Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » CISA issues emergency directive to federal agencies regarding Ivanti zero-day vulnerability
    Cyber Security

    CISA issues emergency directive to federal agencies regarding Ivanti zero-day vulnerability

    techempireBy techempire2 Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 20, 2024Editorial DepartmentCybersecurity/Threat Intelligence

    CISA issues emergency directive

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on Friday urging Federal Civilian Executive Branch (FCEB) agencies to target two actively exploited zero-days in Ivanti Connect Secure (ICS) and Ivanti Policy Secure (IPS). Vulnerability implementation mitigation products.

    This development follows the widespread exploitation of authentication bypass (CVE-2023-46805) and code injection error (CVE-2024-21887) vulnerabilities by multiple threat actors. These flaws allow a malicious actor to craft malicious requests and execute arbitrary commands on the system.

    The US company acknowledged in an advisory report that there had been a “sharp increase in threat actor activity” since the flaw was publicly disclosed on January 11, 2024.

    Internet security

    “Successful exploitation of vulnerabilities in these affected products could allow malicious threat actors to move laterally, perform data exfiltration, and establish persistent system access, resulting in complete compromise of the target information system,” the agency said.

    Ivanti expects to release an update next week to address the flaws and has provided a workaround via an XML file that can be imported into affected products to make the necessary configuration changes.

    CISA urges organizations running ICS to apply mitigations and run external integrity checking tools to identify signs of compromise and, if found, disconnect them from the network and reset the device before importing the XML file.

    Additionally, FCEB entities are urged to revoke and reissue any stored credentials, reset administrator enablement passwords, store API keys, and reset the passwords of any local users defined on the gateway.

    Cybersecurity companies Volexity and Mandiant observed attacks exploiting these two flaws to deploy web shells and passive backdoors to gain persistent access to infected devices. To date, an estimated 2,100 devices worldwide have been compromised.

    Internet security

    The first wave of attacks identified in December 2023 was initiated by a Chinese nation-state group tracked as UTA0178. Mandiant is closely monitoring a campaign known as UNC5221, although it has not yet been linked to any specific organization or country.

    Threat intelligence firm GreyNoise said it had also observed the vulnerabilities being abused to remove persistent backdoors and XMRig cryptocurrency miners, suggesting bad actors would take advantage of these vulnerabilities for financial gain.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.