26 July 2023

Ivanti patches EPMM zero-day abused in attacks on Norway


Ivanti patches EPMM zero-day abused in attacks on Norway

US-based software company Ivanti has released security updates to address a zero-day vulnerability used in the recent attacks on the Norwegian government.

The country’s security service (DSS) said on Monday that a threat actor exploited the zero-day flaw to breach 12 ministries. However, the Prime Minister's Office, the Ministry of Defense, the Ministry of Justice, and the Ministry of Foreign Affairs are said to be not impacted by the incident.

The Norwegian authorities revealed that the attackers used the zero-day flaw in the Ivanti Endpoint Manager Mobile (EPMM) software, formerly known as MobileIron Core.

Tracked as CVE-2023-35078, the vulnerability is an improper authentication issue, which could be used by a remote hacker to bypass authentication and gain unauthorized access to the application.

The bug affects all supported versions – Version 11.4 releases 11.10, 11.9 and 11.8. Older versions/releases are also at risk, Ivanti said, noting that they are “only aware of a very limited number of customers that have been impacted.”

System owners are advised to install security updates as soon as possible to ensure they are fully protected.

Back to the list

Latest Posts

Germany proposes new law to protect security researchers and toughen penalties for cybercrime

Germany proposes new law to protect security researchers and toughen penalties for cybercrime

The draft law also imposes harsher penalties for severe cases of spying on or intercepting data.
7 November 2024
North Korean hackers target crypto firms with new macOS malware in Hidden Risk campaign

North Korean hackers target crypto firms with new macOS malware in Hidden Risk campaign

The campaign involves a multi-stage malware that infects Apple macOS devices.
7 November 2024
Threat actors abuse DocuSign’s Envelopes API to mass-distribute fake invoices

Threat actors abuse DocuSign’s Envelopes API to mass-distribute fake invoices

By leveraging a legitimate platform attackers bypass traditional email security defenses.
6 November 2024