
Edge Device Exploitation: VPN Zero-Day
Investigate a breach targeting exposed edge security appliances. An attacker exploits Ivanti Connect Secure CVE-2025-22457 to obtain unauthenticated code execution, spawns a shell from the gateway web process, retrieves a Linux payload, and attempts to preserve access using edge-device service abuse patterns similar to FortiGate SSL-VPN post-exploitation tradecraft. Trace the intrusion across SIEM, XDR, and firewall telemetry.


