they added. “Organizations must collect and analyze logs and artifacts for malicious activity and apply the recommendations for event response within this advice.”
Ivanti is an American IT software company that specializes in IT security, service management, capital management and more. From 2023, Ivanti employed approximately 3,070 people, claiming that more than 40,000 organizations around the world use its services.
By 2024, Ivanti experienced several cyber security events, including a January 2024 report indicating that Chinese government hackers were using their software to target organizations. Such a group is traced as UNC5221 and is believed to have compromised thousands of Ivanti VPN units where CISA was among the victims.
Via Bleeping computer