New zero-day exploit targets Ivanti VPN product
ID: f409741e-54c7-544f-b746-b35b4dbd169c
STIX ID: report--f409741e-54c7-544f-b746-b35b4dbd169c
Feed Name: CyberScoop
Threat Score
Ivanti disclosed two vulnerabilities (CVE-2025-0282 and CVE-2025-0283) in Ivanti Connect Secure appliances; Mandiant reported active zero‑day exploitation of CVE-2025-0282 (an unauthenticated stack‑based buffer overflow) beginning in mid‑December, observed malware families (SPAWN, DRYHOOK, PHASEJAM) on compromised systems, and associated some activity with China‑linked UNC5337; CISA added the issue to its Known Exploited Vulnerabilities catalog and Ivanti released patches and guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
