One threat actor responsible for 83% of recent Ivanti RCE attacks
What happened
This has now been corrected to list the CVEs: CVE-2026-1286 and CVE-2026-1340 Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340. A single IP address hosted on bulletproof infrastructure is responsible for over 83% of exploitation activity related to the two vulnerabilities, says threat-focused internet intelligence company GreyNoise. This matters for IT, Telecom & Cyber because fresh price movement and input-cost detail should reset bid assumptions, breach response slas, and negotiation guardrails with 2026-1286, 2026-1340, 2026-1281 as the clearest commercial anchors; expect renewal uplift asks
Buyer takeaway
For IT, Telecom & Cyber, this is a staffing-shape signal: remote operating models can shift work offsite and change which suppliers, systems, and service levels matter most
Cost / money
The cost angle is directional, not quantified: moving work offsite can cut travel, rotation, and accommodation exposure, but only if the remote setup stays reliable
Supplier / commercial
Expect scope to move toward software support, communications uptime, cyber obligations, and clearer downtime liability instead of only offshore headcount or hardware supply
Safety / operations
Fewer people offshore can reduce exposure and emergency-response load, but the operating model becomes more dependent on connectivity resilience, remote support readiness, and cyber hygiene
What to watch
Watch bandwidth resilience, latency tolerance, cyber obligations, and who carries downtime cost if the remote link drops
Key facts
- This has now been corrected to list the CVEs: CVE-2026-1286 and CVE-2026-1340 Threat intellig
- A single IP address hosted on bulletproof infrastructure is responsible for over 83% of explo
- Between February 1st and 9th, the monitoring platform observed 417 exploitation sessions orig
- ]42, hosted by PROSPERO OOO (AS200593), which Censys analysts marked as a bulletproof autonom
Source excerpts
The security issues have been flagged as actively exploited in zero-day attacks in Ivanti's security advisory, where the company also announced hotfixes
This has now been corrected to list the CVEs: CVE-2026-1286 and CVE-2026-1340 Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340
]0/24) present in GreyNoise telemetry as scanning Oracle WebLogic instances, but no Ivanti exploitation activity
