Ivanti Connect Secure hacked using zero-day exploit: what you need to know

Ivanti has published a security bulletin confirming that “a limited number of customers’ Ivanti Connect Secure appliances” have been exploited by hackers using a zero-day exploit.

So critical is the issue that the Cybersecurity Infrastructure and Security Agency (CISA) has added CVE-2025-0282 to its Known Exploited Vulnerabilities catalogue and issued a legally binding and time-limited requirement for US federal agencies to apply the patch.

Ivanti Connect Secure hack: key details

The January 8th security bulletin addresses two vulnerabilities impacting Ivanti Connect Secure: Policy Secure and Neurons for ZTA gateways.

It’s CVE-2025-0282, a stack-based buffer overflow issue, rated as critical with a 9/10 Common Vulnerabilities and Exposure (CVE) severity grade. We know that it has already been exploited by attackers.

“Threat actor activity was identified by the Integrity Checker Tool (ICT) on the same day it occurred,” stated the Ivanti security advisory, “enabling Ivanti to respond promptly and rapidly develop a fix.”

While Ivanti said it is working closely with affected customers, external security partners and law enforcement agencies in response to the issue, it strongly advised “all customers to closely monitor their internal and external ICT as a part of a robust and layered approach to cybersecurity to ensure the integrity and security of the entire network infrastructure”.

What experts say

“The watchTowr Labs team is rapidly analysing CVE-2025-0282, the currently in-the-wild exploited Ivanti Connect Secure zero-day, and we will share those findings shortly,” Benjamin Harris, CEO at the attack surface management provider, told us.

Adding that there is significant concern as the attack has “all the hallmarks of Advanced Persistent Threat (APT) usage of a zero-day against a mission-critical appliance,” Harris warned “everyone to please take this seriously”.

Indeed, Harris pointed out that while there is a patch for Ivanti Connect Secure, patches for the other affected appliances are being left waiting.

“Users of these products should not hesitate,” Harris concluded, “these appliances should be pulled offline until patches are available.”

Mandiant has just published a new analysis of CVE-2025-0282 and said “it is possible that multiple actors are responsible for the creation and deployment” of the various malware families they’ve seen in their on-going investigations (including SPAWN, DRYHOOK and PHASEJAM).

But it also notes that “as of publishing this report, we don’t have enough data to accurately assess the number of threat actors targeting CVE-2025-0282”.

CISA instructions to tackle Ivanti Connect Secure hack

CISA, meanwhile, warned that a cyber threat actor could exploit CVE-2025-0282 to take control of an affected system and users should take the following actions:

  • Run the In-Build Integrity Checker Tool (ICT).
  • Conduct threat hunt actions on any systems connected to—or recently connected to—the affected Ivanti device.
  • If threat hunting actions determine no compromise then factory reset the device and apply the patch described in the Ivanti security advisory.
  • Monitor the authentication or identity management services that could be exposed.
  • Continue to audit privilege level access accounts.

About The Author

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.