{"id":213762,"date":"2026-02-12T02:32:00","date_gmt":"2026-02-12T07:32:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/02\/12\/83-of-ivanti-epmm-exploits-linked-to-single-ip-on-bulletproof-hosting-infrastructure\/"},"modified":"2026-02-15T09:20:11","modified_gmt":"2026-02-15T14:20:11","slug":"83-of-ivanti-epmm-exploits-linked-to-single-ip-on-bulletproof-hosting-infrastructure","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/02\/12\/83-of-ivanti-epmm-exploits-linked-to-single-ip-on-bulletproof-hosting-infrastructure\/","title":{"rendered":"83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/83-of-ivanti-epmm-exploits-linked-to.html\">83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/83-of-ivanti-epmm-exploits-linked-to.html\">https:\/\/thehackernews.com\/2026\/02\/83-of-ivanti-epmm-exploits-linked-to.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-12 02:32:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Feb 12, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Network Security<\/span><\/p>\n<p>A significant chunk of the exploitation attempts targeting a newly disclosed security flaw in Ivanti Endpoint Manager Mobile (EPMM) can be traced back to a single IP address on bulletproof hosting infrastructure offered by PROSPERO.<\/p>\n<p>Threat intelligence firm GreyNoise said it recorded 417 exploitation sessions from 8 unique source IP addresses between February 1 and 9, 2026. An estimated 346 exploitation sessions have originated from 193.24.123[.]42, accounting for 83% of all attempts.<\/p>\n<p>The malicious activity is designed to exploit CVE-2026-1281 (CVSS scores: 9.8), one of the two critical security vulnerabilities in EPMM, along with CVE-2026-1340 that could be exploited by an attacker to achieve unauthenticated remote code execution. Late last month, Ivanti acknowledged it&#8217;s aware of a &#8220;very limited number of customers&#8221; who were impacted following the zero-day exploitation of the issues.<\/p>\n<p>Since then, multiple European agencies, including the Netherlands&#8217; Dutch Data Protection Authority (AP), Council for the Judiciary, the European Commission, and Finland&#8217;s Valtori, have disclosed that they were targeted by unknown threat actors using the vulnerabilities.<\/p>\n<p>Further analysis has revealed that the same host has been simultaneously exploiting three other CVEs across unrelated software &#8211;<\/p>\n<p>&#8220;The IP rotates through 300+ unique user agent strings spanning Chrome, Firefox, Safari, and multiple operating system variants,&#8221; GreyNoise said. &#8220;This fingerprint diversity, combined with concurrent exploitation of four unrelated software products, is consistent with automated tooling.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"970\" data-original-width=\"1999\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjbNFL6k046WD-GJb1KNhEzm9vN3Y5FMEsZnbAJMSDHaBjTAx-7voAeQ4uc6yMJII07XFBGSPGVucTT36mosJ2s8WV-ekay5XJ9JQVo_hxP_ppM2eoR41XK3U8PBdOg2ovg17EQiEsEsOo940jGU5Z66zFZIEyXHb8qFj2JmPABSwXkoYNLBmGtMtSkqQ_E\/s1600\/ioc.png\"\/><\/p>\n<p>It&#8217;s worth noting that PROSPERO is assessed to be linked to another autonomous system called Proton66, which has a history of distributing desktop and Android malware like GootLoader, Matanbuchus, SpyNote, Coper (aka Octo), and SocGholish.<\/p>\n<p>GreyNoise also pointed out that 85% of the exploitation sessions beaconed home via the domain&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/83-of-ivanti-epmm-exploits-linked-to.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure https:\/\/thehackernews.com\/2026\/02\/83-of-ivanti-epmm-exploits-linked-to.html Publish&#8230;<\/p>\n","protected":false},"author":1,"featured_media":213763,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYfLBzwwr9ktW_359N5SPDJT-xhZCrJtOdq8gEomlVklbw7KMji47zmZbTKbToZYTw9PY7xIu3p6K6XFXOgE6UvQ2stu1BK5RrGrypa9YSeN2-XM0hGvp8fr_1CCrJSuWx2azFgjZGxd6kwY6sx2RhYQt2ZOh0ogsKHnL3pI_V6EafPtbS36xciBAUHOJh\/s1600\/Bulletproof-Hosting-Infrastructure.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[31,32,29,27],"class_list":["post-213762","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-exploit","tag-malware","tag-network-security","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213762"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=213762"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213762\/revisions"}],"predecessor-version":[{"id":213764,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/213762\/revisions\/213764"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/213763"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=213762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=213762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=213762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}