Ivanti mobile-management zero-day fallout reaches nearly 100 victims

THE BRIEF
CyberScoop reports that fallout from two Ivanti Endpoint Manager Mobile (EPMM) zero-day vulnerabilities has spread to nearly 100 victims. Ivanti disclosed the defects in late January, after attacks had already been observed in the wild, and researchers and threat hunters reported consistent waves linked to them. The Netherlands’ Dutch Data Protection Authority and Council for the Judiciary confirmed that both agencies were impacted by related attacks in a notice sent to parliament. Separately, the European Commission said it found evidence of a cyberattack on its “central infrastructure managing mobile devices,” but did not identify Ivanti or another vendor. The report says Ivanti customers, including major government agencies, face growing pressure as attackers expand the scope of targets. These disclosures describe an active and developing incident picture; they do not establish that every reported victim experienced the same effects or that all cases involved the same organization.
WHY IT MATTERS
This matters because EPMM manages mobile devices centrally, making weaknesses in the platform relevant to organizations that administer phones and other mobile endpoints. The reported involvement of public-sector bodies, together with attacks observed before disclosure, compresses the time available for investigation and response. The European Commission’s statement also shows that public reporting may identify affected infrastructure without naming the technology involved. Organizations should therefore treat this as a live vulnerability-management and incident-review issue, while avoiding assumptions about scope until facts are confirmed.
WHO SHOULD CARE
Security and infrastructure teams running Ivanti EPMM, government agencies managing mobile devices, incident responders, and leaders responsible for vulnerability management should review their exposure and monitor confirmed updates.
WHAT TO DO NOW
- Inventory Ivanti EPMM deployments, connected systems, and externally reachable management interfaces.
- Review Ivanti’s security guidance and confirm that applicable mitigations or updates have been evaluated and applied.
- Search EPMM and related network logs for activity consistent with the reported attack period, and preserve relevant evidence.
- Coordinate with legal, privacy, and incident-response teams before concluding whether an environment or agency was affected.