The US Department of Homeland Security said federal agencies have likely been compromised through vulnerabilities in products from software company Ivanti Inc.

The U.S. Cybersecurity and Infrastructure Security Agency, known as CISA, is working with organizations that were likely targeted by hackers through vulnerabilities in Pulse Connect Secure . CISA has asked organizations to use a tool designed to detect breaches.
See also: FBI/CISA: Beware! APT hackers target Fortinet FortiOS servers
“CISA is aware of at least five federal agencies that have used the Pulse Connect Secure Integrity Tool and identified indications of possible unauthorized access,” said Matt Hartman, CISA executive. “We are working with each agency to verify whether a breach has occurred and provide support, as appropriate.”
Hartman did not provide further information about the organizations that have been affected.
Hartman's statement comes a week after CISA issued an emergency advisory regarding Ivanti's Pulse Connect Secure products. According to the advisory, companies and organizations using private networks and other Pulse Connect Secure products should take steps to identify and mitigate potential breaches.
See also: FBI-CISA: Phishing emails distribute known malware

The US has not attributed the attacks to a specific hacking group. However, security firm FireEye Inc.recently found that hackers likely linked to Chinaused Pulse Secure VPN to break into dozens of organizations for espionage purposes.
See also: Finnish Parliament: Chinese hackers behind last year's hack?
Ivanti said it is working closely with CISA and other security experts to investigate the incident and contain the malicious activity, which has been detected on a limited number of systems.
According to the company, the Pulse team was quick to suggest ways to mitigate the malicious activity and plans to release a software update in the coming days.
According to leaked data, hackers used flaws in Ivanti products to target federal agencies related to finance, transportation, energy, telecommunications and more.
“This is a very big deal from a national security perspective,” said Charles Carmakal, vice president and chief technology officer at FireEye.
Source: Financial Post
