Suspected Chinese spies right now hijacking buggy Ivanti gear – for third time in 3 years
ID: 7f47463b-acbb-5d03-8894-c90bbfdd1545
STIX ID: report--7f47463b-acbb-5d03-8894-c90bbfdd1545
Feed Name: The Register (Security)
Suspected China-linked espionage group UNC5221 has been actively exploiting a critical Ivanti Connect Secure stack-based buffer overflow (CVE-2025-22457) since mid-March to achieve unauthenticated remote code execution on affected VPN/edge appliances; post-exploit activity observed by Mandiant and Google includes in-memory execution of Trailblaze, injection of Brushfire (a passive backdoor), and deployment of Spawn variants. Ivanti released a patch (22.7R2.6) and warned that end-of-support Pulse appliances remain vulnerable, while responders urge rapid patching or migration due to active exploitation and the high operational tempo of the threat actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
