Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere

GreyNoise Version 1 original current

Imported from official source

The GreyNoise Global Observation Grid observed active exploitation of two critical Ivanti Endpoint Manager Mobile vulnerabilities, and 83% of that exploitation traces to a single IP address on bulletproof hosting infrastructure that does not appear on widely circulated IOC lists.

This version

Version
1 of 1
Recorded
September 20, 2026 19:52
Change
Initial
Content hash
38263e8d29d099cdf9618b832ccedd84
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.