Nation-State Attackers Exploiting Ivanti CSA Flaws for Network Infiltration
A zero-day exploit in the Ivanti Cloud Service Appliance (CSA) has been used by a suspected nation-state adversary to carry out a number of malevolent operations.
Fortinet FortiGuard Labs' results support this, stating that the vulnerabilities were exploited to obtain unauthenticated access to the CSA, list all of the users that were set up in the appliance, and try to obtain the login credentials of those users.
According to security experts Faisal Abdul Malik Qureshi, John Simmons, Jared Betts, Luca Pugliese, Trent Healy, Ken Evans, and Robert Reyes, the sophisticated adversaries were seen taking use of and chaining zero-day vulnerabilities to create beachhead access in the victim's network read more about Nation-State Attackers Exploiting Ivanti CSA Flaws for Network Infiltration...

