Feb. 9, 2024, 8:10 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

A new vulnerability has been disclosed in certain versions of Ivanti’s Connect Secure VPN and Ivanti Policy Secure appliances.


This latest flaw (CVE-2024-22024), described by Ivanti as an XML external entity or XXE flaw, stems from the SAML component of Connect Secure, Ivanti Policy Secure and ZTA gateways. If exploited, the flaw could enable an attacker to access certain restricted resources without authentication.


“A patch is available now for Ivanti Connect Secure (versions 9.1R14.5, 9.1R17.3, 9.1R18.4, 22.4R2.3, 22.5R1.2, 22.5R2.3 and …

connect connect secure cve cve-2024-22024 exploited external flaw gateways ivanti ivanti policy secure latest new vulnerability policy policy secure saml secure vpn vpn vulnerability xml xxe zta zta gateways

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Network Security Engineer

@ Meta | Menlo Park, CA | Remote, US

Security Engineer, Investigations - i3

@ Meta | Washington, DC

Threat Investigator- Security Analyst

@ Meta | Menlo Park, CA | Seattle, WA | Washington, DC

Security Operations Engineer II

@ Microsoft | Redmond, Washington, United States

Engineering -- Tech Risk -- Global Cyber Defense & Intelligence -- Bug Bounty -- Associate -- Dallas

@ Goldman Sachs | Dallas, Texas, United States