CISA: Recently patched Ivanti EPM flaw now actively exploited
2026-03-10T13:23:35Z•837c7a54b496892b6b9283a155a09bf89c6ba8a6cda3920714759e7f594c194c
.arpaA0BackdoorAPT28CISAClickFix technique','DonutLoader','CastleRAT'CovenantEricsson breachFBI advisoryIPv6Ivanti EPMMicrosoft IntuneMicrosoft Teams phishingSalesforce AuraShinyHuntersSignalTermite ransomwareVelvet TempestWhatsAppaccount hijackingactively exploitedcloud exploitationhotpatchpatchingphishingphishing evasion
What happened
A batch of active security incidents and advisories: CISA warned that a recently patched high‑severity Ivanti Endpoint Manager (EPM) vulnerability is being actively exploited and ordered U.S. federal agencies to patch within three weeks. Microsoft will enable hotpatching by default for eligible Intune‑managed devices starting May 2026. Nation‑state and criminal actors are active — APT28 is using a custom Covenant variant for long‑term espionage, Microsoft Teams phishing campaigns are pushing a new A0Backdoor via social engineering/Quick Assist, and attackers are increasingly exploiting newly‑d
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 837c7a54b496892b6b9283a155a09bf89c6ba8a6cda3920714759e7f594c194c
- Enrichment time
- 2026-03-10T13:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.