Live data from Hacker News

Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

defusedcyber.com

1–10 of 54 posts

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#2
Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#4
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

Well, next week there will be a similar vulnerability Fortinet and everyone will momentarily forget about Ivanti again :-)

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#5
There is some dark amusement about an MDM and general enterprise management and security systems being used as the attack vector. Ivanti in particular has proven itself to be swiss cheese as of late, and would be bankrupt if people cared about security rather than it being a compliance/insurance checkbox that truly _nobody_ cares about in practice.

Semi-related: with the recent much-touted cybersecurity improvements of AI models (as well as the general recent increase in tensions and conflicts worldwide) I wonder just how much the pace of attacks will increase, and whether it’ll prove to be a benefit or a disadvantage over time. Government sponsored teams were already combing through every random weekend project and library that somehow ended in node or became moderately popular, but soon any dick and tom will be able to do it at scale for a few bucks. On the other hand, what’s being exploited tends to get patched in time - but this can take quite a while, especially when the target is some random side project on github last updated 4 years ago.

My gut feeling is that there will be a lot more exploitation everywhere, and not much upside for the end consumer (who didn’t care about state level actors anyway). Probably a good idea to firewall aggressively and minimize the surface area that can be attacked in the first place. The era of running any random vscode extension and trust-me-bro chrome extension is likely at an end. I’m also looking forward to being pwned by wifi enabled will-never-be-updated smart appliances that seem to multiply by the year.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#7
>We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.

“We are aware” and “very limited” are likely (in our opinion, this is probably not fact, etc, etc) to be doing a significant amount of lifting.

For avoidance of doubt, the following versions of Ivanti EPMM are patched:

None

----

Ah, this company is a security joke as most software security companies are.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#8
post #4
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

Well, next week there will be a similar vulnerability Fortinet and everyone will momentarily forget about Ivanti again :-)

Yes. These companies should be shut down in the name of national security, seriously.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#9
post #2

Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.

If crowdstrike is any indicator, expect Ivanti stock to go up now. Seems to be the mo for security companies. Fuck up, get paid.

Re: Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

#10
post #7

>We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure. “We are aware” and “very limited” are likely (in our opinion, this is probably not fact, etc, etc) to be doing a significant amount of lifting. For avoidance of doubt, the following versions of Ivanti EPMM are patched: None ---- Ah, this company is a security joke as most software security companies are.

"We are aware" can mean "we are taking this very seriously and have seen very little so far" or it can mean "after covering our eyes and plugging our ears we are seeing and hearing very little of this problem".
Post reply on HN