Team Cymru Research[verified]@teamcymru_S2Active Exploitation
Team Cymru reports that the top 25 listed CVEs have been observed with exploitation attempts across multiple unique source IPs in a 14‑day period.
GreyNoise[verified]@GreyNoiseIOGeneral
The post reports increased reconnaissance on CVE‑2025‑0282 but offers no technical details, exploit code, patch information, or evidence of active exploitation.
Audrey Renée Bentley[verified]@BentleyAudreyActive Exploitation
The article indicates that Resurge malware is actively exploiting CVE‑2025‑0282 in Ivanti Connect Secure, suggesting real‑world attacks are underway.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The post reports an active exploitation campaign (Operation Escaneo) that leveraged multiple Fortinet and Ivanti CVEs, employed PoC code and known exploits, and resulted in massive data exfiltration, recommending urgent patching of the affected CVEs.
Machina Record[verified]@MachinaRecordActive Exploitation
The text lists several CVE disclosures, with evidence of active exploitation for at least two of them, but no PoC, exploit code, or patch information is provided.
Abhimanyu Gupta (Reverse engineering life)[verified]@hackerjedi666Active Exploitation
The message details PoC scripts for CVE-2025-0282/0283 and a TLS-based port‑knocking technique that are being shared and actively used by multiple APT actors.
ZeroDayDev[verified]@ZeroDayDevAppActive Exploitation
The post announces Qilin ransomware is taking advantage of CVE‑2025‑0282 to bypass GlobalProtect authentication, with Arctic Wolf reporting active exploitation, while noting that a patch has already been released.
TermsofSurrender 🇨🇿 🇮🇱[verified]@AftershockindexDisclosure
The post announces two zero‑day RCE vulnerabilities in Ivanti products, notes that no patch is available, and warns of potential full system compromise, but does not confirm active exploitation or provide exploit code.