Ivanti Flaw Exploited in MITRE Corporation Cyberattack

December 6, 2024

INCIDENT

MITRE's unclassified collaborative research and development network — where prototyping and other work is housed — was compromised by a foreign nation-state threat actor. MITRE’s work supports a variety of government agencies. MITRE is working to restore operational alternatives for collaboration in an expedited and secure manner.

The company said unidentified threat actors performed reconnaissance on its networks by exploiting one of its VPNs through two vulnerabilities in Ivanti Connect Secure. At the time, Ivanti said the two vulnerabilities — CVE-2023-46805 and CVE-2024-21887 — were used in attacks on at least 10 of its customers.

Incident Date

April 19, 2024

Estimated Cost


No cost values disclosed.

Type of Malware

No Malware identified

Threat Source

No threat source identified