Get access to our best features
Get access to our best features
Published

Ongoing attacks on Ivanti VPNs install a ton of sneaky, well-written malware

  • Google reported that Chinese hackers are likely behind the Ivanti VPN zero-day attacks involving new malware called 'Dryhook' and 'Phasejam' that are not linked to any known threat group.
  • The critical vulnerability, tracked as CVE-2025-0282, affects several Ivanti products and has been exploited since mid-December 2024, according to Mandiant.
  • Ivanti confirmed that its Connect Secure appliances were hacked, and a patch is available, but updates for other affected products will not be released until January 21.
  • The U.S. Cybersecurity agency CISA added the vulnerability to its catalog, while the U.K.'s National Cyber Security Centre is investigating active exploitation cases.
Insights by Ground AI
Does this summary seem wrong?
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

Sources are mostly out of (0)

Similar News Topics