83% of observed Ivanti EPMM exploitation (CVE-2026-1281) traces to one bulletproof IP that isn't on any published IOC list.
Uncategorized
2
Posts
2
Posters
0
Views
-
83% of observed Ivanti EPMM exploitation (CVE-2026-1281) traces to one bulletproof IP that isn't on any published IOC list. The IPs that are? VPN exits with zero Ivanti activity. We broke down who's actually doing this
️ https://www.greynoise.io/blog/active-ivanti-exploitation -
83% of observed Ivanti EPMM exploitation (CVE-2026-1281) traces to one bulletproof IP that isn't on any published IOC list. The IPs that are? VPN exits with zero Ivanti activity. We broke down who's actually doing this
️ https://www.greynoise.io/blog/active-ivanti-exploitation@greynoise fwiw, that ASN has been on the @spamhaus ASN drop list for over a year
-
R relay@relay.infosec.exchange shared this topic