{"id":4364,"date":"2024-07-09T09:00:00","date_gmt":"2024-07-09T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cisa-takedown-ivanti-systems-is-wake-up-call"},"modified":"2024-07-09T09:00:00","modified_gmt":"2024-07-09T14:00:00","slug":"cisa-takedown-of-ivanti-systems-is-a-wake-up-call","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/09\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call\/","title":{"rendered":"CISA Takedown of Ivanti Systems Is a Wake-up Call"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt4763a3548c680d5e\/668d410bda01df066035d4a3\/Alarm%281800%29_Simon_Dannhauer_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the wake of the attack on Ivanti&#8217;s asset management software, which&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cisa-orders-disconnecting-ivanti-vpn-appliances-what-to-do\" rel=\"noopener\">prompted decisive action from the Cybersecurity and Infrastructure Security Agency<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;(CISA), what can we learn? This incident raises new questions about exploit techniques, organizational response to security breaches, and the skyrocketing cost of downtime.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First, let&#8217;s break down what happened. From what&#8217;s been disclosed, the vulnerabilities in Ivanti&#8217;s system, particularly its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/more-ivanti-vpn-zero-day-bugs-attack-frenzy-patches-rolling\" rel=\"noopener\">VPN gateway<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, enabled threat actors to bypass authentication and gain unauthorized access. By sending maliciously crafted packets to the VPN gateway, attackers had a free pass to infiltrate the system without needing to steal credentials. Once inside, they could export user credentials \u2014 including domain administrator credentials.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers also exploited a second vulnerability to inject malicious code into the Ivanti appliance, allowing them access to the VPN persistently (e.g., maintaining malicious control despite reboot or patch). An attacker&#8217;s persistent access to a VPN gateway is especially dangerous because the attacker can now move laterally within the VPN,&nbsp;using&nbsp;the gateway\u2019s&nbsp;trusted position to gain access to critical credentials and data. The bottom line: An attack compromising the VPN is bad, but here, the attack enabled the takeover of stored privileged administrative account credentials, which is much worse.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In response, CISA intervened to let organizations know they should assume the theft of critical credentials given the nature of the breach. The bigger concern was Ivanti&#8217;s apparent failure to detect the compromise, leaving attackers free to operate within a trusted zone, bypassing zero-trust principles, and posing heightened risks to sensitive data.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Prompted by the severity of the vulnerabilities and potential for widespread exploitation,&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/ivanti-breach-cisa-systems-offline\" rel=\"noopener\">CISA took further action by taking two of Ivanti&#8217;s systems offline<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. This is an unusual safeguard that was made after careful assessment of the damage and risk.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISA correctly concluded that the risk of theft of privileged administrative credentials stored in trusted enclaves was much greater than the downside of complete shutdown. The calculus was that safeguarding the system&#8217;s crown jewels, the most powerful credentials, required immediate action to minimize the blast radius of the breach, since they could not be sure they could operate the system securely.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As it turns out, Ivanti later clarified that patches could have been deployed discreetly, which would have prevented the need for an entire system downtime. This miscommunication highlights the importance of having clear open channels during a crisis. Mixed messages cause unnecessary chaos.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Measuring Hard and Soft Cost\">Measuring Hard and Soft Cost<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Entire system level downtime is costly. The IT resources required to securely and smoothly administer shutdown and recovery often are compounded by the losses incurred from complete outages of services, user downtime, and downstream effects (such as customers or dependent organizations that experience service outages). Not to mention the reputational and service level agreement considerations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In Ivanti&#8217;s case, we may never really know the exact cost. At the high end, assuming a VPN is mission critical for a portion of the workforce, downtime is a stop-work scenario for that user population and is therefore very expensive. Downstream customers, businesses, and users are also affected. This should be a warning to those of us addressing the aftermath of an attack in terms of weighing the risk &#8220;wake&#8221; that is likely to result in downtime costs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">CISA\u2019s downtime to risk calculation was founded on assessing the &#8220;blast radius&#8221; of the attack. In this case, lateral movement from the VPN gateway was relatively easier because of the gateway&#8217;s naturally trusted position, and the ability of the attacker to export stored credentials \u2014 including for privileged accounts.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The blast radius of this breach was especially large because attackers were able to steal stored credentials and use them to move laterally. Minimizing blast radius of attacks is achieved by building systems using the principle of least privilege (e.g., zero trust). However, a service that stores credentials is inherently one of the \u2014 if not&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">the<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;\u2014 most trusted service in any given system. It is therefore not surprising that CISA made the call to shut it down, rather than risk further compromise.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">So, what&#8217;s the takeaway? The exploitation of vulnerabilities in Ivanti&#8217;s software is a reminder of the threat facing organizations in the digital age. It underscores the need for robust cybersecurity measures and proactive infrastructure design and response strategies to mitigate risks and protect critical assets. Reducing the number of high value targets in IT infrastructure is an important step that minimizes the blast radius of attacks and can therefore reduce the need for broad shutdowns when attacks do happen. Privileged account credentials and stored keys are among the highest value targets, and IT leaders should accelerate adoption of strategies and technologies that minimize or eliminate such targets. As organizations navigate the aftermath of this incident, collaboration, clear communication, and continuous vigilance is essential in safeguarding against future threats.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/cisa-takedown-ivanti-systems-is-wake-up-call\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY In the wake of the attack on Ivanti&#8217;s asset<\/p>\n","protected":false},"author":12,"featured_media":4365,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4364","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/cisa-takedown-of-ivanti-systems-is-a-wake-up-call.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4364","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4364"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4364\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4365"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4364"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4364"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4364"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}