menu
techminis

A naukri.com initiative

google-web-stories
source image

Securityaffairs

2w

read

259

img
dot

Image Credit: Securityaffairs

China-linked group UNC5221 exploited Ivanti Connect Secure zero-day since mid-March

  • Ivanti has addressed a critical remote code execution flaw in Connect Secure, which has been exploited by a China-linked group since mid-March 2025.
  • The vulnerability, tracked as CVE-2025-22457, is a stack-based buffer overflow that allows remote unauthenticated remote code execution.
  • The flaw impacts Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA gateways. Ivanti has released security updates to address the vulnerability.
  • The China-linked group UNC5221 has been exploiting the vulnerability to deploy TRAILBLAZE, BRUSHFIRE, and SPAWN malware since March 2025.

Read Full Article

like

15 Likes

For uninterrupted reading, download the app