Ivanti VPN Bugged Again: Chinese Spies Unleash Malicious Malware Mayhem!
Chinese government spies have been exploiting a critical bug in Ivanti VPN appliances since mid-March, the third time in three years. The Beijing-backed crew also deployed two new malware strains. Ivanti detailed the 9.0-out-of-10-severity vulnerability, CVE-2025-22457, which allows unauthenticated remote code execution. Patch now, or else!

Hot Take:
Looks like the Ivanti VPN appliances are the “favorite toy” for Beijing’s cyber-spies. Three times in three years? Talk about being in a toxic relationship! Maybe it’s time for Ivanti to break up with those zero-days for good. Meanwhile, China seems to be launching a VPN crash course, complete with a side of malware. Stay tuned for their next episode of “Hackers Gone Wild.”
Key Points:
- Ivanti’s VPN appliances are under attack by suspected Chinese government spies exploiting a critical bug, CVE-2025-22457.
- The vulnerability allows remote code execution and has been exploited alongside two new malware strains and Spawn variants.
- UNC5221, a suspected Beijing-backed crew, has been using this exploit since mid-March 2023.
- Mandiant highlighted the ongoing threat, emphasizing the rapid pace of cyber intrusions by China-nexus espionage groups.
- Ivanti’s advisory urges customers to patch their systems immediately to prevent further exploitation.
Already a member? Log in here