logo

CISA warns of latest Ivanti firewall bug being exploited by suspected Chinese hackers

ID: f1120496-d44e-59d3-b857-84e10c06f566

STIX ID: report--f1120496-d44e-59d3-b857-84e10c06f566

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-04-04

Date Updated: 2026-05-01

...
...

Ivanti disclosed that a critical vulnerability (CVE-2025-22457) affecting Connect Secure, Policy Secure and ZTA Gateways is being actively exploited by a suspected China-based actor tracked as UNC5221; CISA and multiple vendors confirmed attacks in which malware ecosystems including Spawn and a backdoor named Brushfire were deployed. Ivanti released a patch (Feb 11) and mitigation guidance, but warned that end-of-support appliances remain at risk and advised use of an integrity checker and factory resets for compromised devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.