Risky Bulletin Newsletter
January 12, 2024
Risky Biz News: Chinese APT exploits two Pulse Secure zero-days
Presented by
![Catalin Cimpanu](/static/img/catalin-cimpanu.jpg)
News Editor
A Chinese state-sponsored hacking group has exploited two zero-days in Ivanti Connect Secure VPN appliances (formerly known as Pulse Secure) to gain access to corporate networks.
The zero-days were discovered by American cybersecurity firm Volexity, which attributed the attacks to a group it tracks as UTA0178.
Ivanti has published mitigations and workarounds that customers can apply until firmware patches are released on January 22.