Ivanti has disclosed two severe vulnerabilities affecting its Connect Secure VPN appliances. The vulnerabilities have raised concerns due to potential network breaches. One of these, CVE-2025-0282, is being actively exploited and enables remote code execution without authentication. Mandiant, a cybersecurity firm, has identified various malware families associated with this exploitation. While one of the malware, SPAWN, has been linked to Chinese actor UNC5337, attribution for all activity related to the vulnerability is yet to be confirmed.
Mandiant reveals details of major Ivanti VPN vulnerability
Cybersecurity firm Mandiant has discovered a zero-day vulnerability in Ivanti Connect Secure VPN appliances being exploited by a potential China-linked cyber-espionage group. With no clear