A significant spike was observed, with over 230 unique IP addresses probing ICS/IPS endpoints in a single day — a ninefold increase compared to the usual daily average of fewer than 30 unique IPs.
Scanning Activity and Infrastructure
GreyNoise’s monitoring systems detected this anomaly using their dedicated ICS scanner tag, which identifies IP addresses attempting to discover internet-accessible ICS/IPS systems.
Over the past 90 days, a total of 1,004 unique IPs have been recorded conducting similar scans, categorized as follows:
- 634 Suspicious
- 244 Malicious
- 126 Benign

Importantly, none of the observed IPs were spoofed, indicating that attackers are relying on real, traceable infrastructure.
The top three source countries for scanning activity are the United States, Germany, and the Netherlands — which also happen to be the primary targets.
Malicious IPs identified in prior incidents largely originate from Tor exit nodes and well-known cloud or VPS providers. In contrast, suspicious IPs are often linked to lesser-known hosting services and niche cloud infrastructure, suggesting involvement from a mix of sophisticated and opportunistic actors.
Vulnerability Landscape: CVE-2025-22457
The surge in scanning activity aligns with heightened attention to CVE-2025-22457, a critical stack-based buffer overflow vulnerability affecting:
- Ivanti Connect Secure (versions 22.7R2.5 and earlier),
- Pulse Connect Secure 9.x (now end-of-support),
- Ivanti Policy Secure,
- and Neurons for ZTA gateways.
Initially underestimated, this flaw was later found to allow unauthenticated remote code execution (RCE) — enabling attackers to run arbitrary code on vulnerable appliances.
Ivanti released a patch for CVE-2025-22457 on February 11, 2025 (ICS version 22.7R2.6). However, many legacy devices remain unpatched and exposed.
Exploitation in the wild has already been confirmed, with advanced persistent threat (APT) groups like UNC5221 reverse-engineering the patch to develop functional exploits.
Given the widespread deployment of Ivanti Connect Secure VPNs for enterprise remote access, these systems are high-value targets for both cybercriminals and nation-state actors.
Historically, spikes in scanning activity often precede the public disclosure or mass exploitation of new vulnerabilities.
The current reconnaissance wave suggests attackers are mapping vulnerable systems in preparation for large-scale attacks, ransomware operations, or data breaches.
Defensive Recommendations
To mitigate the risk, organizations should:
- Immediately patch all ICS/IPS systems to the latest version (ICS 22.7R2.6 or later).
- Review logs for suspicious probing or login attempts from unfamiliar IPs.
- Block known malicious and suspicious IPs flagged by GreyNoise and other threat intelligence providers.
- Monitor for unusual authentication activity, especially involving Tor or cloud-hosted IPs.
- Utilize Ivanti’s Integrity Checker Tool (ICT) to detect potential compromise.
GreyNoise continues to monitor this evolving threat landscape and urges security teams to stay vigilant.
The spike in scanning activity is a clear warning: attackers are actively seeking to exploit unpatched Ivanti Connect Secure systems. Rapid patching and proactive defense are critical to preventing compromise.




