Tech

French government hit by Chinese hackers exploiting Ivanti security flaws

Share
Share


  • Three zero-day flaws in Ivanti CSA solutions were abused to grab login credentials
  • The group likely sold the access to French government devices
  • Researchers are attributing the attacks to Chinese state-sponsored miscreants

In late 2024, Chinese state-sponsored threat actors abused multiple zero-day vulnerabilities in Ivanti Cloud Services Appliance (CSA) devices to access French government agencies, as well as numerous commercial entities such as telcos, finance, and transportation organizations.

The news was recently confirmed by the French National Agency for the Security of Information Systems (ANSSI), which noted threat actors were abusing three security vulnerabilities in Ivanti CSA devices: CVE-2024-8963, CVE-2024-9380, and CVE-2024-8190.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Venture capital giant IdeaLab confirms breach, says private data was stolen in attack
Tech

Venture capital giant IdeaLab confirms breach, says private data was stolen in attack

IdeaLab confirms it suffered a data breach, offers identity theft protection and...

Quordle hints and answers for Saturday, July 5 (game #1258)
Tech

Quordle hints and answers for Saturday, July 5 (game #1258)

Looking for a different day? A new Quordle puzzle appears at midnight...

NYT Strands hints and answers for Saturday, July 5 (game #489)
Tech

NYT Strands hints and answers for Saturday, July 5 (game #489)

Looking for a different day? A new NYT Strands puzzle appears at...

NYT Connections hints and answers for Saturday, July 5 (game #755)
Tech

NYT Connections hints and answers for Saturday, July 5 (game #755)

Looking for a different day? A new NYT Connections puzzle appears at...