Ongoing attacks on Ivanti VPNs install a ton of sneaky, well-written malware
- Google reported that Chinese hackers are likely behind the Ivanti VPN zero-day attacks involving new malware called 'Dryhook' and 'Phasejam' that are not linked to any known threat group.
- The critical vulnerability, tracked as CVE-2025-0282, affects several Ivanti products and has been exploited since mid-December 2024, according to Mandiant.
- Ivanti confirmed that its Connect Secure appliances were hacked, and a patch is available, but updates for other affected products will not be released until January 21.
- The U.S. Cybersecurity agency CISA added the vulnerability to its catalog, while the U.K.'s National Cyber Security Centre is investigating active exploitation cases.
Insights by Ground AI
Does this summary seem wrong?
Coverage Details
Total News Sources0
Leaning Left0Leaning Right0Center4Last UpdatedBias Distribution100% Center
Bias Distribution
- 100% of the sources are Center
100% Center
C 100%
Factuality
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage