
APT-C-16 exploited Ivanti Connect Secure zero-day since mid-February
A China-linked group, UNC5221, exploited a zero-day vulnerability in Ivanti Connect Secure since mid-March. The vulnerability, discovered in April, allows attackers to gain remote access to affected systems. Ivanti released a patch in May, but the group is believed to have exploited the flaw before the fix was available.