home.social

#mobileiron — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mobileiron, aggregated by home.social.

  1. New #zeroday s in #ivanti EPMM formerly known as #mobileiron. This company alone makes sure that I won't run out of work any time soon 😬 At this point I'm starting to wonder whether your org is more secure with or without Ivanti products 🧐😱

    forums.ivanti.com/s/article/Se

    #infosec #security #vulnerability

  2. New #zeroday s in #ivanti EPMM formerly known as #mobileiron. This company alone makes sure that I won't run out of work any time soon 😬 At this point I'm starting to wonder whether your org is more secure with or without Ivanti products 🧐😱

    forums.ivanti.com/s/article/Se

    #infosec #security #vulnerability

  3. New #zeroday s in #ivanti EPMM formerly known as #mobileiron. This company alone makes sure that I won't run out of work any time soon 😬 At this point I'm starting to wonder whether your org is more secure with or without Ivanti products 🧐😱

    forums.ivanti.com/s/article/Se

    #infosec #security #vulnerability

  4. New #zeroday s in #ivanti EPMM formerly known as #mobileiron. This company alone makes sure that I won't run out of work any time soon 😬 At this point I'm starting to wonder whether your org is more secure with or without Ivanti products 🧐😱

    forums.ivanti.com/s/article/Se

    #infosec #security #vulnerability

  5. Die meisten schaffen es scheinbar nicht die aktuellen kritischen Lücken in Lösungen wie Mobile Iron durch das Installieren von vorhandenen Sicherheitsupdates abzusichern.
    Es gibt immer noch ne Menge angreifbarer Ivanti (ehemals Mobile Iron) Sentry’s da draußen 🤷‍♂️🤦‍♂️. Schlafen die Admins?

    #vulnerability #ivanti #sentry #sicherheit #it #mobileiron #patches #updates

  6. Wer eine Sentry von Ivanti (ehemals Mobile Iron) im Einsatz hat, sollte dringend die letzten Patches einspielen! Angreifer können aus der Ferne Befehle ausführen.

    #mobileiron #ivanti #vulnerability #patch #hacker #exploit #security

  7. #CyberVeille #suisse #MobileIron #Ivanti

    "Des pirates informatiques s'emparent des données de 2800 policiers bernois"

    "Une faille de sécurité dans une application utilisée par la police bernoise a entraîné une importante fuite de données. Des pirates ont pu s'emparer de l'identité et des numéros de téléphone de l'ensemble des 2800 employés de la police cantonale."

    "Le Centre national pour la cybersécurité (NCSC) a informé la police bernoise le 21 juillet de la faille de sécurité dans l'application "MobileIron". Le problème a été rapidement résolu mais les informations avaient déjà fuité."

    👇​
    rts.ch/info/regions/berne/1424

    Vulnérabilités:

    Multiple Vulnerabilities Including Zero-Day Remote Unauthenticated API Access – CVE-2023-35078 – in Ivanti Endpoint Manager Mobile

    ⬇️​
    "On July 24, 2023, Ivanti Endpoint Manager Mobile (EPMM), previously known as MobileIron Core, publicly disclosed details about an unauthenticated API access zero-day vulnerability. CVE-2023-35078 affects versions 11.10, 11.9 and 11.8, but older versions are also at risk of possible exploitation."

    "Our research shows that a total of 85 countries hosted the 5,500 Ivanti Endpoint Manager Mobile servers on the internet. A dozen or so countries had a single server present at the time of our scan, but many countries had dozens each, if not hundreds. Germany and the United States both had over 1,000 servers.
    source:Unit42"

    👇​
    unit42.paloaltonetworks.com/th

  8. #CyberVeille #suisse #MobileIron #Ivanti

    "Des pirates informatiques s'emparent des données de 2800 policiers bernois"

    "Une faille de sécurité dans une application utilisée par la police bernoise a entraîné une importante fuite de données. Des pirates ont pu s'emparer de l'identité et des numéros de téléphone de l'ensemble des 2800 employés de la police cantonale."

    "Le Centre national pour la cybersécurité (NCSC) a informé la police bernoise le 21 juillet de la faille de sécurité dans l'application "MobileIron". Le problème a été rapidement résolu mais les informations avaient déjà fuité."

    👇​
    rts.ch/info/regions/berne/1424

    Vulnérabilités:

    Multiple Vulnerabilities Including Zero-Day Remote Unauthenticated API Access – CVE-2023-35078 – in Ivanti Endpoint Manager Mobile

    ⬇️​
    "On July 24, 2023, Ivanti Endpoint Manager Mobile (EPMM), previously known as MobileIron Core, publicly disclosed details about an unauthenticated API access zero-day vulnerability. CVE-2023-35078 affects versions 11.10, 11.9 and 11.8, but older versions are also at risk of possible exploitation."

    "Our research shows that a total of 85 countries hosted the 5,500 Ivanti Endpoint Manager Mobile servers on the internet. A dozen or so countries had a single server present at the time of our scan, but many countries had dozens each, if not hundreds. Germany and the United States both had over 1,000 servers.
    source:Unit42"

    👇​
    unit42.paloaltonetworks.com/th

  9. #CyberVeille #suisse #MobileIron #Ivanti

    "Des pirates informatiques s'emparent des données de 2800 policiers bernois"

    "Une faille de sécurité dans une application utilisée par la police bernoise a entraîné une importante fuite de données. Des pirates ont pu s'emparer de l'identité et des numéros de téléphone de l'ensemble des 2800 employés de la police cantonale."

    "Le Centre national pour la cybersécurité (NCSC) a informé la police bernoise le 21 juillet de la faille de sécurité dans l'application "MobileIron". Le problème a été rapidement résolu mais les informations avaient déjà fuité."

    👇​
    rts.ch/info/regions/berne/1424

    Vulnérabilités:

    Multiple Vulnerabilities Including Zero-Day Remote Unauthenticated API Access – CVE-2023-35078 – in Ivanti Endpoint Manager Mobile

    ⬇️​
    "On July 24, 2023, Ivanti Endpoint Manager Mobile (EPMM), previously known as MobileIron Core, publicly disclosed details about an unauthenticated API access zero-day vulnerability. CVE-2023-35078 affects versions 11.10, 11.9 and 11.8, but older versions are also at risk of possible exploitation."

    "Our research shows that a total of 85 countries hosted the 5,500 Ivanti Endpoint Manager Mobile servers on the internet. A dozen or so countries had a single server present at the time of our scan, but many countries had dozens each, if not hundreds. Germany and the United States both had over 1,000 servers.
    source:Unit42"

    👇​
    unit42.paloaltonetworks.com/th

  10. Wer es noch nicht gesehen hat: Man konnte bis vor Kurzem auf der Verwaltungsplattform von #MobileIron "einfach so" Adminkonten anlegen, Personendaten auslesen, auf allen Geräten "eigene" Software installieren. Natürlich ohne Berechtigung. Betroffen dürften mehrere tausend Organisationen sein, die ihre Mobilgeräte "sicher" machen wollten… srf.ch/news/international/it-s

  11. Wer es noch nicht gesehen hat: Man konnte bis vor Kurzem auf der Verwaltungsplattform von #MobileIron "einfach so" Adminkonten anlegen, Personendaten auslesen, auf allen Geräten "eigene" Software installieren. Natürlich ohne Berechtigung. Betroffen dürften mehrere tausend Organisationen sein, die ihre Mobilgeräte "sicher" machen wollten… srf.ch/news/international/it-s

  12. Wer es noch nicht gesehen hat: Man konnte bis vor Kurzem auf der Verwaltungsplattform von #MobileIron "einfach so" Adminkonten anlegen, Personendaten auslesen, auf allen Geräten "eigene" Software installieren. Natürlich ohne Berechtigung. Betroffen dürften mehrere tausend Organisationen sein, die ihre Mobilgeräte "sicher" machen wollten… srf.ch/news/international/it-s

  13. Wer es noch nicht gesehen hat: Man konnte bis vor Kurzem auf der Verwaltungsplattform von #MobileIron "einfach so" Adminkonten anlegen, Personendaten auslesen, auf allen Geräten "eigene" Software installieren. Natürlich ohne Berechtigung. Betroffen dürften mehrere tausend Organisationen sein, die ihre Mobilgeräte "sicher" machen wollten… srf.ch/news/international/it-s

  14. Wer es noch nicht gesehen hat: Man konnte bis vor Kurzem auf der Verwaltungsplattform von #MobileIron "einfach so" Adminkonten anlegen, Personendaten auslesen, auf allen Geräten "eigene" Software installieren. Natürlich ohne Berechtigung. Betroffen dürften mehrere tausend Organisationen sein, die ihre Mobilgeräte "sicher" machen wollten… srf.ch/news/international/it-s

  15. #Ivanti, die Firma hinter #MobileIron aka #EMM braucht 4 Monate zum Schliessen einer gemeldeten Lücke zu Unauthenticated Remote Code Execution. 😵‍💫 #RCE
    Sie erwecken damit insgesamt den Anschein, dass sie ihre IT-Sicherheitsprozesse nicht im Griff haben. Oder bisher keinen Weet darauf gelegt hätten.
    heise.de/news/Vielfaeltige-Att

  16. #Ivanti, die Firma hinter #MobileIron aka #EMM braucht 4 Monate zum Schliessen einer gemeldeten Lücke zu Unauthenticated Remote Code Execution. 😵‍💫 #RCE
    Sie erwecken damit insgesamt den Anschein, dass sie ihre IT-Sicherheitsprozesse nicht im Griff haben. Oder bisher keinen Weet darauf gelegt hätten.
    heise.de/news/Vielfaeltige-Att

  17. #Ivanti, die Firma hinter #MobileIron aka #EMM braucht 4 Monate zum Schliessen einer gemeldeten Lücke zu Unauthenticated Remote Code Execution. 😵‍💫 #RCE
    Sie erwecken damit insgesamt den Anschein, dass sie ihre IT-Sicherheitsprozesse nicht im Griff haben. Oder bisher keinen Weet darauf gelegt hätten.
    heise.de/news/Vielfaeltige-Att

  18. #Ivanti, die Firma hinter #MobileIron aka #EMM braucht 4 Monate zum Schliessen einer gemeldeten Lücke zu Unauthenticated Remote Code Execution. 😵‍💫 #RCE
    Sie erwecken damit insgesamt den Anschein, dass sie ihre IT-Sicherheitsprozesse nicht im Griff haben. Oder bisher keinen Weet darauf gelegt hätten.
    heise.de/news/Vielfaeltige-Att

  19. #Ivanti, die Firma hinter #MobileIron aka #EMM braucht 4 Monate zum Schliessen einer gemeldeten Lücke zu Unauthenticated Remote Code Execution. 😵‍💫 #RCE
    Sie erwecken damit insgesamt den Anschein, dass sie ihre IT-Sicherheitsprozesse nicht im Griff haben. Oder bisher keinen Weet darauf gelegt hätten.
    heise.de/news/Vielfaeltige-Att