Jan. 10, 2024, 7:05 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


Volexity has uncovered active in-the-wild exploitation of two vulnerabilities allowing unauthenticated remote code execution in Ivanti Connect Secure VPN devices. An official security advisory and knowledge base article have been released by Ivanti that includes mitigation that should be applied immediately. However, a mitigation does not remedy a past or ongoing compromise. Systems should simultaneously be thoroughly analyzed per details in this post to look for signs of a breach.


During the second week of December 2023, Volexity detected suspicious …

advisory article base code code execution connect devices exploitation ivanti knowledge knowledge base mitigation official remedy remote code remote code execution secure vpn security security advisory unauthenticated uncovered volexity vpn vulnerabilities zero-day zero-day vulnerabilities

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC