Ivanti’s Latest Headache: State-Sponsored Hackers STILL Piling On!
Just when you thought Ivanti Connect Secure VPN vulnerabilities couldn’t get worse, new reports confirm state-sponsored groups are still having a field day, actively exploiting patched and unpatched systems alike. It’s a full-blown crisis for organizations relying on these devices for secure remote access.
The vulnerabilities, primarily CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection), have been chained to achieve unauthenticated remote code execution. Mandiant has identified multiple threat clusters, including state-sponsored groups like UNC5221 (linked to China), continuing to exploit these flaws with sophisticated techniques, even after patches were released[1]. They’re deploying custom malware, backdoors, and web shells, making persistence a nightmare. CISA even issued an emergency directive urging agencies to disconnect Ivanti products entirely until a complete patch and re-imaging process can be done[2]. More recently, new vulnerabilities like CVE-2024-21888 (privilege escalation) and CVE-2024-21893 (server-side request forgery) have emerged, further complicating the situation, with Ivanti releasing new patches[3].
If your organization uses Ivanti Connect Secure or Policy Secure VPNs, this isn’t just “patch and pray” anymore. These aren’t simple drive-by attacks; we’re talking about persistent, sophisticated adversaries. Developers need to understand that the integrity of their build systems and source code



