Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Single IP Dominates Exploitation Campaign Attacking Ivanti EPMM with RCE Vulnerability

A critical remote code execution (RCE) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 , is currently undergoing significant exploitation. Data from GreyNoise indicate that 83% of observed attacks originate from a…

A critical remote code execution (RCE) vulnerability in Ivanti Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 , is currently undergoing significant exploitation. Data from GreyNoise indicate that 83% of observed attacks originate from a single IP address: 193[.]24[.]123[.]42.

This IP address is registered to PROSPERO OOO (AS200593) and classified as "bulletproof" hosting. Notably, this IP was absent in many early indicators of compromise shared with security defenders.

Two Critical Vulnerabilities Under Active Attack

The vulnerability CVE-2026-1281 (CVSS 9.8) permits unauthenticated attackers to execute system commands via Bash arithmetic expansion within backend file-delivery scripts.

Another vulnerability, CVE-2026-1340, also with a CVSS score of 9.8, allows similar code execution in a different EPMM component.

Ivanti released an advisory on January 29. Following this, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog.

Data from GreyNoise indicate that 83% of observed attacks originate from a single IP address: 193[.]24[.]123[.]42.
Aiden Sinclair · Thehackingpost

Dutch authorities confirmed breaches at the Dutch Data Protection Authority (AP) and the Council for the Judiciary (RVDR), indicating pre-existing attacks before organizations applied patches.

Between February 1 and 9, GreyNoise recorded 417 exploitation sessions from eight different IPs. On February 8 alone, there were 269 sessions, approximately 13 times the previous daily average.

The primary IP, 193[.]24[.]123[.]42, is associated with attacks on Oracle WebLogic Server, GNU Inetutils telnetd , and GLPI. The use of numerous user-agent strings suggests automated mass exploitation.

Some commonly shared indicators of compromise did not align with Ivanti exploitation data. For instance, Windscribe VPN exit nodes on M247 infrastructure generated significant traffic, but none targeted Ivanti EPMM.

Advertisement

Another indicator pointed to a residential router involved in limited activity. Organizations blocking only these VPN or residential IPs, without restricting AS200593, may have overlooked the primary threat.

Approximately 85% of the payloads utilized DNS callbacks to verify code execution, rather than immediately deploying malware. This behavior aligns with initial access broker tactics .

Reports also mention "sleeper" webshells located at /mifs/403.jsp, which remain inactive until triggered. Consequently, even patched systems might remain compromised if attackers accessed them before the vulnerabilities were addressed.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories