Sunken Ships: Will Orgs Learn From Ivanti EPMM Attacks?
ID: 7535a1f4-5562-5b13-8aaf-cffa30ebb918
STIX ID: report--7535a1f4-5562-5b13-8aaf-cffa30ebb918
Feed Name: Dark Reading
In 2025 attackers exploited two chained zero‑day vulnerabilities in Ivanti Endpoint Manager Mobile (CVE‑2025‑4427 and CVE‑2025‑4428) to achieve remote code execution on Internet‑facing servers, deploy reverse shells, steal plaintext MySQL credentials and encryption keys, install malicious root certificates on enrolled phones, and exfiltrate device metadata and cloud access tokens; the campaign affected thousands of organizations, was linked to a China‑nexus APT, and demonstrates how privileged endpoint management platforms can enable enterprise‑wide compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
