
Two zero-days in Ivanti Connect Secure VPN, discovered roughly a week ago, are now being massively exploited by threat actors, security researchers have said.
In a blog post, cybersecurity researchers from Volexity (who first discovered the flaws together with Mandiant) claim to have observed evidence of mass exploitation. That includes more than 1,700 Ivanti Connect Secure appliances worldwide that fell prey to different threat actors.