FireEye and networking company Pulse Secure say two China-linked hacking groups used a flaw in its VPN devices to target customers in the US defense industry
Exploitation of Pulse Connect Secure VulnerabilitiesΒ βΒ Summary Department of Homeland Security : Emergency Directive 21-03Β βΒ Mitigate Pulse Secure Product Vulnerabilities CNN : Suspected Chinese hackers exploited Pulse Secure VPN to compromise βdozensβ of agencies and companies in US and Europe TechRadar : Nasty VPN vulnerability used to eavesdrop on companies across the globe Jessica Davis / HealthITSecurity : DHS CISA: Critical Pulse Secure VPN Vulnerabilities Under Active Attack CISA : CISA Issues Emergency Directive Requiring Federal Agencies to Check Pulse Connect Secure Products BeauHD / Slashdot : Hackers Are Exploiting a Pulse Secure 0-Day To Breach Orgs Around the World Sean Lyngaas / CyberScoop : State-linked hackers hit American, European organizations with Pulse Secure exploits Zeljka Zorz / Help Net Security : Attackers are exploiting zero-day in Pulse Secure VPNs to breach orgs (CVE-2021-22893) Keumars Afifi-Sabet / cloudpro.co.uk : Hackers exploit Pulse Secure VPN flaws in sophisticated global campaign Ravie Lakshmanan / The Hacker News : WARNING: Hackers Exploit Unpatched Pulse Secure 0-Day to Breach Organizations iTnews : Hackers used Pulse Secure flaw to target US defence industry Reuters : China-linked hackers accused of spying on US defence industry Tweets: @seattletimes : Chinese government hackers are believed to have compromised dozens of U.S. government agencies, defense contractors, financial institutions and other critical sectors, says a private firm working with the government. The intrusions are ongoing. https://www.seattletimes.com/ ... @summer__heidi : The hackers were operating from U.S. digital infrastructure and borrowing the naming conventions of their victims to camouflage their activity so they would look like any other employee logging in from home. https://www.reuters.com/... Kevin Beaumont / @gossithedog : π¨ SonicWall have now published an advisory saying these patches were for zero day, in the wild attacks on customers π¨ CVSS 9.8 pre-auth RCE. Patch last week. https://www.sonicwall.com/... Catalin Cimpanu / @campuscodi : DHS has released an emergency directive (yes, another one) and has ordered federal agencies to patch their Pulse Secure appliances by Friday It also ordered agencies to run Pulse's security integrity tool every hour until a patch or mitigation is applied https://cyber.dhs.gov/... https://twitter.com/... Sean Wright / @seanwrightsec : Goes without saying patch ASAP if you running Pulse Secure: https://arstechnica.com/... Brian Fung / @b_fung : For months, hackers with suspected ties to China have exploited Pulse Secure VPN to break into government agencies, defense contractors and financial institutions in US and Europe, according to a new @FireEye report: https://www.cnn.com/... His Royal Thighness / @r0wdy_ : CISA is really hammering home the scheduled task talking point. Probably for a good reason. https://twitter.com/... Eric Geller / @ericgeller : FireEye reports that hackers, including a suspected Chinese group, are exploiting Pulse Secure VPN vulnerabilities to target orgs including DIB companies: https://www.fireeye.com/... CISA says govt agencies and critical infrastructure companies breached: https://us-cert.cisa.gov/... @cisagov : Organizations using Ivanti Pulse Connect Secure appliances are encouraged to run the Ivanti Integrity Checker Tool, update to the latest software version, and investigate for malicious activity. Learn more in our Activity Alert: https://us-cert.cisa.gov/... https://twitter.com/... Martijn Grooten / @martijn_grooten : What Paul says, but also: if your org runs _any_ kind of remote access/VPN solution, make sure you are set up to a) receive security alerts as soon as they are published and b) apply relevant patches or mitigations immediately. https://twitter.com/... Maddie Stone / @maddiestone : Pulse Secure VPN 0-day being exploited in-the-wild, CVE-2021-22893. Mitigation instructions here: https://kb.pulsesecure.net/... https://twitter.com/... Cert-Bund / @certbund : Pulse Connect Secure SSL #VPN gateway admins should deploy the workaround as soon as possible and use the integrity tool to check possible compromise. According to @fireeye βa final patch to address the vulnerability will be available in early May 2021β πhttps://www.fireeye.com/ ... https://twitter.com/... Sean Lyngaas / @snlyngaas : And CISA confirms that βU.S. government agenciesβ and βcritical infrastructure entitiesβ have been breached in this campaign: https://us-cert.cisa.gov/...
Context & Ripple Effects
The report extends FireEyeβs earlier account of suspected China-linked activity against U.S. engineering and defense companies, identifying VPN devices as the access point for customers in the defense sector. It also turns vendor and threat-research findings into an operational federal response: CISAβs Emergency Directive 21-03 requires agencies to mitigate Pulse Connect Secure vulnerabilities.
The incident sits within a broader pattern in the supplied coverage: China-linked groups were also reported targeting healthcare research and medical-device intellectual property, while a later joint advisory described exploitation of publicly known flaws to inspect network traffic.
First-order effects
- Federal agencies using affected Pulse Connect Secure products must check and mitigate the vulnerabilities under CISAβs emergency directive, while Pulse Secure customers in government, defense, finance and Europe face incident-response work after reported compromises.
- FireEye and Pulse Secureβs findings put the VPN productβnot only targeted organizationsβ internal systemsβat the center of remediation for the reported defense-industry campaign.
Second-order effects
- Defense contractors and other organizations connected through Pulse Secure must treat remote-access infrastructure as a shared exposure, increasing pressure on their suppliers and service teams to validate mitigations quickly.
- CISAβs directive turns threat reporting into a coordinated customer response, making federal vulnerability handling more consequential for vendors whose products are deployed across agencies.
Third-order effects
- If exploitation of externally exposed VPN flaws continues across sectors, cybersecurity programs will increasingly concentrate on rapid remediation of widely deployed edge products rather than relying on perimeter access as a stable control.
- The pattern points toward a tighter security-to-policy pipeline in which attribution and vendor incident reports can trigger mandatory action for public-sector users.
The trend: China-linked intrusion campaigns are exploiting broadly deployed remote-access products, pushing vulnerability disclosure and mitigation into a more coordinated public-private defense process.