Computer Security News

2,048 Ivanti VPN Instances Vulnerable to Exploited Zero-Day Attacks

A critical security vulnerability in Ivanti Connect Secure VPN appliances has left 2,048 instances worldwide exposed to potential exploitation, with the United States hosting the highest number of vulnerable systems.

The vulnerability tracked as CVE-2025-0282, has been actively exploited since mid-December 2024.

The vulnerability is a critical stack-based buffer overflow with a CVSS score of 9.0 that allows unauthenticated remote code execution. It affects multiple Ivanti products, including Connect Secure versions prior to 22.7R2.5, Policy Secure prior to 22.7R1.2, and Neurons for ZTA gateways prior to 22.7R2.3.

Shadowserver observed that 2,048 instances worldwide are vulnerable.

Mandiant’s investigation revealed that threat actors are executing sophisticated attacks using version-specific exploitation techniques. The attack sequence typically involves:

  • Initial reconnaissance to identify appliance versions
  • Disabling of security features, including SELinux
  • Filesystem remounting for write access
  • Deployment of web shells for persistence
  • Removal of log entries to avoid detection

The exploitation has been linked to UNC5337, a China-nexus threat group, though multiple threat actors appear to be involved.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

The attackers have deployed various malware families, including DRYHOOK and PHASEJAM, demonstrating sophisticated capabilities in maintaining persistent access and facilitating data theft.

Mitigation Steps

Ivanti has released emergency patches for Connect Secure (version 22.7R2.5), while updates for Policy Secure and Neurons for ZTA are scheduled for January 21, 2025. The company strongly recommends that organizations:

  • Immediately apply available patches
  • Monitor systems using the Integrity Checker Tool (ICT)
  • Perform both internal and external ICT scans
  • Conduct factory resets before upgrading to the latest version

The widespread exploitation of this vulnerability follows a pattern of critical zero-day attacks against Ivanti products, including previous incidents that affected major organizations and government agencies.

With thousands of systems still vulnerable, security experts warn of a potential escalation in exploitation attempts by both nation-state actors and cybercriminal groups.

Find this News Interesting! Follow us on Google NewsLinkedIn, and X to Get Instant Updates!

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago