Ivanti Connect Secure flaw massively exploited by attackers (CVE-2024-21893)Help Net Security·Feb 7, 00:00 UTC · Feb 7, 2024VulnerabilityCVE-2024-21893CVE-2024-21888CVE-2023-46805+1 CVEs60
Attackers injected novel DSLog backdoor into 670 vulnerable Ivanti devices (CVE-2024-21893)Help Net Security·Feb 15, 11:46 UTC · Feb 15, 2024VulnerabilityCVE-2024-21893CVE-2024-21888CVE-2023-46805+1 CVEs60
Experts warn of a surge of attacks targeting Ivanti SSRF flawSecurity Affairs·Feb 5, 19:29 UTC · Feb 5, 2024Exploit / PoC in the wildCVE-2024-21893CVE-2024-2188860
Latest Ivanti Zero Day Exploited By Scores of IPsInfosecurity Magazine·Feb 6, 11:00 UTC · Feb 6, 2024Exploit / PoC in the wildCVE-2024-21893CVE-2023-46805CVE-2024-21887+2 CVEs60
Ivanti warns of a new actively exploited zeroSecurity Affairs·Jan 31, 14:37 UTC · Jan 31, 2024Exploit / PoC in the wildCVE-2024-21888CVE-2024-21893CVE-2023-46805+1 CVEs60
New Ivanti Vulnerability Observed as Widespread Security Concerns GrowInfosecurity Magazine·Feb 16, 15:45 UTC · Feb 16, 2024Vulnerability in the wildCVE-2024-22024CVE-2023-46805CVE-2024-21887+2 CVEs60
Ivanti warns of a new auth bypass flaw in its Connect Secure, Policy Secure, and ZTA gateway devicesSecurity Affairs·Feb 9, 08:17 UTC · Feb 9, 2024Exploit / PoC in the wildCVE-2024-22024CVE-2023-46805CVE-2024-21887+2 CVEs60
As if 2 Ivanti vulnerabilities under exploit weren’t bad enough, now there are 3Ars Technica · Security·Feb 6, 02:30 UTC · Feb 6, 2024Vulnerability in the wildCVE-2024-21893CVE-2023-46805CVE-2024-2188760
CISA orders federal agencies to disconnect Ivanti VPN instances by February 2Security Affairs·Feb 1, 19:46 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Five Eyes alliance warns of attacks exploiting known Ivanti Gateway flawsSecurity Affairs·Mar 1, 14:01 UTC · Mar 1, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-21893+2 CVEs60
Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New MalwareThe Hacker News·Feb 29, 07:05 UTC · Feb 29, 2024Malware in the wildCVE-2024-21893CVE-2024-2188760
Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA GatewaysThe Hacker News·Feb 10, 06:48 UTC · Feb 10, 2024Vulnerability in the wildCVE-2024-22024CVE-2023-46805CVE-2024-21887+2 CVEs60
Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass ExploitationThe Hacker News·Feb 6, 14:36 UTC · Feb 6, 2024Exploit / PoC in the wildCVE-2024-21893CVE-2024-21887CVE-2023-36661+1 CVEs60
Alert: Ivanti Discloses 2 New ZeroThe Hacker News·Feb 1, 03:20 UTC · Feb 1, 2024Exploit / PoCCVE-2024-21888CVE-2024-21893CVE-2023-46805+1 CVEs160
Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security FlawsThe Hacker News·Apr 6, 09:12 UTC · Apr 6, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Chinese Groups Deploy New TTPs to Exploit Ivanti VulnerabilitiesInfosecurity Magazine·Apr 5, 15:00 UTC · Apr 5, 2024VulnerabilityCVE-2023-46805CVE-2024-21887CVE-2024-2189347
Week in review: AnyDesk phishing campaign targets employees, Microsoft fixes exploited zero-daysHelp Net Security·Feb 18, 00:00 UTC · Feb 18, 2024Exploit / PoC in the wildCVE-2024-21762CVE-2024-23313CVE-2023-43770+5 CVEs160
Ivanti Vulnerability Exploited to Install 'DSLog' Backdoor on 670+ IT InfrastructuresThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Vulnerability in the wildCVE-2024-21893CVE-2024-2188860
Ivanti Pulse Secure Found Using 11-YearThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21893+1 CVEs60
Week in review: 10 must-read cybersecurity books, AnyDesk hack, Patch Tuesday forecastHelp Net Security·Feb 11, 00:00 UTC · Feb 11, 2024VulnerabilityCVE-2024-23832CVE-2024-21893CVE-2024-23917160
Agencies using vulnerable Ivanti products have until Saturday to disconnect themArs Technica · Security·Feb 1, 23:45 UTC · Feb 1, 2024Vulnerability in the wildCVE-2024-21888CVE-2024-2189360
Ivanti Releases ZeroInfosecurity Magazine·Feb 1, 09:30 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Two new Ivanti bugs discovered as CISA warns of hackers bypassing mitigationsThe Record·Jan 31, 22:21 UTC · Jan 31, 2024AdvisoryCVE-2024-21888CVE-2024-21893CVE-2023-46805+1 CVEs60
State-sponsored hackers know enterprise VPN appliances inside outHelp Net Security·Apr 23, 13:45 UTC · Apr 23, 2026Threat actorCVE-2024-2189360
Attackers hit security device defects hard in 2024CyberScoop·Apr 24, 14:36 UTC · Apr 24, 2025RansomwareCVE-2024-3400CVE-2023-46805CVE-2024-21887+2 CVEs60
Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber AttackThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2025Vulnerability in the wildCVE-2017-0929CVE-2020-7796CVE-2021-21973+7 CVEs60
Experts warn of a coordinated surge in the exploitation attempts of SSRF vulnerabilitiesSecurity Affairs·Mar 13, 14:31 UTC · Mar 13, 2025Vulnerability in the wildCVE-2020-7796CVE-2021-22214CVE-2021-39935+7 CVEs60
Exploit Attempts Recorded Against New MOVEit Transfer VulnerabilityThe Hacker News·Jul 1, 05:51 UTC · Jul 1, 2024Vulnerability in the wildCVE-2024-5806CVE-2024-5805CVE-2023-34362+3 CVEs60
CISA confirmed that CSAT environment was breached in JanuarySecurity Affairs·Jun 25, 05:59 UTC · Jun 25, 2024Data breachCVE-2023-46805CVE-2024-21887CVE-2024-2189350
Volt Typhoon and 4 other groups targeting US energy and defense sectors through Ivanti bugsThe Record·Apr 4, 16:40 UTC · Apr 4, 2024Threat actorCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Ivanti fixed for 4 new issues in Connect Secure and Policy SecureSecurity Affairs·Apr 4, 08:10 UTC · Apr 4, 2024Exploit / PoCCVE-2024-21894CVE-2024-22052CVE-2024-22053+5 CVEs60
Ivanti urges customers to fix critical RCE flaw in Standalone SentrySecurity Affairs·Mar 21, 09:59 UTC · Mar 21, 2024VulnerabilityCVE-2023-41724CVE-2023-46805CVE-2024-21887+1 CVEs60
Hackers leverage 1-day vulnerabilities to deliver custom Linux malwareHelp Net Security·Mar 12, 00:00 UTC · Mar 12, 2024VulnerabilityCVE-2022-24086CVE-2023-41265CVE-2023-41266+5 CVEs147
Magnet Goblin group used a new Linux variant of NerbianRAT malwareSecurity Affairs·Mar 11, 10:45 UTC · Mar 11, 2024MalwareCVE-2024-21887CVE-2022-24086CVE-2023-41265+5 CVEs35
Threat actors breached two crucial systems of the US CISASecurity Affairs·Mar 9, 23:25 UTC · Mar 9, 2024Data breachCVE-2023-46805CVE-2024-21887CVE-2024-2189350
CISA forced to take two systems offline last month after Ivanti compromiseThe Record·Mar 8, 18:33 UTC · Mar 8, 2024Data breachCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Five Eyes Agencies Warn of Active Exploitation of Ivanti Gateway VulnerabilitiesThe Hacker News·Mar 2, 04:02 UTC · Mar 2, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+2 CVEs60
Five Eyes Warn of Ivanti Vulnerabilities ExploitationInfosecurity Magazine·Mar 1, 12:00 UTC · Mar 1, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Spyware isn’t going anywhere, and neither are its tacticsCisco Talos·Feb 8, 19:00 UTC · Feb 8, 2024Malware in the wildCVE-2024-21893CVE-2024-2322260
Warning: New Malware Emerges in Attacks Exploiting Ivanti VPN VulnerabilitiesThe Hacker News·Feb 2, 04:53 UTC · Feb 2, 2024Vulnerability in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60