CISA: Recently patched Ivanti EPM flaw now actively exploited

2026-03-10T13:23:35Z837c7a54b496892b6b9283a155a09bf89c6ba8a6cda3920714759e7f594c194c
.arpaA0BackdoorAPT28CISAClickFix technique','DonutLoader','CastleRAT'CovenantEricsson breachFBI advisoryIPv6Ivanti EPMMicrosoft IntuneMicrosoft Teams phishingSalesforce AuraShinyHuntersSignalTermite ransomwareVelvet TempestWhatsAppaccount hijackingactively exploitedcloud exploitationhotpatchpatchingphishingphishing evasion

What happened

A batch of active security incidents and advisories: CISA warned that a recently patched high‑severity Ivanti Endpoint Manager (EPM) vulnerability is being actively exploited and ordered U.S. federal agencies to patch within three weeks. Microsoft will enable hotpatching by default for eligible Intune‑managed devices starting May 2026. Nation‑state and criminal actors are active — APT28 is using a custom Covenant variant for long‑term espionage, Microsoft Teams phishing campaigns are pushing a new A0Backdoor via social engineering/Quick Assist, and attackers are increasingly exploiting newly‑d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
837c7a54b496892b6b9283a155a09bf89c6ba8a6cda3920714759e7f594c194c
Enrichment time
2026-03-10T13:23:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.