Jan. 24, 2024, 12:24 p.m. | Eswar

Cyber Security News cybersecuritynews.com

It was previously reported that Ivanti Connect Secure was vulnerable to an authentication bypass (CVE-2023-46805) and a command injection vulnerability (CVE-2024-21887) actively exploited by threat actors in the wild. Moreover, these vulnerabilities were added to the CISA’s known exploited vulnerability catalog, and all the FCEB agencies were informed to mitigate these vulnerabilities as soon as […]


The post Mass Exploitation of Ivanti VPN Exposes Corporate Networks to Hack Attacks appeared first on Cyber Security News.

actively exploited attacks authentication authentication bypass bypass catalog cisa command command injection connect corporate cve cve-2023-46805 cve-2024-21887 cyber security exploitation exploited fceb fceb agencies hack injection ivanti ivanti connect secure ivanti vpn known exploited networks threat threat actors vpn vulnerabilities vulnerability vulnerable

Offensive Security Engineering Technical Lead, Device Security

@ Google | Amsterdam, Netherlands

Senior Security Engineering Program Manager

@ Microsoft | Redmond, Washington, United States

Information System Security Analyst

@ Resource Management Concepts, Inc. | Dahlgren, Virginia, United States

Critical Facility Security Officer - Evening Shift

@ Allied Universal | Charlotte, NC, United States

Information System Security Officer, Junior

@ Resource Management Concepts, Inc. | Patuxent River, Maryland, United States

Security Engineer

@ JPMorgan Chase & Co. | Plano, TX, United States