Ivanti disclosed limited exploitation of flaws in on-premises EPMM.
What happened. Ivanti issued an update for Endpoint Manager Mobile and said it knew of a very limited number of exploited customer environments. The company separated the affected on-prem product from its cloud MDM and similarly named products.
Impact and confidence
Vendor-confirmed exploitation was limited in the disclosure; “limited” did not make an exposed unpatched system low risk.
Defensive takeaway
Confirm product identity before acting, install the security update, retain logs, and use the vendor’s analysis to scope investigation.