cognitive cybersecurity intelligence

News and Analysis

Search

Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE Malware

Ivanti has patched a critical security vulnerability, CVE-2025-22457, that could have allowed remote, unauthenticated attackers to execute arbitrary code on its Connect Secure product. The company also fixed several other vulnerabilities in its products. Google-owned Mandiant observed evidence of exploitation of CVE-2025-22457 in mid-March 2025, attributed to a China-nexus adversary, UNC5221. This marks the first time UNC5221 has been identified as exploiting a security flaw in Ivanti devices.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts