Page 2 of 2
Earlier Research
Ivanti Connect Secure Mass Exploitation (CVE-2024-21893, CVE-2024-21887): Chinese APT VPN Appliance Compromise at ScaleState-SponsoredSupply Chain Attack
In January 2024, multiple Chinese APT clusters (UNC5221, UNC5325) exploited two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances — CVE-2024-21893 (SAML authentication bypass) and CVE-2024-21887 (command injection) — compromising 1,700+ organizations globally in one of the largest VPN appliance exploitation campaigns to date.
State-SponsoredSupply Chain Attack
BROWSE BY CATEGORY13 CATEGORIES
1Data Breach
82Ransomware
23Financial Fraud
34State-Sponsored
55Social Engineering
16Malware
27Supply Chain Attack
108Darknet & Illicit Markets
19Cryptocurrency & Web3
110Identity Theft
111Extortion & Blackmail
212AI & Machine Learning
113OT & Industrial Systems
1Weekly Digest
New research, once a week. No vendor pitches.
About ThreatPaper
Structured, technical research on real high-impact cybercrime incidents. Not news. Not CVE feeds. Verified, cited, educational.
Learn more →