logo

One threat actor responsible for 83% of recent Ivanti RCE attacks

ID: 9e72bbd0-8e50-5898-9fbb-95b94e56d2e7

STIX ID: report--9e72bbd0-8e50-5898-9fbb-95b94e56d2e7

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-02-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat intelligence from GreyNoise and vendor reporting shows active, automated exploitation of critical Ivanti EPMM RCE flaws (CVE-2026-21962, CVE-2026-24061) between Feb 1–9, with 417 observed exploitation sessions and a single bulletproof-hosted IP (193.24.123.42) accounting for ~83% of activity; many sessions used OAST DNS callbacks consistent with initial-access brokering. Ivanti released hotfixes and recommended mitigations while planning full patches in EPMM 12.8.0.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.