ThreatPaper

Page 2 of 2

Earlier Research

In January 2024, multiple Chinese APT clusters (UNC5221, UNC5325) exploited two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances — CVE-2024-21893 (SAML authentication bypass) and CVE-2024-21887 (command injection) — compromising 1,700+ organizations globally in one of the largest VPN appliance exploitation campaigns to date.

State-SponsoredSupply Chain Attack

Weekly Digest

New research, once a week. No vendor pitches.

About ThreatPaper

Structured, technical research on real high-impact cybercrime incidents. Not news. Not CVE feeds. Verified, cited, educational.

Learn more →