Initial Access Brokers are deploying patches to exploited vulnerabilities to effectively lock out rival cybercriminals.

Initial Access Brokers are deploying patches to exploited vulnerabilities to effectively lock out rival cybercriminals.

A recent cyber campaign has brought to light a sophisticated new tactic employed by initial access brokers, believed to be linked to China. These threat actors are leveraging zero-day vulnerabilities in Ivanti Connect Secure systems to infiltrate target networks. Uniquely, after gaining access, the attackers are applying their own patches to the exploited vulnerabilities, effectively locking out both defenders and rival cybercriminals.