
CISA Directs Federal Agencies to Mitigate Ivanti Software Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on Friday urging agencies to mitigate vulnerabilities in Ivanti Connect Secure VPN devices and its Policy Secure tools. The directive also requires federal agencies to remove compromised products from agency networks and report any indications of compromise to CISA. CISA said it had observed “widespread and active exploitation of vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure solutions,” which could pose “an unacceptable risk” to federal agencies. According to the directive, successful exploitation of vulnerabilities would allow a threat actor to “move laterally, perform data exfiltration, and establish persistent system access, resulting in full compromise of target information systems.”...
