News

Organisations are struggling to prioritise vulnerability patching appropriately, leading to situations where everything is a ...
Ivanti, Fortinet, and Splunk have released patches for critical- and high-severity vulnerabilities in their products.
It seems like CISA knows something that maybe we don’t, and it’s not great news for Ivanti users. Do note that this even applies to devices that have had the XML mitigation applied. Yikes. Jenkins ...
The news was recently confirmed by the French National Agency for the Security of Information Systems (ANSSI), which noted ...
Read details about the new Ivanti VPN zero-day vulnerabilities, along with the latest information about patches. Most of the exposed VPN appliances are reported to be in the U.S., followed by ...
Ivanti is now warning that it has discovered two additional flaws — tracked as CVE-2024-21888 and CVE-2024-21893 — affecting its Connect Secure VPN product. The former is described as a ...
Ivanti VPN users should stay alert as IP scanning for the vendor's Connect Secure and Pulse Secure systems surged by 800 percent last week, according to threat intel biz GreyNoise.… The team at ...
Federal agencies are facing significant challenges due to outdated IT systems that hinder efficiency, compromise security and ...
Networks protected by Ivanti VPNs are under active attack by well-resourced hackers who are exploiting a critical vulnerability that gives them complete control over the network-connected devices.
Authentication in Ivanti VPNs occurs through the doAuthCheck function in an HTTP web server binary located at /root/home/bin/web. The endpoint /dana-ws/saml20.ws doesn’t require authentication.
Ivanti VPN appliances have been under attack since December 2023 using exploits chaining the CVE-2023-46805 authentication bypass and the CVE-2024-21887 command injection flaws as zero days.
Ivanti Neurons is a multi-faceted RMM software that allows businesses to discover and automate various endpoint management functions, including patching. With various products to look after ...