logo

Fixed Ivanti Bugs Still Haunt Japan Orgs 6 Months Later

ID: 712646a2-46fd-592a-b803-4369bcd0d31d

STIX ID: report--712646a2-46fd-592a-b803-4369bcd0d31d

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-07-24

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Ivanti Connect Secure critical vulnerabilities (CVE-2025-0282 CVSS 9.0 and CVE-2025-22457 CVSS 9.8) have been actively exploited since December 2024 by China-linked UNC5221 and other actors in Japan; initial access tools (SpawnChimera, DslogdRAT) and subsequent loaders/RATs (MDifyLoader, Fscan, vshell) enabled prolonged lateral movement and persistence, while a large number of Japanese Connect Secure devices remain unpatched due to EOL hardware and migration/patching barriers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.