Ivanti EPMM vulnerabilities exploited against Dutch agencies
The Dutch data protection authority (AP) and the Judicial Council (Rvdr) have disclosed that a threat actor exploited vulnerabilities in Ivanti EPMM and gained access to work-related contact information about AP employees. The consequences at the Judicial Council are not known. The incidents are confirmed to relate to the vulnerabilities Ivanti reported in late January. Separately, the European Commission has announced an incident affecting its mobile device management platform. That incident has not been confirmed as related to the Ivanti flaws, but the timing may suggest a connection, and CERT-EU is investigating.
What this means for your organisation
The platform managing mobile devices holds authority over the entire fleet and everything stored on it. If it is compromised, you lose not just a system but control of the devices it governs. Three European public bodies affected in the same period shows that actors are actively hunting for such platforms exposed to the internet.
Berigo recommends
- Confirm that your Ivanti EPMM installation is updated in line with the late January advisory.
- Remove device management administration interfaces from open internet exposure wherever possible.
- Review logs from the period before patching, looking for new administrator accounts and unexpected profile deployments.
- Decide in advance who notifies the data protection authority if employee contact details are exposed.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch