Shady Ivanti equipment compromised once more – Chinese operatives involved, according to GadgetLad

Shady Ivanti equipment compromised once more – Chinese operatives involved, according to GadgetLad

Ivanti? More Like Immune to Patching

Shady Ivanti equipment compromised once more – Chinese operatives involved, according to GadgetLad

Listen mate, if you’ve still got Ivanti equipment in your rack, I’d say you’d be better off trying to secure your network with Blu Tack and hope. As of this week, Ivanti’s VPN devices have once again turned into a hacker’s paradise, with suspected state-sponsored Chinese snoopers breaking in through a newly uncovered critical vulnerability. And it’s not their first misstep—they’ve had three turns on the naughty list in just three years. A hat-trick of embarrassment, that is.

According to the brainiacs at Volexity, who uncover these issues for a living, the bad actors have been taking advantage of this vulnerability since mid-March. If you’re thinking, “Hey, didn’t they just resolve something similar?”—You’re absolutely right. But obviously, Ivanti’s take on patch management is the IT equivalent of slapping paint over a leaking wall.

The Vulnerability: From “Whoops” to “You’re Completely Done”

Simple Denial-of-Service? Nope, Complete Remote Code Execution

What began as a simple denial-of-service exploit (you know, making a device crash) has now escalated into total remote unauthenticated code execution. That’s right, no login barriers to slow things down. Just stroll in, help yourself to the data, and maybe switch the wallpaper to Xi Jinping in a Santa hat while you’re at it.

Honestly, the only thing more accessible than these devices is a Wetherspoons entrance at 9am.

CVSS Score? Think “Buy New Equipment Immediately”

This vulnerability is so severe it received a solid 9.1 on the CVSS scale. And for those who aren’t fluent in infosec jargon, that means “You’re in serious trouble, mate.” It’s a complete disaster, and I swear Ivanti must be writing their firmware on cocktail napkins by now.

The Attack: Stealthy as a Ninja, Persistent as a Cold Sore

These snoopers didn’t just pop in and out. They were meticulous, systematic—like someone grocery shopping in Aldi with a list. They zeroed in on at least one US-based organization, but, let’s face it, it’s probably dozens globally, and we’ll only learn about them once the press office has finished panicking.

The attackers were using a cheeky mix of stolen session data, sketchy shell scripts, and executing code without anyone being aware—while remaining as persistent as your Auntie Jean’s Facebook friend requests. You’d be none the wiser until they’d already swiped the fancy biscuits and the company secrets.

Ivanti’s Optimistic Response: “We’re Looking Into It”… Again

Ivanti, bless their hearts, put out a little statement saying they’re “aware” of the problem and currently “investigating.” Which, translated from PR lingo, means: “We’re patching up our systems with duct tape and divine prayers, just hoping nobody sues us into oblivion.”

In the meantime, they’ve been issuing emergency steps like a construction worker giving you a quote over a pint—no promises, no guarantees, just hopeful intentions.

Patching? Maybe Next Year

And if you’re expecting a quick resolution, you’ve got some waiting to do. They’re claiming they’re working on updates. I’ll believe it when I see it. Until then, your safest option is probably to pull the device from your network, ceremonially burn it, and run OpenVPN on a Raspberry Pi wrapped in tinfoil. Safer, to be honest.

Seriously Though, Just Quit Using Ivanti VPNs

We’ve now had three—I repeat: three—major security vulnerabilities in Ivanti VPN gear in just as many years, all of them exploited like a purse at the Bigg Market on a Friday night. If you’re still relying on one of these devices, what exactly are you waiting for? A handwritten invitation from the Ministry of State Security?

Summary

Hack Me Baby One More Time

Another year, another disaster. Ivanti VPNs remain a gift that keeps on giving—to Chinese spies. If your company still relies on these devices, perhaps it’s time to rethink that loyalty. Toss them in the Tyne, get a new firewall, and give yourself half a fighting chance. I’m thoroughly fed up with writing about this nonsense now. Off to walk the dog.

— GadgetLad, over and out