Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Ivanti EPMM exploitation: Researchers warn of “sleeper” webshells
    Cybersecurity

    Ivanti EPMM exploitation: Researchers warn of “sleeper” webshells

    adminBy adminFebruary 11, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Ivanti EPMM exploitation: Researchers warn of "sleeper" webshells
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned.

    Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation by other threat actors.

    “On February 9, Defused Cyber reported a campaign deploying dormant in-memory Java class loaders to compromised EPMM instances at the path /mifs/403.jsp. The implants require a specific trigger parameter to activate, and no follow-on exploitation was observed at the time of their report,” Greynoise noted.

    From their own vantage point – Greynoise sensors placed in data center networks and public IP space that passively observe unsolicited internet traffic around the world – the company spotted exploitation sessons that involved payloads that “phone home via DNS to confirm “this target is exploitable.”

    “They do not deploy malware. They do not exfiltrate data. They verify access,” Greynoise researchers noted. “This is consistent with initial access operations that verify exploitability first and deploy follow-on tooling later.”

    CVE-2026-1281 exploitation picks up steam

    Ivanti disclosed CVE-2026-1281 and CVE-2026-1340, two code injection vulnerabilities in its Endpoint Manager Mobile solution, on January 29, 2026, and said that they were aware of in-the-wild exploitation. CISA added CVE-2026-1281 to its Known Exploited Vulnerabilities catalog on the same day.

    The company provided a temporary fix for the flaws (and fixed them with a patch and security updates on February 4), but on January 30, watchTowr researchers released their analysis of one of the patches.

    It was revealed last week that the Dutch Data Protection Authority (AP) and the Council for the Judiciary (Rvdr) have had their EPMM instances breached on or before January 29, likely via CVE-2026-1281, and that the European Commission’s mobile device management platform was hacked (though the solution remains unnamed).

    Another confirmed victim is Valtori, Finland’s central government ICT service center.

    Ivanti, with the help of the Dutch National Cyber Security Center (NCSC-NL) has released a detection script to help customers find evidence of exploitation in their Ivanti EPMM environment. NCSC-NL warned that all organizations using Ivanti EPMM should assume they’ve been compromised and mount a forensic investigation to check.

    Defused Cyber has shared log indicators and indicators of compromise and has advised organizations to patch their Ivanti EPMM instance, restart application servers to flush in-memory implants, and review access logs with the provided indicators.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    EPMM exploitation Ivanti researchers sleeper warn webshells
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleChatGPT Has 12% of Google’s Search Volume but Google Sends 190x More Traffic to Websites
    Next Article Why your ‘2TB’ drive only shows 1.8TB
    admin
    • Website

    Related Posts

    Fideo Intelligence enhances dark web monitoring capabilities to reduce payment fraud

    March 5, 2026

    Microsoft, Europol disrupt global phishing platform Tycoon 2FA

    March 5, 2026

    FBI arrests suspect linked to $46M crypto theft from US Marshals

    March 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Yep, Amazon Is Down | Lifehacker

    March 5, 2026

    Fideo Intelligence enhances dark web monitoring capabilities to reduce payment fraud

    March 5, 2026

    AI Max increases revenue 13% but drives higher CPA: Study

    March 5, 2026

    Why everyone should use VS Code (even if they aren’t programmers)

    March 5, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (620)
    • Privacy & Online Earning (92)
    • SEO & Digital Marketing (394)
    • Tech Tools & Mobile / Apps (758)
    • WiFi / Internet & Networking (111)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Yep, Amazon Is Down | Lifehacker

    March 5, 2026

    Fideo Intelligence enhances dark web monitoring capabilities to reduce payment fraud

    March 5, 2026

    AI Max increases revenue 13% but drives higher CPA: Study

    March 5, 2026
    Most Popular
    • Yep, Amazon Is Down | Lifehacker
    • Fideo Intelligence enhances dark web monitoring capabilities to reduce payment fraud
    • AI Max increases revenue 13% but drives higher CPA: Study
    • Why everyone should use VS Code (even if they aren’t programmers)
    • Microsoft, Europol disrupt global phishing platform Tycoon 2FA
    • Linux Mint finally fixed its Wayland problem and it’s a game changer
    • Cisco issues emergency patches for critical firewall vulnerabilities
    • FBI arrests suspect linked to $46M crypto theft from US Marshals
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.