Story perspectives
Chinese Hackers Exploit Critical Ivanti VPN Flaw
1/12/2025
26 2
1 of 1
Story summary
- Chinese cyberespionage exploits a critical zero-day flaw (CVE-2025-0282) in Ivanti Connect Secure VPN appliances, enabling remote code execution.
- Ivanti has confirmed the flaw's exploitation and issued a patch (version 22.7R2.5) to resolve the issue.
- Mandiant reported attacks utilizing SPAWN, PHASEJAM, and DRYHOOK malware associated with Chinese hackers.
- Ivanti recommends users upgrade and perform factory resets; other Ivanti products are not impacted.
