Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways
Cosa significa
CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.
Perché conta
L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.
Azioni consigliate
- Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
- Verificare sistemi esposti, accessi remoti e versioni rispetto all'advisory ufficiale.
- Confermare che backup offline e immutabili siano separati e ripristinabili.
- Correlare TTP e IOC pubblicati con la telemetria autorizzata del proprio perimetro.
Benefici operativi potenziali
- Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
- Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
- Validazione documentata della capacita di ripristino
Traduzione in elaborazione
Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.
Testo acquisito dalla fonte
Cybersecurity Advisory Threat Actors Exploit Multiple Vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways Release Date February 29, 2024 Alert Code AA24-060B Related topics: Cyber Threats and Response , Incident Response , Securing Networks Actions to take today to mitigate cyber threats against Ivanti appliances: Limit outbound internet connections from SSL VPN appliances to restrict access to required services. Keep all operating systems and firmware up to date. Limit SSL VPN connections to unprivileged accounts. SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA) and the following partners (hereafter referred to as the authoring organizations) are releasing this joint Cybersecurity Advisory to warn that cyber threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. CISA and authoring organizations appreciate the cooperation of Volexity, Ivanti, Mandiant and other industry partners in the development of this advisory and ongoing incident response activities. Authoring organizations: Federal Bureau of Investigation (FBI) Multi-State Information Sharing & Analysis Center (MS-ISAC) Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) United Kingdom National Cyber Security Centre (NCSC-UK) Canadian Centre for Cyber Security (Cyber Centre), a part of the Communications Security Establishment New Zealand National Cyber Security Centre (NCSC-NZ) CERT-New Zealand (CERT NZ) Of particular concern, the authoring organizations and industry partners have determined that cyber threat actors are able to deceive Ivanti’s internal and external Integrity Checker Tool (ICT), resulting in a failure to detect compromise. Cyber threat actors are actively exploitin
Indicatori CISA verificabili
65 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.
Ultima verifica: 2026-09-26T05:30:35.146211+00:00
Scarica STIX 2.1| Tipo | Indicatore (non cliccabile) | File |
|---|---|---|
| SHA-256 | ed4b855941d6d7e07aacf016a2402c4c870876a050a4a547af194f5a9b47945f | Cav-0.1- py3.6.egg |
| ipv4-addr | 46[.]8[.]68[.]100 | |
| ipv4-addr | 88[.]119[.]169[.]227 | |
| ipv4-addr | 103[.]13[.]28[.]40 | |
| MD5 | b15f47e234b5d26fb2cc81fc6fd89775 | |
| MD5 | e8489983d73ed30a4240a14b1f161254 | |
| SHA-1 | d07a080c62c28a22903e71990a6dce780f29c831 | |
| SHA-256 | e1d0ccfb7f1c46c7b8b8b154c97bac33f3ba89dae6481464cbe1448aca1e9dea | |
| SSDEEP | 96:EUsoDneD8id6WOgrYuJ9l2Zianz6WeNJdOFqiXCauHv0lFnGO3y:hsUnY8EwcanWRNSFqbaSvKEO3y | |
| MD5 | a81813f70151a022ea1065b7f4d6b5ab | |
| SHA-1 | aeab57aca571dbaaa95cf54d1dcaf85de86c3cba | |
| SHA-256 | ccdc02cf931c525af18003c62cc54fbedf1f793ba840fe26cc43ba4b8a9af667 | |
| MD5 | a739bd4c2b9f3679f43579711448786f | |
| SHA-1 | e1d9e32309072d57bc396ed343e9fe5981a078a5 | |
| SHA-256 | 48bda8b8d0f17b1e5c017f208151677efd996b64141faca3d7b29fc4d337dbc7 | |
| MD5 | 8eb042da6ba683ef1bae460af103cc44 | |
| SHA-1 | 4afe9789cef5aee2aa4b6bbed013e393f41d1ecc | |
| SHA-256 | 1079e1b6e016b070ebf3e1357fa23313dcb805d3a6805088dbc3ab6d39330548 | |
| MD5 | 465600cece80861497e8c1c86a07a23e | |
| SHA-1 | b48a60046096460d2d100a31a3e614eddff08abc | |
| SHA-256 | b5c063c8df7d2ecc82ed18cdcf88660d776b14486fbbec901933198d58cc10e6 | |
| MD5 | 3045f5b3d355a9ab26ab6f44cc831a83 | |
| SHA-1 | 9d7c607ea3e75d3816c71f0636b549be7a40c56d | |
| SHA-256 | 08c986a82a1c925b2b178c28ec4177f4221bf2a8c2b9649363ab666b3d4ec6ab | |
| MD5 | 2ec505088b942c234f39a37188e80d7a | |
| SHA-1 | 3a7dc837c1a00bed96980e8624eb454d5a30f71d | |
| SHA-256 | d4de1b866f94cdc43e55fab932880da1f4e9c7406bb17926e30baa9b7b824ecb | |
| SSDEEP | 96:f5lsF50nl088WDEjHJ7YbH0GvfjQtiaFQCD9bRWSPG4W87shHCy67ge4q0y/Rcbm:fnsFKnC8wdpcfjQoaFQkdTPG478Cy67p | |
| ipv4-addr | 8[.]137[.]112[.]245 | |
| ipv4-addr | 186[.]179[.]39[.]235 | |
| ipv4-addr | 159[.]65[.]130[.]146 | |
| domain-name | secure-cama[.]com | |
| domain-name | miltonhouse[.]nl | |
| domain-name | line-api[.]com | |
| domain-name | entraide-internationale[.]fr | |
| domain-name | ehangmun[.]com | |
| domain-name | clicko[.]click | |
| domain-name | clickcom[.]click | |
| domain-name | areekaweb[.]com | |
| ipv4-addr | 146[.]0[.]228[.]66 | |
| domain-name | duorhytm[.]fun | |
| domain-name | cpanel[.]netbar[.]org | |
| domain-name | api[.]d-n-s[.]name | |
| MD5 | d0c7a334a4d9dcd3c6335ae13bee59ea | |
| SHA-1 | 3b03f9b02b2d90e00c5067ff428ee13b0cbdf677 | |
| SHA-256 | 5bc21fc0cab9f1ef0d5f34365c131ccdb885dbb14abcca85dafaa3ac4568d554 | |
| MD5 | 3d97f55a03ceb4f71671aa2ecf5b24e9 | |
| domain-name | webb-institute[.]com | |
| domain-name | gpoaccess[.]com | |
| ipv4-addr | 173[.]53[.]43[.]7 | |
| ipv4-addr | 71[.]127[.]149[.]194 | |
| ipv4-addr | 50[.]215[.]39[.]49 | |
| ipv4-addr | 75[.]145[.]224[.]109 | |
| ipv4-addr | 64[.]24[.]179[.]210 | |
| ipv4-addr | 50[.]213[.]208[.]89 | |
| ipv4-addr | 50[.]243[.]177[.]161 | |
| ipv4-addr | 73[.]128[.]178[.]221 | |
| ipv4-addr | 173[.]220[.]106[.]166 | |
| ipv4-addr | 98[.]160[.]48[.]170 | |
| ipv4-addr | 47[.]207[.]9[.]89 | |
| ipv4-addr | 75[.]145[.]243[.]85 | |
| ipv4-addr | 206[.]189[.]208[.]156 | |
| ipv4-addr | 91[.]92[.]254[.]14 | |
| domain-name | symantke[.]com | |
| ipv4-addr | 45[.]61[.]136[.]14 |
Provenienza
Allegato ufficiale CISA · 2024-02-22T04:31:51Z
SHA-512: 85c486158ad8349466cf9e95060b582beb96f9413042eb6ddaae62e5d8dc5280c55100fcaac745ce6f3aa2f0e7faa6b72fc1724f7909f5e1c4e465243fcfd074
- Fonte
- CISA Cybersecurity Advisories
- Entità pubblicatrice
- CISA
- Tipo entità
- Autorità nazionale
- Area
- North America · US
- Lingua originale
- en · traduzione in preparazione
- Pubblicazione
- 29/02/2024 13:00
- Condivisione
- TLP:CLEAR
- MITRE ATT&CK
- T1059.001, T1068, T1078, T1190, T1203, T1505.003
- CVE
- CVE-2023-46805, CVE-2024-21887, CVE-2024-21893, CVE-2024-22024, CVE-2024-21888
- Classificazione
- Critica
- Paese indicato
- US
Prodotti e versioni interessati
Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.
Azione indicata dalla fonte
Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.
Riferimenti tecnici ufficiali
- https://www.cisa.gov/sites/default/files/2024-02/AA24-060B-Threat-Actors-Exploit-Multiple-Vulnerabilities-in-Ivanti-Connect-Secure-and-Policy-Secure-Gateways_0.pdf
- https://www.cisa.gov/sites/default/files/2024-02/AA24-060B.stix_.xml
- https://www.cisa.gov/sites/default/files/2024-02/AA24-060B-threat-actors-exploit-multiple-vulnerabilities-in-ivanti-connect-secure-and-policy-secure-gateways.stix_.json
- https://www.cisa.gov/sites/default/files/2023-03/CISA_CPG_REPORT_v1.0.1_FINAL.pdf
- https://www.cisa.gov/sites/default/files/publications/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf