Ivanti Connect Secure hacked using zero-day exploit: what you need to know

Ivanti has published a security bulletin confirming that โ€œa limited number of customersโ€™ Ivanti Connect Secure appliancesโ€ have been exploited by hackers using a zero-day exploit.

So critical is the issue that the Cybersecurity Infrastructure and Security Agency (CISA) has added CVE-2025-0282 to its Known Exploited Vulnerabilities catalogue and issued a legally binding and time-limited requirement for US federal agencies to apply the patch.

Ivanti Connect Secure hack: key details

The January 8th security bulletin addresses two vulnerabilities impacting Ivanti Connect Secure: Policy Secure and Neurons for ZTA gateways.

Itโ€™s CVE-2025-0282, a stack-based buffer overflow issue, rated as critical with a 9/10 Common Vulnerabilities and Exposure (CVE) severity grade. We know that it has already been exploited by attackers.

โ€œThreat actor activity was identified by the Integrity Checker Tool (ICT) on the same day it occurred,โ€ stated the Ivanti security advisory, โ€œenabling Ivanti to respond promptly and rapidly develop a fix.โ€

While Ivanti said it isย working closely with affected customers, external security partners and law enforcement agencies in response to the issue, it strongly advised โ€œall customers to closely monitor their internal and external ICT as a part of a robust and layered approach to cybersecurity to ensure the integrity and security of the entire network infrastructureโ€.

What experts say

โ€œThe watchTowr Labs team is rapidly analysing CVE-2025-0282, the currently in-the-wild exploited Ivanti Connect Secure zero-day, and we will share those findings shortly,โ€ Benjamin Harris, CEO at the attack surface management provider, told us.

Adding that there is significant concern as the attack has โ€œall the hallmarks of Advanced Persistent Threat (APT) usage of a zero-day against a mission-critical appliance,โ€ Harris warned โ€œeveryone to please take this seriouslyโ€.

Indeed, Harris pointed out that while there is a patch for Ivanti Connect Secure, patches for the other affected appliances are being left waiting.

โ€œUsers of these products should not hesitate,โ€ Harris concluded, โ€œthese appliances should be pulled offline until patches are available.โ€

Mandiant has just published a new analysis of CVE-2025-0282 and said โ€œit is possible that multiple actors are responsible for the creation and deploymentโ€ of the various malware families theyโ€™ve seen in their on-going investigations (including SPAWN, DRYHOOK and PHASEJAM).

But it also notes that โ€œas of publishing this report, we don’t have enough data to accurately assess the number of threat actors targeting CVE-2025-0282โ€.

CISA instructions to tackle Ivanti Connect Secure hack

CISA, meanwhile, warned that a cyber threat actor could exploit CVE-2025-0282 to take control of an affected system and users should take the following actions:

  • Run the In-Build Integrity Checker Tool (ICT).
  • Conduct threat hunt actions on any systems connected toโ€”or recently connected toโ€”the affected Ivanti device.
  • If threat hunting actions determine no compromise then factory reset the device and apply the patch described in the Ivanti security advisory.
  • Monitor the authentication or identity management services that could be exposed.
  • Continue to audit privilege level access accounts.
Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.