Cyber-Attacks Target Vulnerable Ivanti Products
ID: ba7e8f9b-9f47-5d11-a8a3-686c2d784b26
STIX ID: report--ba7e8f9b-9f47-5d11-a8a3-686c2d784b26
Feed Name: Cyble Blog
Threat Score
Cyble reports active exploitation attempts against Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry exploiting multiple CVEs (including CVE-2023-35078 and CVE-2023-35081). Sensors observed GET/POST requests targeting vulnerable endpoints, use of compromised SOHO routers as proxies, public forum activity offering a zero-day, and notable internet exposure concentrated in the United States and Germany; the report includes IoCs, ATT&CK mappings, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
