• News/
  • https://www.theregister.com/2025/04/03/suspected_chines_snoops_hijacked_buggy/

Suspected Chinese snoops hijacking buggy Ivanti gear — again

The Register
·
Jessica Lyons
·
Published Apr 3, 2025
·
Updated

Suspected Chinese government spies have been exploiting a newly disclosed critical bug in Ivanti VPN appliances since mid-March. This is now at least the third time in three years these snoops have been pwning these products. Plus, post-exploit, the Beijing-backed crew deployed on compromised Ivanti equipment two new malware strains along with variants of the Spawn software nasty, we're told. Ivanti today detailed the under-attack 9.0-out-of-10-severity vulnerability, tracked as CVE-2025-22457, and said it affects Ivanti Connect Secure (version 22.7R2.5 and earlier), Pulse Connect Secure 9.x (end-of-support as of December 31), Ivanti Policy Secure, and ZTA gateways. The alert comes just days after the US government warned a new form of Spawn was being used in attacks exploiting an earlier Ivanti zero-day, this one tracked as CVE-2025-0282, in these same products. The new critical bug, CVE-2025-22457, is a stack-based buffer overflow flaw that can lead to unauthenticated remote code execution (RCE); the vendor fixed this in Ivanti Connect Secure 22.7R2.6, released in February. We don't have enough visibility at this time to provide an accurate estimate, but given how fast this threat actor operates, it's imperative that companies move quickly to patch to limit the impact At the time, this CVE was believed to be a low-risk, denial-of-service bug. It turns out the vulnerability wasn't so low risk and could be exploited to achieve RCE, as UNC5221, a suspected Beijing-run espionag...

Read full article

Affected Software

10 affected components
Ivanti Connect Secure=22.7R2.5
Ivanti Pulse Connect Secure=9.x
Ivanti Policy Secure
Ivanti ZTA gateways
NetScaler ADC
NetScaler Gateway appliances
Ivanti Connect Secure=22.7R2.5
Ivanti Pulse Connect Secure=9.x
Ivanti Policy Secure
Ivanti ZTA gateways
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how suspected Chinese government spies have exploited a critical vulnerability in Ivanti VPN appliances.

2

What security implications are discussed?

The article highlights the ongoing cyber espionage activity targeting Ivanti products, which presents severe risks to organizations using these systems.

3

What products or software are affected?

The affected products include Ivanti Connect Secure, Ivanti Pulse Connect Secure, Ivanti Policy Secure, and Ivanti ZTA gateways.

4

How long has the vulnerability been exploited?

The vulnerability has been actively exploited since mid-March 2025.

5

Is this the first time these Ivanti products have been targeted?

No, this is at least the third time in three years that these Ivanti products have been compromised by suspected Chinese state actors.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203