Ivanti Connect Secure VPN Targeted in New Zero-Day Exploitation
ID: 21742a5c-e268-5243-9e9b-ab090ed0e8ef
STIX ID: report--21742a5c-e268-5243-9e9b-ab090ed0e8ef
Feed Name: Google Cloud Threat Intelligence
On Jan 8, 2025 Mandiant and Ivanti disclosed active exploitation of Ivanti Connect Secure vulnerabilities—most notably CVE-2025-0282, an unauthenticated stack-based buffer overflow enabling remote code execution that was observed exploited in the wild beginning mid-December 2024. Mandiant attributes the campaign to UNC5221 (a suspected China-nexus espionage actor) which previously leveraged other Ivanti CVEs and a set of custom malware (ZIPLINE, THINSPOOL, LIGHTWIRE, WARPWIRE) and tunneling/post-exploitation tools; Ivanti has released patches and customers are urged to follow the security advisory to remediate affected appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
