Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications

released on 2025-01-24 @ 02:18:11 PM
The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory in response to exploitation in September 2024 of vulnerabilities in Ivanti Cloud Service Appliances (CSA): CVE-2024-8963, an administrative bypass vulnerability; CVE-2024-9379, a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380, remote code execution vulnerabilities.