APT41 Exploits Critical Flaw in VPN Appliances

State-sponsored group targeting unpatched Pulse Secure gateways worldwide. Over 2,000 organizations affected.

CISA has issued an emergency alert regarding APT41, a state-sponsored threat group, exploiting a critical vulnerability in Pulse Secure VPN appliances. Over 2,000 organizations across multiple sectors have been affected globally.

The group is using the compromised VPN appliances as initial access points, then moving laterally within victim networks to deploy custom backdoors and exfiltrate sensitive data.

Organizations using Pulse Secure appliances are urged to immediately apply the latest patches and conduct forensic analysis to determine if they have been compromised.

Source: CISA Alert