Ivanti has patched a critical flaw in its Connect Secure VPN reportedly exploited by Chinese state-backed actors. Identified as CVE-2025-22457, the buffer overflow vulnerability was linked to remote code execution attacks using two new malware variants: TRAILBLAZE and BUSHFIRE. Research firm Mandiant advised Ivanti users to upgrade their systems as the threat persists. Ivanti confirmed that their Integrity Checker Tool has successfully detected potential compromises in certain client systems.

SpyCloud Research Shows that Endpoint Detection and Antivirus Solutions Miss Two-Thirds (66%) of Malware Infections
SpyCloud, an identity threat protection company, has found that 66% of malware infections bypass endpoint protection solutions, regardless of their advanced artificial intelligence and telemetry