Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
ID: 2aa6dd07-03c2-54e9-83be-7ee26401593f
STIX ID: report--2aa6dd07-03c2-54e9-83be-7ee26401593f
Feed Name: ThreatCluster
Threat Score
On April 3, 2025 Ivanti disclosed CVE-2025-22457, a critical unauthenticated buffer-overflow RCE affecting Ivanti Connect Secure and other products; despite a February 11, 2025 patch, evidence from mid-March 2025 shows UNC5221 (China-linked) exploited the flaw—reverse-engineering the patch—to deploy new malware families named TRAILBLAZE and BRUSHFIRE, prompting urgent upgrade advisories from Ivanti and Mandiant.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
