Live data from Hacker News

Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

defusedcyber.com

31–40 of 54 posts

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#31

Earlier quoted context omitted.

Actually there is a significant push to more effective products coming from the reinsurance companies that underwrite cyber risks. Most of them come with a checklist of things you need to have before they sign you at any reasonable price. The more we get government regulation for fines in cases of breaches etc. the more this trend will accelerate.

The thing is that real security isn't something that a checklist can guarantee. You have to build it into the product architecture and mindset of every engineer that works on the project. At every single stage, you have to be thinking "How do I minimize this attack surface? What inputs might come in that I don't expect? What are the ways that this code might be exploited that I haven't thought about? What privileges…

You are asserting that security has to be hand-crafted. That is a very strong claim, if you think about it.

Is it not possible to have secure software components that only work when assembled in secure ways? Why not?

Conversely, what security claims about a component can one rely upon, without verifying it oneself?

How would a non-professional verify claims of security professionals, who have a strong interest in people depending upon their work and not challenging its utility?

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#32

Earlier quoted context omitted.

Actually there is a significant push to more effective products coming from the reinsurance companies that underwrite cyber risks. Most of them come with a checklist of things you need to have before they sign you at any reasonable price. The more we get government regulation for fines in cases of breaches etc. the more this trend will accelerate.

The thing is that real security isn't something that a checklist can guarantee. You have to build it into the product architecture and mindset of every engineer that works on the project. At every single stage, you have to be thinking "How do I minimize this attack surface? What inputs might come in that I don't expect? What are the ways that this code might be exploited that I haven't thought about? What privileges…

> but now there's a very strong incentive to not report data breaches and have your insurance premiums go up or government regulation come down

I would argue the opposite is true. Insurance doesn’t pay out if you don’t self-report in time. Big data breaches usually get discovered when the hacker tries to peddle off the data in a darknet marketplace so not reporting is gambling that this won’t happen.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#33
post #6

Related: Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) https://labs.watchtowr.com/someone-knows-bash-far-too-well-a...

I think there is an easier substitution attack since there is shell expansion occuring. I will toy with it later today.

[dead]

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#34
post #28
post #19

Earlier quoted context omitted.

And "a very limited number" may mean "though we pretend to be a big company, we have a limited number of customers and while they all pay licence fees, most are not actually using the product in production."

Ivanti isn't exactly a small company. It's products are used in fair amount of the F100's out there so any risk on their part can have an outsized influence.

That's why you hire a CSO: Chief Scapegoat Officer.

You pay them a million per year, and fire them when a breach happens.

Way cheaper than improving security.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#35

Earlier quoted context omitted.

Actually there is a significant push to more effective products coming from the reinsurance companies that underwrite cyber risks. Most of them come with a checklist of things you need to have before they sign you at any reasonable price. The more we get government regulation for fines in cases of breaches etc. the more this trend will accelerate.

Holy those checklists are the bane of my existence. For example demanding 2FA for email, which is impossible if you self host, unless you force everyone to use RoundCube, but then you have to answer to the CEO why he can’t get email on his iPhone in the mail app. Or just loads of other stuff that really only applies to large Fortune 500 size companies. My small startups certainly don’t have a network engineer on staf…

Why is 2FA impossible if you self host?

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#36
post #31

Earlier quoted context omitted.

The thing is that real security isn't something that a checklist can guarantee. You have to build it into the product architecture and mindset of every engineer that works on the project. At every single stage, you have to be thinking "How do I minimize this attack surface? What inputs might come in that I don't expect? What are the ways that this code might be exploited that I haven't thought about? What privileges…

You are asserting that security has to be hand-crafted. That is a very strong claim, if you think about it. Is it not possible to have secure software components that only work when assembled in secure ways? Why not? Conversely, what security claims about a component can one rely upon, without verifying it oneself? How would a non-professional verify claims of security professionals, who have a strong interest in peo…

Not the person you are responding to, but: I would agree that at the stage of full maturity of cybersecurity tooling and corporate deployment, configuration would be canonical and painless, and robust and independent verification of security would be possible by less-than-expert auditors. At such a stage of maturity, checklist-style approaches make perfect sense.

I do not think we're at that stage of maturity. I think it would be hubris to imitate the practices of that stage of maturity, enshrining those practices in the eyes of insurance underwriters.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#37

Earlier quoted context omitted.

Actually there is a significant push to more effective products coming from the reinsurance companies that underwrite cyber risks. Most of them come with a checklist of things you need to have before they sign you at any reasonable price. The more we get government regulation for fines in cases of breaches etc. the more this trend will accelerate.

The thing is that real security isn't something that a checklist can guarantee. You have to build it into the product architecture and mindset of every engineer that works on the project. At every single stage, you have to be thinking "How do I minimize this attack surface? What inputs might come in that I don't expect? What are the ways that this code might be exploited that I haven't thought about? What privileges…

You’re making many assumptions which fit your worldview.

I can assure you that insurers don’t work like that.

If underwriting was as sloppy as you think it is insurance as a business model wouldn’t work.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#38
post #37

Earlier quoted context omitted.

The thing is that real security isn't something that a checklist can guarantee. You have to build it into the product architecture and mindset of every engineer that works on the project. At every single stage, you have to be thinking "How do I minimize this attack surface? What inputs might come in that I don't expect? What are the ways that this code might be exploited that I haven't thought about? What privileges…

You’re making many assumptions which fit your worldview. I can assure you that insurers don’t work like that. If underwriting was as sloppy as you think it is insurance as a business model wouldn’t work.

Err, cybersecurity insurance as a business model has not worked. I have seen analyst reports showing that there have been multiple large claims that are each individually larger than all premiums ever collected industry wide. Those same reports indicated that all the large cybersecurity insurance vendors were basically no longer issuing policies with significant coverage, capping out at the few million dollar range. Cybersecurity insurance is picking up pennies in front of a steamroller; you wonder why no one else is picking up this free money on the ground until you get crushed.

Note, that is not to say that cybersecurity insurance if fundamentally impossible, just that the current cost structure and risk mitigation structure is untenable and should not be pointed at as evidence of function.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#39

Earlier quoted context omitted.

The purpose of cybersecurity products and companies is not to sell security . It's to sell the illusion of security to (often incompetent) execs - which is perfectly fine because the market doesn't actually punish security breaches so an illusion is all that's needed. It is an insanely lucrative industry selling luxury-grade snake oil. Actual cybersecurity isn't something you can just buy off-the-shelf and requires s…

Actually there is a significant push to more effective products coming from the reinsurance companies that underwrite cyber risks. Most of them come with a checklist of things you need to have before they sign you at any reasonable price. The more we get government regulation for fines in cases of breaches etc. the more this trend will accelerate.

Those checklists are frequently answered like this:

"Hey it says we need to do mobile management and can't just let people manage their own phones. Looks like we'll buy Avanti mobile manager". Same conversation I've seen play out with generally secure routers being replaced with Fortigates that have major vulnerabilities every week because the checklist says you must be doing SSL interception.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#40

Earlier quoted context omitted.

Actually there is a significant push to more effective products coming from the reinsurance companies that underwrite cyber risks. Most of them come with a checklist of things you need to have before they sign you at any reasonable price. The more we get government regulation for fines in cases of breaches etc. the more this trend will accelerate.

Holy those checklists are the bane of my existence. For example demanding 2FA for email, which is impossible if you self host, unless you force everyone to use RoundCube, but then you have to answer to the CEO why he can’t get email on his iPhone in the mail app. Or just loads of other stuff that really only applies to large Fortune 500 size companies. My small startups certainly don’t have a network engineer on staf…

I'm mostly with you (see my other comment) but MFA on email really is table stakes and your CEO will be the first to be phished without it.
Post reply on HN