Ivanti Commits to Enhanced Security Measures Following Disclosure of 4 New Vulnerabilities

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Ivanti Announces Security Overhaul Amid Fresh Set of Bugs In Connect Secure and Policy Secure Products

Ivanti CEO Jeff Abbott has announced a complete overhaul of the company’s security practices in response to a series of bug disclosures in its Ivanti Connect Secure and Policy Secure remote access products. This comes after Ivanti disclosed four new bugs this week, including high-severity vulnerabilities that pose a risk to customers.

In an open letter to customers, Abbott outlined a series of changes that Ivanti will implement in the coming months to enhance its security operating model. This includes a revamp of engineering, security, and vulnerability management processes, as well as the implementation of a new secure-by-design initiative for product development.

These changes aim to embed security into every stage of the software development life cycle and enhance internal vulnerability discovery and management processes. Additionally, Ivanti plans to increase incentives for third-party bug hunters and provide more resources to customers for finding vulnerability information.

Despite these commitments, some customers remain skeptical due to Ivanti’s recent security track record, which includes a total of 11 vulnerabilities disclosed since January. Security researcher Jake Williams notes that many Fortune 500 clients view Ivanti’s response as “too little, too late,” raising concerns about the security of Ivanti’s products.

The steady stream of bug disclosures has led to questions about the risk posed to Ivanti’s 40,000 customers worldwide. Some customers have expressed frustration, while competitors like Cisco have seized the opportunity to offer incentives to lure Ivanti VPN customers to their platforms.

Analyst Eric Parizo attributes some of Ivanti’s challenges to its history of acquisitions, resulting in uneven software quality. However, he sees Ivanti’s commitment to improving security processes as a positive step and suggests that indemnifying customers for damages from vulnerabilities could help restore confidence in the company.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

FQ-42 Vengeance unmanned fighter aircraft displayed at AFA 2026

The FQ-42 Vengeance unmanned fighter aircraft, developed by General Atomics, was prominently displayed at the Air, Space and Cyber conference on September 14, 2026....

Meta’s AI Assistant Muse Exposed by Zero-Day Vulnerability, Prompting Amazon to Block Access

Meta's new AI assistant, Muse, has come under scrutiny following the discovery of a zero-day vulnerability that allows locally run applications and terminal commands...

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...