Ivanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

On October 16, 2024, Ivanti disclosed two vulnerabilities in Endpoint Manager (EPM) chained for pre-auth remote code execution: CVE-2024-29224, an unauthenticated SSRF rated 9.6, and CVE-2024-29226, a path traversal in a downstream service. The week’s disclosure calendar placed it days after FortiManager’s FortiJump and amid a year of Ivanti security crises — from January’s Connect Secure zero-days to September’s Cloud Service Appliance flaw. This account explains the chain mechanics, why consortium defenders pushed urgent patching, and the management-plane pattern of 2024.

Continue ReadingIvanti Endpoint Manager RCE: Two Bugs, One Dangerous Chain

Ivanti Connect Secure Zero-Days: The Edge-Appliance Crisis

January 2024 opened with the year’s first appliance crisis: two pre-authentication zero-days in Ivanti Connect Secure that nation-state actors had already exploited, followed by integrity-check failures and a reset wave across thousands of enterprise VPNs. This account covers CVE-2023-46805 and CVE-2024-21887, the mass exploitation between disclosure and patch, the customers whose breaches surfaced weeks later, and why edge appliances became the year’s most contested patch surface.

Continue ReadingIvanti Connect Secure Zero-Days: The Edge-Appliance Crisis

Zero-Days & AI Supply Chain Attacks: May 2026 Briefing

Five threat streams converged in May 2026: the actively exploited Ivanti EPMM zero-day, a fake OpenAI repo on Hugging Face dropping infostealers, cPanel CVEs reaching CVSS 8.8, TCLBANKER worming through WhatsApp and Outlook, and ShinyHunters hitting Canvas LMS. One briefing, one action plan.

Continue ReadingZero-Days & AI Supply Chain Attacks: May 2026 Briefing