Single IP Dominates Exploitation Campaign Attacking Ivanti EPMM with RCE Vulnerability
ID: 863483dd-14d0-557c-8b3d-f884efdb9e37
STIX ID: report--863483dd-14d0-557c-8b3d-f884efdb9e37
Feed Name: cybersecurityNews.com
**Executive Summary:** A critical remote code execution (RCE) flaw in Ivanti Endpoint Manager Mobile (CVE-2026-1281, and a related CVE-2026-1340) is being actively exploited at scale; GreyNoise data shows 83% of observed exploitation traffic originating from a single IP (193.24.123.42) tied to bulletproof hosting, while observed exploitation sessions and confirmed breaches at Dutch authorities indicate real-world compromise. Attackers use automated mass-scanning with rotating user-agents, DNS callbacks to verify execution, and sleeper webshells that may persist post-patch; defenders should note IOC gaps in early feeds where the principal infrastructure was missing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
