
- CISA warns attackers chained CVE-2025-4427 and CVE-2025-4428 to breach Ivanti EPMM systems
- Malware was delivered via EL injection and reconstructed from Base64-encoded payloads
- CISA did not confirm attribution; reports suggest possible Chinese targeting of Australian entity
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations about two patched Ivanti flaws being chained together in real-life attacks.