First reportedJanuary 10, 2024
ActivityActivity date not specified
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencehigh

Key facts

Affected

  • Organizations using Ivanti Connect Secure / Policy Secure appliances
  • U.S. federal agencies (per CISA emergency directives)

Initial access

  • vuln

Impact

  • data_theft
  • service_disruption
  • financial_loss

Attribution

unknown low confidence

Cited sources focus on active exploitation and mitigation guidance; definitive actor attribution is not provided in the included materials.

CVEs and ATT&CK

CVEs

CVE-2023-46805 · highCVE-2024-21887 · high

ATT&CK techniques

  • T1190: CISA and Ivanti described active exploitation of internet-facing VPN/access gateway vulnerabilities for initial access.

Mitigations

Now

  • Apply Ivanti security updates and follow vendor mitigation guidance (including integrity checks)Removes or reduces the exploited weakness and helps identify compromised appliances.

Soon

  • Isolate appliances and restrict administrative access (management interfaces, MFA, allowlisted IPs)Reduces exposure of high-value gateway systems and limits attacker opportunities.

Later

  • Rotate credentials and tokens used by/through the gateway (VPN creds, API tokens, service accounts)Mitigates risk of stolen credentials being reused after appliance compromise.

Detection ideas

Detect suspicious requests and exploitation patterns in appliance and web logs

Search for IOCs and unusual request paths/parameters identified by vendor and CISA; alert on repeated hits to known vulnerable endpoints.

Data sources: Ivanti appliance logs, Web server access logs, WAF logs

Detect post-exploitation artifacts and unexpected administrative changes

Alert on new admin accounts, unexpected config changes, unusual outbound connections from the appliance, or file changes indicative of web shell implantation.

Data sources: Appliance audit logs, EDR telemetry on adjacent hosts, SIEM

Sources