Ivanti VPN Bugged Again: Chinese Spies Unleash Malicious Malware Mayhem!

Chinese government spies have been exploiting a critical bug in Ivanti VPN appliances since mid-March, the third time in three years. The Beijing-backed crew also deployed two new malware strains. Ivanti detailed the 9.0-out-of-10-severity vulnerability, CVE-2025-22457, which allows unauthenticated remote code execution. Patch now, or else!

Pro Dashboard

Hot Take:

Looks like the Ivanti VPN appliances are the “favorite toy” for Beijing’s cyber-spies. Three times in three years? Talk about being in a toxic relationship! Maybe it’s time for Ivanti to break up with those zero-days for good. Meanwhile, China seems to be launching a VPN crash course, complete with a side of malware. Stay tuned for their next episode of “Hackers Gone Wild.”

Key Points:

  • Ivanti’s VPN appliances are under attack by suspected Chinese government spies exploiting a critical bug, CVE-2025-22457.
  • The vulnerability allows remote code execution and has been exploited alongside two new malware strains and Spawn variants.
  • UNC5221, a suspected Beijing-backed crew, has been using this exploit since mid-March 2023.
  • Mandiant highlighted the ongoing threat, emphasizing the rapid pace of cyber intrusions by China-nexus espionage groups.
  • Ivanti’s advisory urges customers to patch their systems immediately to prevent further exploitation.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?