CVE-2025-0282 and CVE-2025-0283: Critical Ivanti 0days Exploited in the Wild
ID: 5c0591b2-dca1-5d01-8db5-6212a2e12efa
STIX ID: report--5c0591b2-dca1-5d01-8db5-6212a2e12efa
Feed Name: Wiz Blog
Ivanti has confirmed active exploitation of CVE-2025-0282 (an unauthenticated RCE zero-day) and CVE-2025-0283 in Ivanti Connect Secure appliances; Mandiant observed exploitation since December 2024 with multiple malware families and IOCs (including DRYHOOK and PHASEJAM) and some activity attributed to the China-nexus cluster UNC5337. The report details attacker reconnaissance and post-exploitation behaviors (web shells, disabling SELinux, tunneling, credential theft, log tampering), lists affected products and file-based IOCs, and urges customers to upgrade appliances, use Ivanti's ICT, and perform factory reset/reinstall if compromise is detected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
