National Cyber Warfare Foundation (NCWF) Forums


Hackers Exploiting Ivanti VPN Flaws to Deploy KrustyLoader Malware


0 user ratings
2024-01-31 10:16:39
milo
Blue Team (CND) , Attacks

 - archive -- 
A pair of recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been exploited to deliver a Rust-based payload called KrustyLoader that's used to drop the open-source Sliver adversary simulation tool.
The security vulnerabilities, tracked as CVE-2023-46805 (CVSS score: 8.2) and CVE-2024-21887 (CVSS score: 9.1), could be abused



Source: TheHackerNews
Source Link: https://thehackernews.com/2024/01/chinese-hackers-exploiting-critical-vpn.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



© Copyright 2012 through 2024 - National Cyber War Foundation - All rights reserved worldwide.