• Автор темы News
  • Дата начала
  • " /> News - Ongoing attacks on Ivanti VPNs install a ton of sneaky, well-written malware | SoftoolStore.de - Программное обеспечение, Avid Media Composer, Книги, Новости, Windows, Интернет-новости, Бесплатные прокси (HTTP, Socks 4, Socks 5)

    News Ongoing attacks on Ivanti VPNs install a ton of sneaky, well-written malware

    News

    Команда форума
    Редактор
    Регистрация
    17 Февраль 2018
    Сообщения
    32 821
    Лучшие ответы
    0
    Баллы
    2 093
    Offline
    #1
    Networks protected by Ivanti VPNs are under active attack by well-resourced hackers who are exploiting a critical vulnerability that gives them complete control over the network-connected devices.

    Hardware maker Ivanti disclosed the vulnerability, tracked as CVE-2025-0283, on Wednesday and warned that it was under active exploitation against some customers. The vulnerability, which is being exploited to allow hackers to execute malicious code with no authentication required, is present in the company’s Connect Secure VPN, and Policy Secure & ZTA Gateways. Ivanti released a security patch at the same time. It upgrades Connect Secure devices to version 22.7R2.5.

    Well-written, multifaceted


    According to Google-owned security provider Mandiant, the vulnerability has been actively exploited against “multiple compromised Ivanti Connect Secure appliances” since December, a month before the then zero-day came to light. After exploiting the vulnerability, the attackers go on to install two never-before-seen malware packages, tracked under the names DRYHOOK and PHASEJAM on some of the compromised devices.

    Read full article

    Comments
     
    Сверху Снизу