Ivanti Zero-Days: Your VPN Just Got a Whole Lot Riskier
Heads up, folks! The Ivanti Connect Secure and Policy Secure vulnerabilities are still the talk of the town, and not in a good way. Active exploitation by state-sponsored groups and other threat actors continues, turning these VPN appliances into wide-open doors for network breaches[1].
This isn’t just another patch Tuesday; it’s a critical alert demanding immediate action for anyone running these appliances, as attackers are already inside networks globally[2].
We’re talking about a nasty chain of zero-day vulnerabilities that give attackers serious power. Specifically, CVE-2023-46805 (an authentication bypass) and CVE-202



