惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
I
InfoQ
The Register - Security
The Register - Security
L
LangChain Blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
S
Schneier on Security
博客园 - 【当耐特】
W
WeLiveSecurity
Attack and Defense Labs
Attack and Defense Labs
IT之家
IT之家
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Google DeepMind News
Google DeepMind News
The Cloudflare Blog
H
Heimdal Security Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Y
Y Combinator Blog
雷峰网
雷峰网
N
Netflix TechBlog - Medium
Security Archives - TechRepublic
Security Archives - TechRepublic
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
L
Lohrmann on Cybersecurity
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
T
The Exploit Database - CXSecurity.com
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
V
Visual Studio Blog
博客园 - 聂微东
PCI Perspectives
PCI Perspectives
Last Week in AI
Last Week in AI
A
Arctic Wolf
宝玉的分享
宝玉的分享
T
The Blog of Author Tim Ferriss
S
Secure Thoughts
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
云风的 BLOG
云风的 BLOG
D
Darknet – Hacking Tools, Hacker News & Cyber Security
S
SegmentFault 最新的问题
SecWiki News
SecWiki News
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
Schneier on Security
Schneier on Security
P
Proofpoint News Feed
博客园 - Franky
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
AI
AI
Engineering at Meta
Engineering at Meta

The Register - Special Features: Datacenter Networking Nexus

How Broadcom is quietly invading AI infrastructure Cisco punts network-security integration as key for agentic A trip through vintage datacenter networking The network is indeed trying to become the computer Cisco fixes two critical make-me-root bugs AI could finally see DPUs take off in enterprise networks An introduction to rack-scale networking HPE Aruba touts new AI agents and network orchestrator Microsoft to retire default outbound access for VMs in Azure Human error and power glitches to blame for most outages Hyperconverged infrastructure now needs liquid cooling Asia reaches 50 percent IPv6 capability Rising demand for datacenter capacity sees prefabs sprout The No-Nvidia networking club delivers first spec Nvidia punts silicon photonic switches to keep GPUs fed Chinese snoops spotted on end-of-life Juniper routers
Same suspected Chinese spies again attacking Ivanti bugs
Jessica Lyons Jessica Lyons · 2025-05-23 · via The Register - Special Features: Datacenter Networking Nexus

Datacenter Networking Nexus

Ivanti makes dedicated fans of Chinese spies who just can't resist attacking its buggy kit

If it ain't broke?

A suspected Chinese government spy group is behind the rash of attacks that exploit two Ivanti bugs that can be chained together to achieve unauthenticated remote code execution (RCE), according to analysts at threat intelligence outfit EclecticIQ.

The exploits began on May 15, we're told, and targeted organizations in the healthcare, telecommunications, aviation, municipal government, finance, and defense sectors. Attackers went after entities across Europe, North America, and Asia-Pacific.

Targets include UK local government authorities and National Health Service institutions, the "largest" German telecommunications provider and its managed IT service provider subsidiaries, and an Irish aerospace leasing company, North American healthcare companies, and a US transport infrastructure entity that manages airport systems in Houston, we understand.

The suspected spies also went after a multi-national bank operating in South Korea, and a Japanese automotive parts supplier known for advanced electronics and powertrain systems, we're told.

Ivanti did not immediately respond to The Register's request for comment.

Fourth time in three years

"Based on the tactics, techniques, and procedures (TTPs) observed, EclecticIQ attributes this activity with high confidence to UNC5221, a China-nexus espionage group previously linked to zero-day exploitation of edge network appliances since at least 2023," wrote Arda Büyükkaya, a security researcher at EclecticIQ.

EclecticIQ attributes this activity with high confidence to UNC5221, a China-nexus espionage group previously linked to zero-day exploitation of edge network appliances since at least 2023.

This marks the fourth time in three years that this same group has pwned buggy Ivanti products, which is not a good look given Ivanti sells infosec products.

The newest Ivanti security flaws under exploit are CVE-2025-4427, an authenticated bypass vulnerability, and CVE-2025-4428, a post-authentication remote-code execution (RCE) flaw. Together they allow a miscreant to run malware on a vulnerable deployment and hijack it.

Both holes affect Ivanti Endpoint Manager Mobile (EPMM), software used to manage and secure company-issued devices and applications. The software can be run on-premises and also be deployed in the cloud using customer-managed resources.

Ivanti disclosed and patched the bugs last week, warning in a security alert it was "aware of a very limited number of customers" whose products had been exploited.

Earlier this week, soon-to-be-Google-owned security firm Wiz warned exploitation now extends into Ivanti customers' self-managed cloud environments. "We can confirm that the incident we found was on cloud hosted virtual appliances and not an on-prem device," Gili Tikochinski, malware researcher at Wiz, told The Register on Wednesday.

That assessment echoes EclecticIQ's analysis. The Dutch threat intel firm told us it saw UNC5221 deploy the KrustyLoader backdoor on compromised Ivanti EPMM systems from a compromised AWS S3 bucket and then used the malware to deliver additional payloads including the Sliver remote-control suite.

The snoops also specifically targeted the so-called mifs database present in some Ivanti devices, which Büyükkaya said is a "primary target for espionage and data exfiltration operations by China-nexus actors," because it “gives threat actors visibility into managed mobile devices (including IMEI, phone numbers, location, SIM details etc.), LDAP users, and Office 365 refresh and access tokens.”

Anther piece of evidence tying this attack to China is the alleged attackers’ use of the IP address 27.25.148[.]183, which is hosted in China, and was previously used in the SAP NetWeaver attacks that the security shop attributed to UNC5221 in early May.

Probe pop preceded pwnage?

These new compromises follow an April warning from threat intelligence firm GreyNoise, which sounded the alarm on a surge of Ivanti endpoint scans. The number of IP addresses scanning for the vendor's Connect Secure and Pulse Secure systems jumped 800 percent in mid-April, according to GreyNoise analysts, who noted that this steep uptick in scans usually precedes exploitation and public disclosure of new vulnerabilities.

While these most recent attacks aren't due to flaws in Connect Secure and Pulse Secure like the previous three, near-constant probing of Ivanti products by the same Chinese crew since 2023 suggests quality control is an issue for the vendor.

Ivanti CEO Jeff Abbott called a 2024 Connect Secure security SNAFU "humbling," and committed to overhauling his company's security practices. ®