Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways
What it means
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Why it matters
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Recommended actions
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Potential operational benefits
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
Cybersecurity Advisory Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways Release Date February 29, 2024 Alert Code AA24-060B Related topics: Cyber Threats and Response , Incident Response , Securing Networks Actions to take today to mitigate cyber threats against Ivanti appliances: Limit outbound internet connections from SSL VPN appliances to restrict access to required services. Keep all operating systems and firmware up to date. Limit SSL VPN connections to unprivileged accounts. SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA) and the following partners (hereafter referred to as the authoring organizations) are releasing this joint Cybersecurity Advisory to warn that cyber threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. CISA and authoring organizations appreciate the cooperation of Volexity, Ivanti, Mandiant and other industry partners in the development of this advisory and ongoing incident response activities. Authoring organizations: Federal Bureau of Investigation (FBI) Multi-State Information Sharing & Analysis Center (MS-ISAC) Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) United Kingdom National Cyber Security Centre (NCSC-UK) Canadian Centre for Cyber Security (Cyber Centre), a part of the Communications Security Establishment New Zealand National Cyber Security Centre (NCSC-NZ) CERT-New Zealand (CERT NZ) Of particular concern, the authoring organizations and industry partners have determined that cyber threat actors are able to deceive Ivanti’s internal and external Integrity Checker Tool (ICT), resulting in a failure to detect compromise. Cyber threat actors are actively exploitin
Indicatori CISA verificabili
65 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T05:30:35.146211+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| SHA-256 | ed4b855941d6d7e07aacf016a2402c4c870876a050a4a547af194f5a9b47945f | Cav-0.1- py3.6.egg |
| ipv4-addr | 46[.]8[.]68[.]100 | |
| ipv4-addr | 88[.]119[.]169[.]227 | |
| ipv4-addr | 103[.]13[.]28[.]40 | |
| MD5 | b15f47e234b5d26fb2cc81fc6fd89775 | |
| MD5 | e8489983d73ed30a4240a14b1f161254 | |
| SHA-1 | d07a080c62c28a22903e71990a6dce780f29c831 | |
| SHA-256 | e1d0ccfb7f1c46c7b8b8b154c97bac33f3ba89dae6481464cbe1448aca1e9dea | |
| SSDEEP | 96:EUsoDneD8id6WOgrYuJ9l2Zianz6WeNJdOFqiXCauHv0lFnGO3y:hsUnY8EwcanWRNSFqbaSvKEO3y | |
| MD5 | a81813f70151a022ea1065b7f4d6b5ab | |
| SHA-1 | aeab57aca571dbaaa95cf54d1dcaf85de86c3cba | |
| SHA-256 | ccdc02cf931c525af18003c62cc54fbedf1f793ba840fe26cc43ba4b8a9af667 | |
| MD5 | a739bd4c2b9f3679f43579711448786f | |
| SHA-1 | e1d9e32309072d57bc396ed343e9fe5981a078a5 | |
| SHA-256 | 48bda8b8d0f17b1e5c017f208151677efd996b64141faca3d7b29fc4d337dbc7 | |
| MD5 | 8eb042da6ba683ef1bae460af103cc44 | |
| SHA-1 | 4afe9789cef5aee2aa4b6bbed013e393f41d1ecc | |
| SHA-256 | 1079e1b6e016b070ebf3e1357fa23313dcb805d3a6805088dbc3ab6d39330548 | |
| MD5 | 465600cece80861497e8c1c86a07a23e | |
| SHA-1 | b48a60046096460d2d100a31a3e614eddff08abc | |
| SHA-256 | b5c063c8df7d2ecc82ed18cdcf88660d776b14486fbbec901933198d58cc10e6 | |
| MD5 | 3045f5b3d355a9ab26ab6f44cc831a83 | |
| SHA-1 | 9d7c607ea3e75d3816c71f0636b549be7a40c56d | |
| SHA-256 | 08c986a82a1c925b2b178c28ec4177f4221bf2a8c2b9649363ab666b3d4ec6ab | |
| MD5 | 2ec505088b942c234f39a37188e80d7a | |
| SHA-1 | 3a7dc837c1a00bed96980e8624eb454d5a30f71d | |
| SHA-256 | d4de1b866f94cdc43e55fab932880da1f4e9c7406bb17926e30baa9b7b824ecb | |
| SSDEEP | 96:f5lsF50nl088WDEjHJ7YbH0GvfjQtiaFQCD9bRWSPG4W87shHCy67ge4q0y/Rcbm:fnsFKnC8wdpcfjQoaFQkdTPG478Cy67p | |
| ipv4-addr | 8[.]137[.]112[.]245 | |
| ipv4-addr | 186[.]179[.]39[.]235 | |
| ipv4-addr | 159[.]65[.]130[.]146 | |
| domain-name | secure-cama[.]com | |
| domain-name | miltonhouse[.]nl | |
| domain-name | line-api[.]com | |
| domain-name | entraide-internationale[.]fr | |
| domain-name | ehangmun[.]com | |
| domain-name | clicko[.]click | |
| domain-name | clickcom[.]click | |
| domain-name | areekaweb[.]com | |
| ipv4-addr | 146[.]0[.]228[.]66 | |
| domain-name | duorhytm[.]fun | |
| domain-name | cpanel[.]netbar[.]org | |
| domain-name | api[.]d-n-s[.]name | |
| MD5 | d0c7a334a4d9dcd3c6335ae13bee59ea | |
| SHA-1 | 3b03f9b02b2d90e00c5067ff428ee13b0cbdf677 | |
| SHA-256 | 5bc21fc0cab9f1ef0d5f34365c131ccdb885dbb14abcca85dafaa3ac4568d554 | |
| MD5 | 3d97f55a03ceb4f71671aa2ecf5b24e9 | |
| domain-name | webb-institute[.]com | |
| domain-name | gpoaccess[.]com | |
| ipv4-addr | 173[.]53[.]43[.]7 | |
| ipv4-addr | 71[.]127[.]149[.]194 | |
| ipv4-addr | 50[.]215[.]39[.]49 | |
| ipv4-addr | 75[.]145[.]224[.]109 | |
| ipv4-addr | 64[.]24[.]179[.]210 | |
| ipv4-addr | 50[.]213[.]208[.]89 | |
| ipv4-addr | 50[.]243[.]177[.]161 | |
| ipv4-addr | 73[.]128[.]178[.]221 | |
| ipv4-addr | 173[.]220[.]106[.]166 | |
| ipv4-addr | 98[.]160[.]48[.]170 | |
| ipv4-addr | 47[.]207[.]9[.]89 | |
| ipv4-addr | 75[.]145[.]243[.]85 | |
| ipv4-addr | 206[.]189[.]208[.]156 | |
| ipv4-addr | 91[.]92[.]254[.]14 | |
| domain-name | symantke[.]com | |
| ipv4-addr | 45[.]61[.]136[.]14 |
Provenance
Allegato ufficiale CISA · 2024-02-22T04:31:51Z
SHA-512: 85c486158ad8349466cf9e95060b582beb96f9413042eb6ddaae62e5d8dc5280c55100fcaac745ce6f3aa2f0e7faa6b72fc1724f7909f5e1c4e465243fcfd074
- Source
- CISA Cybersecurity Advisories
- Publishing entity
- CISA
- Entity type
- National authority
- Area
- North America · US
- Original language
- en · translation in preparation
- Publication
- 29/02/2024 13:00
- Sharing
- TLP:CLEAR
- MITRE ATT&CK
- T1059.001, T1068, T1078, T1190, T1203, T1505.003
- CVE
- CVE-2023-46805, CVE-2024-21887, CVE-2024-21893, CVE-2024-22024, CVE-2024-21888
- Classification
- Critical
- Stated country
- US
Affected products and versions
The collector will check NVD and the available official vendor advisories.
Action indicated by the source
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
Official technical references
- https://www.cisa.gov/sites/default/files/2024-02/AA24-060B-Threat-Actors-Exploit-Multiple-Vulnerabilities-in-Ivanti-Connect-Secure-and-Policy-Secure-Gateways_0.pdf
- https://www.cisa.gov/sites/default/files/2024-02/AA24-060B.stix_.xml
- https://www.cisa.gov/sites/default/files/2024-02/AA24-060B-threat-actors-exploit-multiple-vulnerabilities-in-ivanti-connect-secure-and-policy-secure-gateways.stix_.json
- https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf
- https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf