Live data from Hacker News

Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

defusedcyber.com

11–20 of 54 posts

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#11
post #7

>We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure. “We are aware” and “very limited” are likely (in our opinion, this is probably not fact, etc, etc) to be doing a significant amount of lifting. For avoidance of doubt, the following versions of Ivanti EPMM are patched: None ---- Ah, this company is a security joke as most software security companies are.

"We are aware" can mean "we are taking this very seriously and have seen very little so far" or it can mean "after covering our eyes and plugging our ears we are seeing and hearing very little of this problem".

If you're aware of the sheer number of exploits that can work around or without authentication against anything Ivanti, it has to be the latter.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#12
post #6

Related: Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) https://labs.watchtowr.com/someone-knows-bash-far-too-well-a...

I think there is an easier substitution attack since there is shell expansion occuring. I will toy with it later today.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#13
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

If crowdstrike is any indicator, expect Ivanti stock to go up now. Seems to be the mo for security companies. Fuck up, get paid.

There is no bad publicity? I take few had heard of them before so this is free marketing putting the name in public. Or then there is some broken LLM based sentiment analysis bot that automatically buy companies in news...

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#14
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

> How they haven't been sued into bankruptcy is something I'll never understand.

Isn't most off-the-shelf software effectively always supplied without any kind of warranty? What grounds would the lawsuit have?

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#15
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

The purpose of cybersecurity products and companies is not to sell security. It's to sell the illusion of security to (often incompetent) execs - which is perfectly fine because the market doesn't actually punish security breaches so an illusion is all that's needed. It is an insanely lucrative industry selling luxury-grade snake oil.

Actual cybersecurity isn't something you can just buy off-the-shelf and requires skill and making every single person in the org to give a shit about it, which is already hard to achieve, and even more so when you've tried for years to pay them as little as you can get away with.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#16
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

The purpose of cybersecurity products and companies is not to sell security . It's to sell the illusion of security to (often incompetent) execs - which is perfectly fine because the market doesn't actually punish security breaches so an illusion is all that's needed. It is an insanely lucrative industry selling luxury-grade snake oil. Actual cybersecurity isn't something you can just buy off-the-shelf and requires s…

It's also selling box checks for various certifications.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#17
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

> How they haven't been sued into bankruptcy is something I'll never understand. Isn't most off-the-shelf software effectively always supplied without any kind of warranty? What grounds would the lawsuit have?

Suing for negligence and friends is how car companies -- when it is found out they've built something highly unsafe/dangerously broken -- happens. I don't see the difference.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#19
post #7

>We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure. “We are aware” and “very limited” are likely (in our opinion, this is probably not fact, etc, etc) to be doing a significant amount of lifting. For avoidance of doubt, the following versions of Ivanti EPMM are patched: None ---- Ah, this company is a security joke as most software security companies are.

"We are aware" can mean "we are taking this very seriously and have seen very little so far" or it can mean "after covering our eyes and plugging our ears we are seeing and hearing very little of this problem".

And "a very limited number" may mean "though we pretend to be a big company, we have a limited number of customers and while they all pay licence fees, most are not actually using the product in production."

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#20
post #7

>We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure. “We are aware” and “very limited” are likely (in our opinion, this is probably not fact, etc, etc) to be doing a significant amount of lifting. For avoidance of doubt, the following versions of Ivanti EPMM are patched: None ---- Ah, this company is a security joke as most software security companies are.

It seems you forgot to note this comment is a quote from [1].

1. https://labs.watchtowr.com/someone-knows-bash-far-too-well-a...

Post reply on HN