cloud.google.com Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
Article Content
- •CVE-2025-22457 allows unauthenticated remote code execution in Ivanti products.
- •Exploitation was confirmed by Mandiant, with evidence dating back to mid-March 2025.
- •Threat actor UNC5221, linked to China, deployed new malware following the exploit.
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and evidence of exploitation was observed in mid-March 2025. Threat actor UNC5221, linked to China, successfully exploited the vulnerability, deploying new malware families TRAILBLAZE and BRUSHFIRE. The patch for this vulnerability was released on February 11, 2025, but the threat actor managed to reverse engineer it to exploit earlier versions. Ivanti and Mandiant have urged customers to upgrade their systems immediately to mitigate the risk. The incident highlights the ongoing threat posed by state-sponsored actors who can exploit vulnerabilities even after patches are issued.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track China-Nexus, Brushfire and Ivanti Policy Secure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310 On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…