Nightfighter 🛡️ · @Optimus
49 followers · 1557 posts · Server social.tchncs.de

Die meisten schaffen es scheinbar nicht die aktuellen kritischen Lücken in Lösungen wie Mobile Iron durch das Installieren von vorhandenen Sicherheitsupdates abzusichern.
Es gibt immer noch ne Menge angreifbarer Ivanti (ehemals Mobile Iron) Sentry’s da draußen 🤷‍♂️🤦‍♂️. Schlafen die Admins?

#vulnerability #ivanti #sentry #sicherheit #it #mobileiron #patches #updates

Last updated 2 years ago

Nightfighter 🛡️ · @Optimus
48 followers · 1553 posts · Server social.tchncs.de

Wer eine Sentry von Ivanti (ehemals Mobile Iron) im Einsatz hat, sollte dringend die letzten Patches einspielen! Angreifer können aus der Ferne Befehle ausführen.

#mobileiron #ivanti #vulnerability #patch #hacker #exploit #security

Last updated 2 years ago

Marcel SIneM(S)US · @simsus
214 followers · 5249 posts · Server social.tchncs.de
Mosfet Corley · @corley
1 followers · 81 posts · Server social.tchncs.de

Länger nichts von gehört? 🙈

„[…] critical ( -2023-38035 )enables unauthenticated attackers to gain access to sensitive admin portal configuration APIs exposed over port 8443, used by Configuration Service (MICS).“

bleepingcomputer.com/news/secu

#ivanti #vulnerability #cve #mobileiron

Last updated 2 years ago

fthy · @fthy
13 followers · 94 posts · Server mastodon.green

bleepingcomputer.com/news/secu

Caitlin Condon: „We would consider this a bypass for the fix for CVE-2023-35078, but notably, it only works on unsupported versions of MobileIron Core (11.2 and below). CVE-2023-35082 could be chained with CVE-2023-35081 to allow an attacker write malicious webshell files to the appliance.“

#infosec #mobileiron #vulnerabiliy #Ivanti

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
30942 followers · 1143 posts · Server cyberplace.social

CISA advisory says the zero day exploitation of was happening from "at least" April 2023 (which backs up from I wrote in my blog - i.e. I can see exploitation in logs going back to early this year).

Threat actors were uploading webshells and such.

cisa.gov/news-events/cybersecu

#mobileiron #threatintel #mobileirony

Last updated 2 years ago

fthy · @fthy
13 followers · 93 posts · Server mastodon.green

spiegel.de/netzwelt/netzpoliti German Federal Ministry for Digital and Transport has not patched the critical vulnerability for almost a week, even after warning from the Federal Office of Information Security BSI

#infosec #Ivanti #mobileiron

Last updated 2 years ago

RootWyrm 🇺🇦🏳️‍🌈 · @rootwyrm
61 followers · 429 posts · Server weird.autos

Watching the Ivanti shitshow, "unsurprised" doesn't even begin to describe it. The only surprise is in how long it took to find.
Leadership not only minimizing it, but being outright dishonest with the public and with customers?
Yeah.
Not surprised.

#mobileiron

Last updated 2 years ago

Marcel SIneM(S)US · @simsus
206 followers · 4754 posts · Server social.tchncs.de
fthy · @fthy
11 followers · 88 posts · Server mastodon.green

Now public info from Ivanti: forums.ivanti.com/s/article/CV

Ask Ivanti for the IOC PDF and check your mobileiron logs. If the logs cover only a short period of time, check the logs of the backup of your mobileiron systems.

#infosec #Ivanti #mobileiron #vulnerability

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
30608 followers · 1103 posts · Server cyberplace.social

The zero day saga continues.

The vendor note to customers says the flaw allows the attacker to "make limited changes to the server".

CISA have released a statement saying "An attacker can also make other configuration changes, including creating an EPMM administrative account that can make further changes to a vulnerable system"

cisa.gov/news-events/alerts/20

#mobileiron #threatintel

Last updated 2 years ago

fthy · @fthy
11 followers · 87 posts · Server mastodon.green

heise.de/news/Ivanti-schliesst

heise.de writes about Ivanti mobileiron core unauthenticated api access CVE-2023-35078 —> patch now

#infosec #mobileiron #vulnerability

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
30522 followers · 1093 posts · Server cyberplace.social

⚠️ Regarding the vulnerability ⚠️

Patches are out for 11.8.1.1, 11.9.1.1 and 11.10.0.2. It also applied to unsupported and EOL versions.

It's a serious zero day vulnerability which is very easy to exploit, where Ivanti are trying to hide it for some reason - this will get mass internet swept. I'd strongly recommend upgrading, and if you can get off EOL, switch off the appliance.

#mobileiron

Last updated 2 years ago

Kevin Beaumont · @GossiTheDog
30519 followers · 1093 posts · Server cyberplace.social

We have a winner already - CVE-2023-35078, zero day in aka Ivanti Endpoint Manager Mobile

Exploitation in the wild.
forums.ivanti.com/s/article/KB

#mobileiron #threatintel

Last updated 2 years ago

fthy · @fthy
9 followers · 85 posts · Server mastodon.green

ivanti.com/blog/epmm-security-
Ivanti Endpoint Manager Mobile (formerly known as MobileIron Core)

CVE-2023-25690 CVSS3.1 Score9.8

Afftected version 11.9.0.1 and below

#infosec #vulnerability #mobileiron #Ivanti

Last updated 2 years ago

Derek · @Darus
4 followers · 55 posts · Server techhub.social

Any users here?

#mobileiron #mdm

Last updated 2 years ago

Benjamin · @blindcoder
165 followers · 1299 posts · Server toot.berlin

: Neither nor support on mobile devices, with US issuing only IPv6 addresses to mobile devices.

#til #mobileiron #okta #ipv6 #tmobile

Last updated 2 years ago

Patchday Robot · @patchday
2 followers · 83 posts · Server social.adlerweb.info

New Version: Ivanti Sentry 9.17.0 (Stable;x86_64) bit.ly/3HIM3Tz

#mobileiron

Last updated 3 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online
ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online