Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
ID: 71974df6-919b-5432-9ffc-abc7064771a5
STIX ID: report--71974df6-919b-5432-9ffc-abc7064771a5
Feed Name: ThreatCluster
Threat Score
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow in Ivanti Connect Secure enabling unauthenticated remote code execution; evidence of exploitation was observed in mid-March 2025. Threat actor UNC5221, linked to China, exploited the flaw—despite a February 11, 2025 patch—by reverse engineering the fix and deploying new malware families called TRAILBLAZE and BRUSHFIRE; Ivanti and Mandiant urged immediate upgrades to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
