The attackers who exploited Pulse Secure are extremely sophisticated and used their access to steal account credentials and other sensitive data belonging to victim organizations, said Charles Carmakal, FireEye's senior vice president.
"These actors are highly skilled and have deep technical knowledge of the Pulse Secure product," Carmakal said.
Some of the intrusions using the vulnerabilities began as early as August of last year, according to FireEye's report. The group conducting those attacks may be working for the Chinese government, the report said, and Carmakal added that "there are some similarities between portions of this activity and a Chinese actor we call APT5."
Other actors have exploited the vulnerabilities as well, though FireEye said it's unclear whether they may be linked to a particular government.
In a blog post, Pulse Secure said the newly discovered flaw affects a "very limited number of customers" and that a more permanent software update to address that vulnerability will be issued in early May. Software patches already exist for the other vulnerabilities.
"The Pulse Connect Secure (PCS) team is in contact with a limited number of customers who have experienced evidence of exploit behavior on their PCS appliances," Pulse Secure said. "The PCS team has provided remediation guidance to these customers directly."
It added: "Customers are also encouraged to apply and leverage the efficient and easy-to-use Pulse Secure Integrity Checker Tool to identify any unusual activity on their system."
CISA said that since March 31, it has assisted "multiple entities" whose vulnerable products have been exploited by a cyber threat actor.
"CISA has been working closely with Ivanti, Inc. to better understand the vulnerability in Pulse Secure VPN devices and mitigate potential risks to federal civilian and private sector networks," Nicky Vogt, an agency spokesperson, said Tuesday. "We will continue to provide guidance and recommendations to support potentially impacted organizations."
That post exemplifies the root of the problem - a historical legacy of centuries of propaganda based on the premise of European racial supremacy. It portrays the white colonial master that is the savior to the ever thankful poor black slave. Thank God, I’m an emancipated African - and I don’t worship at the feet of white gods - the Queen or the Governor, who are simply relics of outmoded colonialism built on the tenets of racist institutions of white supremacy that colonized and enslaved Africans for centuries.
As Bob Marley said, “Emancipate yourself from mental slavery,” because sometimes, “shit is just shit!”