As cited
Copy frozen at (site build).
threat intel
Active Ivanti Exploitation Traced to Single Bulletproof IP-Published IOC Lists Point Elsewhere
GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.
Why it matters: Organizations running Ivanti Endpoint Manager Mobile need to monitor for exploitation attempts from this IP and update detection rules, as widely shared IOC lists may miss this primary attack vector.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Active Ivanti Exploitation Traced to Single Bulletproof IP-Published IOC Lists Point Elsewhere
GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.
Why it matters: Organizations running Ivanti Endpoint Manager Mobile need to monitor for exploitation attempts from this IP and update detection rules, as widely shared IOC lists may miss this primary attack vector.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Active Ivanti Exploitation Traced to Single Bulletproof IP-Published IOC Lists Point Elsewhere
GreyNoise detected active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, with 83% of observed attacks originating from a single IP address hosted on bulletproof infrastructure. This IP does not appear on most public indicator of compromise (IOC) lists, suggesting gaps in threat intelligence sharing.
Why it matters: Organizations running Ivanti Endpoint Manager Mobile need to monitor for exploitation attempts from this IP and update detection rules, as widely shared IOC lists may miss this primary attack vector.
- Source published
- First seen by Cybersecurity Tracker