logo

Threat Brief: CVE-2025-0282 and CVE-2025-0283 (Updated Jan. 17)

ID: 7aca0527-f11b-5965-bd04-62785df1e2ce

STIX ID: report--7aca0527-f11b-5965-bd04-62785df1e2ce

Feed Name: Palo Alto Networks Unit 42

Threat Score
82/100

Date Published: 2025-01-17

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 reports active exploitation of a critical stack‑based buffer overflow (CVE‑2025‑0282) in Ivanti Connect Secure appliances enabling unauthenticated remote code execution, with observed intrusions following a four‑phase pattern (initial access, credential harvesting and lateral movement, defense evasion, persistence); the brief includes malware and tooling analysis (ldap.pl, package.dll, DLL sideloading backdoors), related IOCs (C2 IPs, hashes, hostnames), and recommends applying Ivanti patches and Palo Alto Networks product protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.