logo

Inside the Infrastructure: Who’s Scanning for Ivanti Connect Secure?

ID: fa01008f-3679-5779-bdb2-61a2be1f1316

STIX ID: report--fa01008f-3679-5779-bdb2-61a2be1f1316

Feed Name: GreyNoise Labs

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

Author: Glenn Thorpe & 🔮Orbie✨

...
...

GreyNoise observed a large spike (Jan 21–28) in reconnaissance against Ivanti Connect Secure’s /dana-na/auth/url_default/welcome.cgi (CVE-2025-0282, EPSS 93.05%). Two concurrent campaigns were identified: a high-volume, bursty cluster centered in AS213790 (Romania/Moldova) with ~34,172 sessions, and a distributed approach using ~6,000 unique IPs consistent with botnets, proxies, or multi-cloud instances; defenders are advised to patch immediately, review logs for the target path, and reassess internet exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.