Ivanti has confirmed that its end-of-life MobileIron Core versions 11.2 and older are being impacted by a new critical authentication bypass vulnerability, which could be leveraged to compromise mobile device users' personally identifiable information and enable webshell deployment in impacted servers, reports BleepingComputer.
A hacking campaign that exploited Ivanti mobile device manager to target the Norwegian government began in April and possible earlier, say cybersecurity agencies
UPDATE: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an alert on July 28, 2023, regarding three (3) new malware reports in association with the exploitation of CVE-2023-2868.