European Governments Breached in Zero-Day Attacks Targeting Ivanti
ID: a3848625-7dbe-5935-87bf-10a12f7b0a5b
STIX ID: report--a3848625-7dbe-5935-87bf-10a12f7b0a5b
Feed Name: Infosecurity Magazine (News)
Several European government organisations (European Commission, Finnish government/Valtori, and multiple Dutch agencies) were targeted via exploitation of two critical Ivanti Endpoint Manager Mobile (EPMM) zero-day vulnerabilities (CVSS 9.8: CVE-2026-1281 and CVE-2026-1340). Attackers accessed the MDM control plane, exposing staff names, work emails, phone numbers and device metadata (Valtori estimates up to ~50,000 accounts affected); vendors released patches on 29 January and incidents were contained after detection, but risks remain for credential compromise and spearphishing follow-on attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
