Article Details
Scrape Timestamp (UTC): 2025-03-11 04:05:59.124
Source: https://thehackernews.com/2025/03/cisa-adds-five-actively-exploited.html
Original Article Text
Click to Toggle View
CISA Adds Five Actively Exploited Vulnerabilities in Advantive VeraCore and Ivanti EPM to KEV List. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws impacting Advantive VeraCore and Ivanti Endpoint Manager (EPM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild. The list of vulnerabilities is as follows - The exploitation of VeraCore vulnerabilities has been attributed to likely a Vietnamese threat actor named XE Group, which has been observed dropping reverse shells and web shells to maintain persistent remote access to compromised systems. On the other hand, there are currently public reports about how the three Ivanti EPM flaws are being weaponized in real-world attacks. A proof-of-concept (PoC) exploit was released by Horizon3.ai last month. The cybersecurity company described them as credential coercion, which is" bugs that could allow an unauthenticated attacker to compromise the servers. In light of active exploitation, it's essential that Federal Civilian Executive Branch (FCEB) agencies apply the necessary patches by March 31, 2025. The development comes as threat intelligence firm GreyNose warned of mass exploitation of CVE-2024-4577, a critical vulnerability impacting PHP-CGI, with spikes in attack activity targeting Japan, Singapore, Indonesia, the United Kingdom, Spain, and India. "More than 43% of IPs targeting CVE-2024-4577 in the past 30 days are from Germany and China," GreyNoise said, adding it "detected a coordinated spike in exploitation attempts against networks in multiple countries, suggesting additional automated scanning for vulnerable targets" in February.
Daily Brief Summary
CISA has updated its Known Exploited Vulnerabilities catalog with five new entries concerning Advantive VeraCore and Ivanti Endpoint Manager (EPM) due to active exploitation evidence.
The vulnerabilities in VeraCore have been actively exploited by a Vietnamese threat group known as XE Group, which uses reverse shells and web shells for sustained remote access.
Ivanti EPM's vulnerabilities have been publicly detailed, with reports of real-world attacks and a recent proof-of-concept exploit demonstrating credential coercion vulnerabilities.
Federal Civilian Executive Branch (FCEB) agencies are urged to implement necessary security patches for these vulnerabilities by March 31, 2025.
Concurrently, threat intelligence firm GreyNose has reported a critical exploit targeting PHP-CGI, notably affecting several countries with a high concentration of attack IPs originating from Germany and China.
GreyNose notes a significant coordinated effort in February to scan and exploit networks across multiple nations, indicating the scale and organization of the cyber attacks.