I created a blog post on the NVISO blog, to share some observations we made in a recent incident dealing with Ivanti Endpoint Manager (EPMM), CVE-2026-1281, CVE-2026-1340 and not so sleepy 'sleeper shells'. https://blog.nviso.eu/2026/03/13/ivanti-epmm-sleeper-shells-not-so-sleepy/#BlueTeam #IncidentResponse #SharingIsCaring