[v7.4.1] Threat Advisory: One threat actor responsible for 83% of recent Ivanti RCE attacks

ANALYST: BIVASH KUMAR NAYAK (CHIEF SECURITY ARCHITECT) • PUBLISHED: Sunday, 15 February 2026
TLP:AMBER // GOC-APEX-VERIFIED-INTELLIGENCE

One threat actor responsible for 83% of recent Ivanti RCE attacks

ID: CDB-APEX-1771162799 | Risk: 7.5/10 | Generated: 1771162799

Executive Summary (BLUF)

Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-21962 and CVE-2026-24061. [...]...

Tactical Correlation (Diamond Model)

Adversary / Capability

Initial Access

Infrastructure / Assets

Internal/Cloud

Visual Geographic Intelligence

GLOBAL THREAT DISTRIBUTION

* Red pulses indicate active IoC origins triaged in this sweep.

[+] Open Technical Annex (IOCs & Raw Data)

CVE: CVE-2026-21962, CVE-2026-24061

This document is a machine-generated intelligence advisory from CyberDudeBivash Pvt. Ltd. Unauthorized distribution of TLP:AMBER data is prohibited.