Daily Security Intel

Archives
Log in
Subscribe
August 10, 2026

[SecurityIntel] 10 Aug | Active Scanning Targets Ivanti Connect Secure Gateways

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, August 10, 2026

INTEL CONFIDENCE  76%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Scanning Targets Ivanti Connect Secure Gateways

CRITICAL

5

C2 IPs

8

OTX IOCs

1

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by active exploitation attempts targeting Ivanti Connect Secure gateways via an unauthenticated remote code execution vulnerability. Additionally, threat actors are leveraging compromised websites to distribute infostealers through fake Google Chrome and Microsoft Edge browser updates. Organizations must also secure exposed Redis instances as automated scanning for unauthenticated database servers continues to surge.

■ CRITICAL STORIES

CRITICAL#1

Active Exploitation of Ivanti Connect Secure Gateways

Threat actors are actively scanning for and exploiting an unauthenticated remote code execution vulnerability in Ivanti Connect Secure gateways to gain initial access to corporate networks.

HIGH#2

Fake Browser Updates Distribute Infostealer Malware

Compromised websites are being used to deliver fake Google Chrome and Microsoft Edge updates, tricking users into executing malicious payloads that steal credentials.

INFO#3

Automated Scanning Surge Against Exposed Redis Instances

Analysts have detected a significant spike in automated scanning targeting unauthenticated Redis servers to execute unauthorized commands and deploy cryptocurrency miners.

■ CVEs IDENTIFIED

[CVE-TBD]

Ivanti Connect Secure — Unauthenticated Remote Code Execution

Critical

[CVE-TBD]

Redis Server — Unauthorized Command Execution via Unauthenticated Access

High

■ THREAT ACTORS

Unknown

APT

Exploiting Ivanti Connect Secure gateways for initial access and persistence.

Unknown

Cybercrime

Distributing infostealers via fake browser update campaigns targeting Chrome and Edge users.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of Ivanti Connect Secure gateways.
T1189
Drive-by Compromise | Fake browser updates delivered via compromised websites.
T1059
Command and Scripting Interpreter | Execution of unauthorized commands on exposed Redis servers.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Ivanti — Connect Secure — Active exploitation of unauthenticated RCE [CVE-TBD] poses immediate compromise risk — SANS ISC

[P2 PATCH NOW]≤72h

Redis — Redis Server — Exposed unauthenticated instances are being actively scanned and exploited — SANS ISC

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply the latest security patches or vendor-provided workarounds for Ivanti Connect Secure to mitigate the active [CVE-TBD] RCE vulnerability.
2[P2] Restrict Redis Server access to trusted internal networks and enable robust authentication to prevent unauthorized command execution.
3[P2] Configure endpoint detection and response (EDR) policies to monitor and block anomalous process execution originating from Google Chrome and Microsoft Edge paths.
4[P3] Monitor network logs for anomalous outbound traffic from Ivanti Connect Secure gateways to unverified external IP addresses.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 11 Aug | Private APN pivot breaches Polish energy sector networks Older → [SecurityIntel] 09 Aug | Metabase Zero-Day Exploited in the Wild
Powered by Buttondown, the easiest way to start and grow your newsletter.