CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Active Ivanti Exploitation Traced to Single Bulletproof IP-Published IOC Lists Point Elsewhere

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1860

As cited

Copy frozen at (site build).

threat intel

Active Ivanti Exploitation Traced to Single Bulletproof IP-Published IOC Lists Point Elsewhere

GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.

Why it matters: Organizations running Ivanti Endpoint Manager Mobile need to monitor for exploitation attempts from this IP and update detection rules, as widely shared IOC lists may miss this primary attack vector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Active Ivanti Exploitation Traced to Single Bulletproof IP-Published IOC Lists Point Elsewhere

GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.

Why it matters: Organizations running Ivanti Endpoint Manager Mobile need to monitor for exploitation attempts from this IP and update detection rules, as widely shared IOC lists may miss this primary attack vector.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Active Ivanti Exploitation Traced to Single Bulletproof IP-Published IOC Lists Point Elsewhere

GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.

Why it matters: Organizations running Ivanti Endpoint Manager Mobile need to monitor for exploitation attempts from this IP and update detection rules, as widely shared IOC lists may miss this primary attack vector.

VendorsIvanti
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary