CISA warns of latest Ivanti firewall bug being exploited by suspected Chinese hackers
ID: f1120496-d44e-59d3-b857-84e10c06f566
STIX ID: report--f1120496-d44e-59d3-b857-84e10c06f566
Feed Name: The Record from Recorded Future News
Ivanti disclosed that a critical vulnerability (CVE-2025-22457) affecting Connect Secure, Policy Secure and ZTA Gateways is being actively exploited by a suspected China-based actor tracked as UNC5221; CISA and multiple vendors confirmed attacks in which malware ecosystems including Spawn and a backdoor named Brushfire were deployed. Ivanti released a patch (Feb 11) and mitigation guidance, but warned that end-of-support appliances remain at risk and advised use of an integrity checker and factory resets for compromised devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
