Ivanti’s VPNs Are Facing Heavy Attacks
If you’re involved with Ivanti’s Connect Secure or Pulse Secure VPNs, it might be wise to pay attention and get your head out of the sand. Security monitoring company GreyNoise has recorded an astounding 800% increase—yes, eight hundred percent—in scanning activity directed at them. Simply put: hackers are prowling around like a dog with a treat, and that likely spells trouble soon.

GreyNoise: Something Sinister Approaches
Pre-Vulnerability Antics
GreyNoise, which tracks the unusual happenings across the web (likely while sipping bad instant coffee like the rest of us), notes that this type of activity usually suggests a new vulnerability is either already leaking among insiders or about to emerge suddenly. You know the scenario—someone testing your locks before they break in.
This uptick in scanning hasn’t been observed since earlier this year when Ivanti dealt with a severe chained vulnerability issue. Remember that mess? A number of dubious actors exploited multiple remote code execution vulnerabilities in Ivanti VPNs—and people were scrambling like my mum when she discovers she left the oven on.
No Patch, No Safety
Back then, there was no patch available, just workarounds—like slapping duct tape on a sinking vessel. Not ideal in any sense. When large entities like CISA and other government officials in the US start sounding alarms, you know you’re in troubled waters. They effectively warned everyone: “If you’re running Ivanti VPNs and haven’t shut down the affected services, you might as well draw a target on your data.”
Regenerating Session IDs – The Digital Equivalent of Changing Your Locks
Even when they eventually released a patch, it wasn’t a simple “apply it and forget it” fix. You needed to regenerate all your system’s session identifiers to prevent hackers from lingering in your network like an unwanted smell in an elevator. Imagine relying on a vendor that tells you after weeks: “Oh yes, it seems our temporary fix wasn’t sufficient. Change everything, mate.”
GadgetLad’s Recommendation: Stay Alert or Get Burned
Listen, I’m not your mother, but if you’re still operating Ivanti VPNs without a recent security audit or updates, you’re either bold or foolish. The attackers scanning these devices are serious—they’re hunting for easy targets, and if your system is outdated, you’ll find yourself among them.
This type of activity often kicks off just before someone discloses another vulnerability or releases a functional exploit online, and suddenly everyone from amateur hackers to state-sponsored entities is on the attack.
What Should You Do?
Patch as If Your Life Depends on It
First and foremost, get patched, and I mean genuinely patched—not “we’ll get to it next week” patched. If your security team is dragging their feet, give them a gentle reminder. Or a firmer nudge. Whatever gets the job done.
Monitor Your Perimeter
Establish rules to track unusual traffic to your VPN endpoints. A large amount of scanning activity isn’t typical—unless you’re Google or hiding something valuable in your data center. If you can’t invest in proper monitoring tools, there’s open-source software available that will get you at least halfway there. No excuse for ignorance these days.
Consider a Change?
Honestly, if Ivanti’s products keep having more vulnerabilities than a sieve, perhaps it’s time to pose the difficult question: should we discard it and seek alternatives? There are other VPN solutions that aren’t making headlines every few months for providing easy access to hackers.

Conclusion
When the VPN’s on Fire, Perhaps Avoid Toasting Marshmallows
If you’re still using Ivanti as if nothing is wrong, good luck to you—you’ll certainly need it. There’s smoke on the horizon, and scanning activity doesn’t rise like this unless the predators are nearby. Patch your stuff, monitor your traffic, and think about switching before your network ends up on some ransomware bingo card. As always, GadgetLad will be watching for you—so you don’t have to lament over your configuration files later.
Visit gadgetlad.co.uk for more unfiltered tech reviews, rants, and the occasional nugget of helpful advice.

