In January of 2024, a US government agency initiated an investigation with CPIRT following suspicious RDP (Remote Desktop Protocol) connections to one of their devices. This event occurred in the wake of two critical CVEs (CVE-2023-46805 and CVE-2024-21887) potentially impacting their Ivanti VPN. The customer’s team, along with the Check Point Incident Response Team (CPIRT), embarked on a forensic analysis to assess the extent of the breach.
In this CPIRT blog post, we will dive into the vulnerabilities exploited, the actions of the threat actor, the investigation logs, and the lessons learned.
Read More