CISA Alerts on Malware Exploiting Ivanti EPMM Vulnerabilities and Supply Chain Risks

1 min read
Source: BleepingComputer
CISA Alerts on Malware Exploiting Ivanti EPMM Vulnerabilities and Supply Chain Risks
Photo: BleepingComputer
TL;DR Summary

CISA has revealed that threat actors exploited two vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) to deploy malware, with evidence suggesting a China-linked espionage group was involved. The malware was delivered via segmented HTTP requests, allowing attackers to execute remote commands, exfiltrate data, and establish persistence. Ivanti addressed the vulnerabilities in May, but attacks had already occurred, prompting recommendations for immediate patching and heightened security measures.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

87%

49066 words

Want the full story? Read the original article

Read on BleepingComputer