Threat Brief: CVE-2025-0282 and CVE-2025-0283 (Updated Jan. 17)
ID: 7aca0527-f11b-5965-bd04-62785df1e2ce
STIX ID: report--7aca0527-f11b-5965-bd04-62785df1e2ce
Feed Name: Palo Alto Networks Unit 42
Unit 42 reports active exploitation of a critical stack‑based buffer overflow (CVE‑2025‑0282) in Ivanti Connect Secure appliances enabling unauthenticated remote code execution, with observed intrusions following a four‑phase pattern (initial access, credential harvesting and lateral movement, defense evasion, persistence); the brief includes malware and tooling analysis (ldap.pl, package.dll, DLL sideloading backdoors), related IOCs (C2 IPs, hashes, hostnames), and recommends applying Ivanti patches and Palo Alto Networks product protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
