One threat actor responsible for 83% of recent Ivanti RCE attacks
ID: 9e72bbd0-8e50-5898-9fbb-95b94e56d2e7
STIX ID: report--9e72bbd0-8e50-5898-9fbb-95b94e56d2e7
Feed Name: Bleeping Computer
Threat Score
Threat intelligence from GreyNoise and vendor reporting shows active, automated exploitation of critical Ivanti EPMM RCE flaws (CVE-2026-21962, CVE-2026-24061) between Feb 1–9, with 417 observed exploitation sessions and a single bulletproof-hosted IP (193.24.123.42) accounting for ~83% of activity; many sessions used OAST DNS callbacks consistent with initial-access brokering. Ivanti released hotfixes and recommended mitigations while planning full patches in EPMM 12.8.0.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
