logo

Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor

ID: 2aa6dd07-03c2-54e9-83be-7ee26401593f

STIX ID: report--2aa6dd07-03c2-54e9-83be-7ee26401593f

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

...
...

On April 3, 2025 Ivanti disclosed CVE-2025-22457, a critical unauthenticated buffer-overflow RCE affecting Ivanti Connect Secure and other products; despite a February 11, 2025 patch, evidence from mid-March 2025 shows UNC5221 (China-linked) exploited the flaw—reverse-engineering the patch—to deploy new malware families named TRAILBLAZE and BRUSHFIRE, prompting urgent upgrade advisories from Ivanti and Mandiant.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.