News
This VPN has problems: attacked by hackers and issues for its users
The patches for Ivanti's VPN devices have not been published yet.
- January 25, 2024
- Updated: March 7, 2024 at 1:09 PM
A group of hackers that could work for the Chinese Government has exploited two serious vulnerabilities in Ivanti VPN devices to infect networks worldwide. These vulnerabilities would allow attackers to bypass two-factor authentication and execute malicious code on systems using Ivanti Connect Secure, a very popular VPN.
According to the security company Censys, at least 492 Ivanti VPN devices would be infected, out of a total of 26,000 that are connected to the Internet. The company claims that more than a quarter of the compromised devices are located in the United States.
Ivanti has not yet released patches to fix these vulnerabilities, known as CVE-2023-46805 and CVE-2024-21887. The company has published a mitigation and recovery guide that affected users are recommended to follow. The United States Cybersecurity and Infrastructure Security Agency has issued a directive that requires all civilian government agencies to take corrective actions to prevent the exploitation of these vulnerabilities.
Thanks to these vulnerabilities, hackers could steal data, modify files, download remote files, and create reverse tunnels from VPN devices, as detailed by Censys. They could also capture user credentials who connect to the VPN.
Publicist and audiovisual producer in love with social networks. I spend more time thinking about which videogames I will play than playing them.
Latest from Pedro Domínguez
You may also like
Samsung Vs Apple: The Smartphone Battle Heats Up- And Other Compelling Stats You Can’t Miss
Read more
iOS 18.2 and ChatGPT: This is everything we can do
Read more
It's already Christmas in GTA Online: access new bonuses and gifts
Read more
Dune: Prophecy is renewed for a second season on Max
Read more
Clint Eastwood’s latest movie finally arrives on Max; why should you watch it?
Read more
The ChatGPT app is updated on Mac and PC: these are its new abilities
Read more