United States
USA
MITRE disclosed on 19 April 2024 that a foreign nation-state actor had compromised its NERVE research, development and prototyping network after exploiting Ivanti Connect Secure zero-day vulnerabilities. MITRE took NERVE offline and established alternative collaboration arrangements while restoration proceeded; its core enterprise network and partners' systems were not affected. MITRE later said the activity aligned with UNC5221.
Estimated severity
69 / 100
Source reliability
83 / 100
Approximate Date
19/04/2024
Targeted Company
MITRE
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone