Hackers Exploiting Ivanti EPMM Devices to Deploy Dormant Backdoors
ID: 4bd62323-ab8c-5f9e-8b0f-f2a8d9e0a3c9
STIX ID: report--4bd62323-ab8c-5f9e-8b0f-f2a8d9e0a3c9
Feed Name: cybersecurityNews.com
Ivanti EPMM appliances are being actively exploited in the wild to install a dormant, in-memory Java class loader at /mifs/403.jsp (class base.Info) via unauthenticated flaws (CVE-2026-1281 and CVE-2026-1340); the loader awaits a second-stage Base64-encoded class delivered via the HTTP parameter k0f53cf964d387, avoids disk writes, and returns responses wrapped in delimiters (3cd3d / e60537). The report includes detection and mitigation guidance (patch and restart application servers), a SHA-256 for the implant, request/response patterns to hunt for, and a list of observed source IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
