Desk live·
ForensicPost
Cloud/Exploitation/File 25-0109

Ivanti Connect Secure Flaw CVE-2025-0282 Exploited From January 2025

CVE-2025-0282 in Ivanti Connect Secure was exploited from January 2025, followed by CVE-2025-22457. The first significant campaign of the year targeted the device organisations use to work remotely.

Constructed geometry · not a chart of case data
TargetIvanti Connect Secure estates
ActorMultiple
S. Rosler10 min readConfidence: high2 sources reviewed

CVE-2025-0282, affecting Ivanti Connect Secure, was exploited in the wild from January 2025. A second vulnerability, CVE-2025-22457, followed in the same product line.

A VPN Concentrator Is A Privileged Position

The device exists to authenticate remote users and place them inside the network. Compromising it means occupying the point through which trusted access is granted — able to observe credentials as they arrive and to reach whatever the network permits an authenticated user to reach.

It is the identity-boundary argument this corpus files repeatedly, expressed as hardware rather than as a help desk. At 25-0512 the boundary was a person who could be persuaded; here it is an appliance with a parser.

Two In One Product Line In One Quarter

Consecutive exploited vulnerabilities in the same product within months is the pattern also recorded at 25-0624. It suggests a codebase receiving concentrated research attention — which happens precisely because the first finding demonstrated the category was productive.

For a defender that has an unwelcome implication: a vendor whose product was exploited recently is more likely, not less, to be exploited again soon. The disclosure that prompts patching also advertises where to look.

And Remediation Does Not End At The Update

As at 25-0723, an appliance compromise leaves questions the patch does not answer: whether credentials passing through were captured, whether persistence was established in the appliance image, whether sessions issued during the exposure window remain valid.

Vendor guidance for these events routinely includes factory reset and credential rotation. How often that is completed is not something this desk can measure, and nobody publishes it.

How we reported this

Compiled from vendor advisories and public research, listed below. Victim counts are not established. Corrections: corrections@forensicpost.com.

Sources
  1. Lessons from 2025: zero-day exploitation shaping 2026Outpost24
  2. Top zero-day vulnerabilities exploited in the wild in 2025Cybersecurity News
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary