ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

SentinelOne Warns Cybersecurity Vendors of Chinese Attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-8190
OS Command Injection RCE in Ivanti Cloud Services Appliance 4.6

Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before contain an OS command injection flaw (CWE-78) that allows a remote, authenticated attacker to achieve remote code execution. The attacker must already hold administrator-level privileges on the appliance, and exploitation is triggered by sending crafted input to the appliance over the network. Successful exploitation yields arbitrary command execution on the CSA, and related reporting indicates nation-state actors have been exploiting Ivanti CSA flaws for network infiltration, including attacks on French government and telecom targets. Only organizations still running CSA 4.6.x are affected, and that product line has reached end-of-life and will not receive further security updates. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-13 and carries a very high EPSS score (88.5%, 100th percentile), signaling confirmed and likely ongoing exploitation in the wild.

Do: Because CSA 4.6.x has reached end-of-life, remove CSA 4.6.x from service or migrate to the supported 5.0.x line, as future 4.6.x flaws are unlikely to receive fixes. Given confirmed nation-state exploitation, hunt for signs of compromise such as unexpected admin sessions, processes, or network tunnels, and restrict internet exposure of any remaining 4.6.x appliances in the interim.

7.289% KEV
  • Ivanti Cloud Services Appliance 4.6 through Patch 518 (versions 4.6 Patch 518 and before)
moderateroughly 1,000–2,000 internet-exposed CSA appliances (public internet scan counts)
CVE-2024-8963
Unauthenticated Path Traversal in Ivanti Cloud Services Appliance

CVE-2024-8963 is a path traversal vulnerability (CWE-22) in the Ivanti Cloud Services Appliance (CSA), a virtual appliance used to remotely manage Ivanti Endpoint Manager environments. A remote, unauthenticated attacker can send crafted requests containing directory traversal sequences to reach restricted functionality without any credentials. Successful exploitation grants access to restricted (including administrative) functions on the appliance, and public reporting indicates it has been chained with other CSA zero-day flaws by nation-state attackers to infiltrate networks. All CSA 4.6.x releases before Patch 519 are affected, and the 4.6.x product line has reached end-of-life, meaning future 4.6.x vulnerabilities will not receive fixes. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-19, and multiple outlets report Chinese-linked actors exploiting CSA zero-days against French government, telecom and other critical-infrastructure targets.

Do: Upgrade CSA 4.6.x to Patch 519 or later, or move to the supported 5.0.x line; because 4.6.x is end-of-life, CISA urges removing CSA 4.6.x from service or migrating to 5.0.x rather than relying on future 4.6.x patches. Until patched, restrict or remove internet exposure of CSA appliances and review logs for unauthenticated access to restricted functionality, since this flaw is being chained with other CSA vulnerabilities in targeted intrusions.

9.199% KEV
  • Ivanti Cloud Services Appliance (CSA) CSA 4.6.x before 4.6 Patch 519
moderate≈1,000–2,000 internet-exposed CSA appliances (order of magnitude; installed base larger if internal-only deployments are counted)
Full article483 words · extracted from infosecurity-magazine.com · click to collapse

SentinelOne has urged greater industry transparency and collaboration after warning that cybersecurity vendors represent a growing target for threat actors.

The cybersecurity vendor made the plea after revealing more information about two related operations it said were carried out by China-nexus actors.

The first, dubbed “PurpleHaze,” was linked to APT15 and UNC5174 and occurred in October 2024. APT15 (aka Ke3Chang and Nylon Typhoon) is a suspected Chinese cyber-espionage actor known for targeting critical infrastructure, while UNC5174 is described as an initial access broker and contractor for the Chinese government.

The attack took the form of “remote connections to internet-facing SentinelOne servers for reconnaissance,” the firm said.

Read more on Chinese threats: Chinese State Hackers Exploiting Newly Disclosed Ivanti Flaw

SentinelOne added that other victims of the same campaign, including a South Asian government entity, were hit with the GOREshell backdoor and publicly available tools developed by security research community The Hacker’s Choice (THC). The actors also exploited chained Ivanti zero days CVE-2024-8963 and CVE-2024-8190 for initial access.

“We track some of the infrastructure used in this intrusion as part of an operational relay box (ORB) network used by several suspected Chinese cyber-espionage actors, particularly a threat group that overlaps with public reporting on APT15,” the report continued.

“The use of ORB networks is a growing trend among Chinese threat groups, since they can be rapidly expanded to create a dynamic and evolving infrastructure that makes tracking cyber-espionage operations and their attribution challenging.”

The second intrusion attempt at SentinelOne was part of broader activity that took place between July 2024 and March 2025, impacting as many as 70 organizations worldwide.

Attributed to APT41, it deployed the ShadowPad backdoor platform, obfuscated by ScatterBrain, to target a SentinelOne supplier – an IT services and logistics company – in an attempted supply chain attack.

“We suspect that the most common initial access vector involved the exploitation of Check Point gateway devices, consistent with previous research on this topic,” SentinelOne said.

“We also observed communication to ShadowPad C2 servers originating from Fortinet Fortigate, Microsoft IIS, SonicWall, and CrushFTP servers, suggesting potential exploitation of these systems as well.”

A Warning for the Security Industry

The security vendor urged its peers to be alert to similar attacks.

“The activities detailed in this research reflect the strong interest these actors have in the very organizations tasked with defending digital infrastructure,” it concluded.

“Our findings underscore the critical need for constant vigilance, robust monitoring, and rapid response capabilities.”

Craig Jones, VP of security operations at Ontinue, said the report presented as classic China-nexus activity.

“It echoes exactly what was tracked during the Pacific Rim attacks when I led the defense activity at Sophos,” he added.

“Back then, we saw the same playbook: highly targeted operations, stealthy implants on edge devices, and a relentless focus on long-term access to high-value infrastructure. This isn’t new – it’s a continuation of a well-honed strategy.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/sentinelone-cybersecurity-vendors/