22 April 2024

MITRE discloses security breach via Ivanti zero-days


MITRE discloses security breach via Ivanti zero-days

The MITRE Corporation, a non-profit overseeing a knowledge base that helps model cyber adversaries' tactics and techniques, disclosed a security breach affecting its Networked Experimentation, Research, and Virtualization Environment (NERVE), a collaborative network used for research, development, and prototyping.

The organization said that an unnamed foreign state-sponsored threat actor was behind the attack.

Following the breach, the non-profit took measures to contain the incident, including taking some systems offline.

As MITRE CTO Charles Clancy and principal cybersecurity engineer Lex Crumpton explained in a separate blog post on Medium, the attackers exploited one of the organization’s Virtual Private Networks (VPNs) through two Ivanti Connect Secure zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887) and bypassed multi-factor authentication using session hijacking.

The threat actor then moved laterally and accessed the network’s VMware infrastructure via a compromised administrator account. The attackers employed a combination of sophisticated backdoors and webshells to maintain persistence and harvest credentials.

“MITRE has contacted authorities and notified affected parties and is working to restore operational alternatives for collaboration in an expedited and secure manner,” the organization said, adding that the investigation into the incident is ongoing.

Back to the list

Latest Posts

Cyber Security Week in Review: May 3, 2024

Cyber Security Week in Review: May 3, 2024

In brief: the Dropbox breach, Chinese hackers caught manipulating China’s Great Firewall, REvil hacker sentenced, and moreю
3 May 2024
REvil hacker sentenced to 13 years for $700M ransomware spree

REvil hacker sentenced to 13 years for $700M ransomware spree

In addition to his prison sentence, Vasinskyi was ordered to pay over $16 million in restitution.
2 May 2024
Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

Dropbox says hackers breached its Sign eSignature platform and stole sensitive data

The attackers accessed authentication tokens, MFA keys, hashed passwords, and customer info.
2 May 2024