logo

Suspected Chinese spies right now hijacking buggy Ivanti gear – for third time in 3 years

ID: 7f47463b-acbb-5d03-8894-c90bbfdd1545

STIX ID: report--7f47463b-acbb-5d03-8894-c90bbfdd1545

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-04-03

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Suspected China-linked espionage group UNC5221 has been actively exploiting a critical Ivanti Connect Secure stack-based buffer overflow (CVE-2025-22457) since mid-March to achieve unauthenticated remote code execution on affected VPN/edge appliances; post-exploit activity observed by Mandiant and Google includes in-memory execution of Trailblaze, injection of Brushfire (a passive backdoor), and deployment of Spawn variants. Ivanti released a patch (22.7R2.6) and warned that end-of-support Pulse appliances remain vulnerable, while responders urge rapid patching or migration due to active exploitation and the high operational tempo of the threat actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.