logo

83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure

ID: ea3303c5-462d-5fee-994b-6667e6989b36

STIX ID: report--ea3303c5-462d-5fee-994b-6667e6989b36

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

GreyNoise and other researchers observed active exploitation of two critical Ivanti EPMM zero-days (notably CVE-2026-1281, CVSS 9.8) with 417 exploitation sessions recorded and a single PROSPERO-hosted IP responsible for ~83% of attempts; activity includes OAST DNS callbacks and a dormant in-memory Java class loader deployed to /mifs/403.jsp, indicating initial access broker tradecraft and the potential for widespread MDM compromise. Organizations are advised to patch, audit internet-facing MDM infrastructure, monitor DNS/OAST callbacks and the specified JSP path, and block the PROSPERO AS at the perimeter.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.