Ivanti’s Patch Predicament: 5,000+ Vulnerable Devices Awaiting Attention
The Shadowserver Foundation warns over 5,000 Ivanti Connect Secure appliances are still vulnerable to CVE-2025-22457. Despite February’s fix, attacks by Chinese hackers persist. Users are urged to update, but many Pulse Connect Secure 9.x devices remain unpatched, as their support ended in December. Time to patch up before hackers get too comfortable!

Hot Take:
**_Looks like Ivanti just pulled the classic “Oops, I did it again” move, misdiagnosing a major security flaw as a production bug. Meanwhile, a Chinese hacking group is playing whack-a-mole with over 5,000 unpatched appliances. Time to patch things up, folks!_**
Key Points:
– A vulnerability in Ivanti Connect Secure, CVE-2025-22457, allows remote code execution.
– The flaw was misdiagnosed by Ivanti as a production issue, despite ongoing in-the-wild exploitation.
– Chinese hacking group UNC5221 has been exploiting the vulnerability since March.
– Over 5,000 internet-accessible Ivanti appliances remain unpatched.
– Older Pulse Connect Secure 9.x appliances won’t receive patches due to discontinued support.