Jon Greig · @jgreig
106 followers · 553 posts · Server ioc.exchange

Ivanti updated its advisory on CVE-2023-35082 to say all versions of Ivanti Endpoint Manager Mobile 11.10, 11.9 and 11.8 and MobileIron Core 11.7 are affected

therecord.media/all-ivanti-ver

#Ivanti #MobileIron #epmm

Last updated 1 year ago

adlerweb // BitBastelei · @adlerweb
655 followers · 4911 posts · Server social.adlerweb.info

Sachtma was machen die bei eigentlich beruflich?

"Cybersecurity researchers have discovered a bypass for a recently fixed actively exploited vulnerability in some versions of Ivanti Endpoint Manager Mobile (EPMM)"

thehackernews.com/2023/08/rese

#Ivanti

Last updated 1 year ago

fthy · @fthy
13 followers · 94 posts · Server mastodon.green

bleepingcomputer.com/news/secu

Caitlin Condon: „We would consider this a bypass for the fix for CVE-2023-35078, but notably, it only works on unsupported versions of MobileIron Core (11.2 and below). CVE-2023-35082 could be chained with CVE-2023-35081 to allow an attacker write malicious webshell files to the appliance.“

#infosec #mobileiron #vulnerabiliy #Ivanti

Last updated 1 year ago

fthy · @fthy
13 followers · 93 posts · Server mastodon.green

spiegel.de/netzwelt/netzpoliti German Federal Ministry for Digital and Transport has not patched the critical vulnerability for almost a week, even after warning from the Federal Office of Information Security BSI

#infosec #Ivanti #mobileiron

Last updated 1 year ago

Philipp · @derfopps
108 followers · 1061 posts · Server digitalcourage.social

gehackt, weil sie ihr nicht aktualisiert haben. Einmal mit Profis …
nl-link.sueddeutsche.de/u/nrd.
Das schönste ist ja, dass wegen des Hackerparagraphen in Kartoffelland nicht möglich ist. Und sich die Hacker_in(en) deswegen an die SZ gewandt hat/haben. Wegen Quellenschutz.^^
wann?

#wissingrucktritt #responsibledisclosure #Ivanti #Digitalministerium

Last updated 1 year ago

Aida Akl · @AAKL
372 followers · 707 posts · Server noc.social

How many other organizations have intruders lurking in their systems for months and they don't even know it? We have a problem with detection (or lack of.)

US, Norway say threat actors have been exploiting zero-day since April techcrunch.com/2023/08/02/ivan @TechCrunch @carlypage

#Ivanti #infosec #cybersecurity

Last updated 1 year ago

Jon Greig · @jgreig
102 followers · 536 posts · Server ioc.exchange

Hackers began exploiting a new vulnerability in Ivanti products used by Norway's government at least as early as April, according to a new joint advisory from CISA and Norway

CVE-2023-35078 and CVE-2023-35081

therecord.media/ivanti-hack-be

#Ivanti #MobileIron

Last updated 1 year ago

Dirk Roebers · @prexclusiv
55 followers · 818 posts · Server nrw.social

: Patch für den - früher MobileIron - Endpoint Manager Mobile (EPMM). 2.600 angreifbare Instanzen, davon 500 in D. Schwachstellen spielten wohlr Rolle bei den Angriffen norwegische Ministerien.

heise.de/news/Jetzt-patchen-Iv

#security #alert #Ivanti #itsicherheit #ITSecurity #cybersecurity

Last updated 1 year ago

Dag · @dagb
141 followers · 1192 posts · Server snabelen.no
fthy · @fthy
11 followers · 88 posts · Server mastodon.green

Now public info from Ivanti: forums.ivanti.com/s/article/CV

Ask Ivanti for the IOC PDF and check your mobileiron logs. If the logs cover only a short period of time, check the logs of the backup of your mobileiron systems.

#infosec #Ivanti #mobileiron #vulnerability

Last updated 1 year ago

fthy · @fthy
9 followers · 85 posts · Server mastodon.green

ivanti.com/blog/epmm-security-
Ivanti Endpoint Manager Mobile (formerly known as MobileIron Core)

CVE-2023-25690 CVSS3.1 Score9.8

Afftected version 11.9.0.1 and below

#infosec #vulnerability #mobileiron #Ivanti

Last updated 1 year ago

· @twitter
1 followers · 54808 posts · Server mstdn.skullb0x.io

Referenced link: 0day.today/exploit/description
Originally posted by 0day Exploit Database 🌴 / @inj3ct0r@twitter.com: twitter.com/inj3ct0r/status/16

Avalanche FileStoreConfig 0day.today/exploit/description

#0day #Ivanti #ShellUpload #exploit

Last updated 1 year ago

dispatch · @dispatch
472 followers · 2723 posts · Server ioc.exchange
dispatch · @dispatch
472 followers · 2723 posts · Server ioc.exchange
dispatch · @dispatch
472 followers · 2723 posts · Server ioc.exchange