Related Threat Clusters
-
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
On April 3, 2025, Ivanti disclosed CVE-2025-22457, a critical buffer overflow vulnerability affecting Ivanti Connect Secure and other products. The vulnerability allows unauthenticated remote code execution, and…
2 articles · Updated June 17, 2026 -
Operation Escaneo Targets Latin American Critical Infrastructure
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
4 articles · Updated June 18, 2026 -
Google Reports 90 Exploited Zero-Day Vulnerabilities in 2025
Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors…
35 articles · Updated March 5, 2026 -
Critical Vulnerability in Ivanti Endpoint Manager Requires Immediate Patching
Ivanti has issued security updates for a critical vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) product. This flaw could allow remote, unauthenticated attackers to execute arbitrary JavaScript code,…
6 articles · Updated December 10, 2025 -
CISA Issues Update on RESURGE Malware Targeting Ivanti Devices
CISA has released updated findings on RESURGE, a malware implant exploiting CVE-2025-0282 to compromise Ivanti Connect Secure devices. This malware can remain undetected and utilize advanced evasion techniques for…
11 articles · Updated February 27, 2026 -
Chinese Hackers Exploit Vulnerability in Ivanti VPN Software
In early 2024, the US government issued an emergency order for all civilian federal agencies to disconnect the Connect Secure VPN software made by Ivanti Inc. due to a breach by Chinese hackers. The hackers infiltrated…
7 articles · Updated February 19, 2026
Recent Intelligence Reports
- Mandiant and Google's Threat Intelligence Group documented — cloud.google.com · July 29, 2026
- LATAM Infrastructure Hit by Fortinet and Ivanti Exploits — Infosecurity-Magazine · June 18, 2026
- Zero — Csoonline · March 6, 2026
- Look What You Made Us Patch: 2025 Zero — Mandiant · March 5, 2026
- CISA warns that RESURGE malware can be dormant on Ivanti devices — Bleepingcomputer · February 27, 2026
- New CISA guidance targets persistent RESURGE implant as Ivanti Connect Secure threat ... — Industrialcyber.Co · February 27, 2026
- Chinese Hackers Bypassed a U.S. Government VPN, Raising New Cybersecurity Concerns — Gadgetreview · February 20, 2026
- Ivanti patches Endpoint Manager flaw allowing remote code execution — Computing · December 10, 2025