Ivanti Flaw Exploited in MITRE Corporation Cyberattack
INCIDENT
MITRE's unclassified collaborative research and development network — where prototyping and other work is housed — was compromised by a foreign nation-state threat actor. MITRE’s work supports a variety of government agencies. MITRE is working to restore operational alternatives for collaboration in an expedited and secure manner.
The company said unidentified threat actors performed reconnaissance on its networks by exploiting one of its VPNs through two vulnerabilities in Ivanti Connect Secure. At the time, Ivanti said the two vulnerabilities — CVE-2023-46805 and CVE-2024-21887 — were used in attacks on at least 10 of its customers.
Victims
Type of Malware
No Malware identified
Threat Source
No threat source identified
