Ivanti has disclosed two critical vulnerabilities in its Sentry product, scoring 10.0 and 9.9 on the CVSS scale. The most severe flaw allows remote, unauthenticated attackers to execute code with root privileges. Ivanti is urging all Sentry customers to apply patches immediately.
Table of contents
January blues return as Ivanti coughs up exploited EPMM zero-daysDutch data watchdog snitches on itself after getting caught in Ivanti zero-day attacksCredential-stealing crew spoofs VPN clients from Cisco, Fortinet, and othersIvanti patches two zero-days under active attack as intel agency warns customers143 Impressions