Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Ivanti Uncovers Fresh Vulnerabilities in Connect Secure VPN
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Ivanti Uncovers Fresh Vulnerabilities in Connect Secure VPN

Highlights

  • Ivanti announces new vulnerabilities in Connect Secure VPN.

  • Chinese-linked groups exploit these security flaws.

  • Immediate patches released to protect affected systems.

Samantha Reed
Last updated: 9 January, 2025 - 8:18 pm 8:18 pm
Samantha Reed 4 months ago
Share
SHARE

A persistent threat to federal agencies has resurfaced as Ivanti, a Utah-based software provider, identifies new security flaws in its Connect Secure VPN products. These vulnerabilities pose significant risks to network integrity, prompting urgent measures to safeguard affected systems. While Ivanti had previously addressed similar issues, the recurrence underscores the evolving nature of cybersecurity threats.

Contents
What Are the Newly Disclosed Vulnerabilities?How Are Threat Actors Exploiting These Vulnerabilities?What Measures Are Being Taken to Address the Issues?

Last year, Ivanti faced widespread scrutiny after vulnerabilities in its VPN solutions led to an emergency directive from the Cybersecurity and Infrastructure Security Agency (CISA). The latest disclosures highlight an ongoing challenge in maintaining robust security measures against sophisticated cyber-attacks, reflecting the company’s continuous efforts to enhance its defenses.

What Are the Newly Disclosed Vulnerabilities?

Ivanti announced the discovery of two critical vulnerabilities, CVE-2025-0282 and CVE-2025-0283, affecting its Connect Secure appliances. These weaknesses allow unauthenticated remote code execution, potentially enabling attackers to compromise entire networks. The immediate release of patches aims to mitigate these risks and protect users from exploitation.

How Are Threat Actors Exploiting These Vulnerabilities?

According to Mandiant, Ivanti enlisted for investigating these vulnerabilities, the CVE-2025-0282 exploit has been active since December of the previous year. The exploitation has been linked to Chinese espionage groups, particularly UNC5337, which is believed to be part of UNC5221. This sophisticated attack strategy involves deploying malware such as SPAWN, DRYHOOK, and PHASEJAM to gain persistent access to victim networks.

What Measures Are Being Taken to Address the Issues?

Ivanti is collaborating with Mandiant, government partners, and security vendors to address the vulnerabilities. The company has released patches and provided detailed instructions to customers for securing their systems.

“We are committed to protecting our users and are actively working to resolve these issues,”

a company spokesperson stated. Additionally, CISA has added the latest vulnerability to its Known Exploited Vulnerability catalog, emphasizing the need for immediate action.

The Integrity Checker Tool, previously criticized by CISA for its inadequacy in detecting compromises, remains a point of contention. Ivanti strongly refutes the claims, maintaining that the tool effectively identifies and mitigates security breaches. This disagreement highlights the complexities in developing and maintaining security solutions that meet evolving threats.

Effective cybersecurity requires continuous monitoring and prompt response to new vulnerabilities. Organizations using Ivanti’s Connect Secure VPN should implement the latest patches and follow recommended security practices to defend against potential threats. Staying informed about emerging vulnerabilities and collaborating with security experts are essential steps in safeguarding digital infrastructure.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

House Bill Proposes Overhaul for Federal Cyber Workforce Training

CIOs Tackle Quantum Threat in Encryption Race

FTC Seeks New Tools to Combat Deepfake Pornography

Cyberattacks Exploit Major Software Vulnerabilities, Affecting Global Infrastructure

North Korea Builds Cyber Network Resembling a Mafia Operation

Share This Article
Facebook Twitter Copy Link Print
Samantha Reed
By Samantha Reed
Samantha Reed is a 40-year-old, New York-based technology and popular science editor with a degree in journalism. After beginning her career at various media outlets, her passion and area of expertise led her to a significant position at Newslinker. Specializing in tracking the latest developments in the world of technology and science, Samantha excels at presenting complex subjects in a clear and understandable manner to her readers. Through her work at Newslinker, she enlightens a knowledge-thirsty audience, highlighting the role of technology and science in our lives.
Previous Article Bio Prototype Innovates Weapon Crafting with Unique Body Part Chains
Next Article Assassin’s Creed Shadows Release Moved to March 2025

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Saildrone Secures $60M to Enhance Maritime Security in Europe
Robotics
Lyall Faces GitHub Suspension, Uploads Patches to NexusMods
Gaming
Best Buy Offers Big Discount on Samsung Galaxy Watch 7
Wearables
Tesla Faces Criticism Before Robotaxi Launch
Electric Vehicle
Qualcomm Teases Future Innovations at Computex 2025
Computing
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?