frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Sleeper Shells: Attackers Are Planting Dormant Backdoors in Ivanti EPMM

https://defusedcyber.com/ivanti-epmm-sleeper-shells-403jsp
65•waihtis•2h ago

Comments

mmsc•1h ago
Every single Ivanti product (including their SSL-VPN) should be considered a critical threat. The fact that this company is allowed to continue to sell their malware dressed-up as "security solutions" is a disaster. How they haven't been sued into bankruptcy is something I'll never understand.
waihtis•1h ago
Well, next week there will be a similar vulnerability Fortinet and everyone will momentarily forget about Ivanti again :-)
mmsc•1h ago
Yes. These companies should be shut down in the name of national security, seriously.
yoyohello13•1h ago
If crowdstrike is any indicator, expect Ivanti stock to go up now. Seems to be the mo for security companies. Fuck up, get paid.
Ekaros•43m ago
There is no bad publicity? I take few had heard of them before so this is free marketing putting the name in public. Or then there is some broken LLM based sentiment analysis bot that automatically buy companies in news...
Nextgrid•43m ago
> How they haven't been sued into bankruptcy is something I'll never understand.

Isn't most off-the-shelf software effectively always supplied without any kind of warranty? What grounds would the lawsuit have?

mmsc•29m ago
Suing for negligence and friends is how car companies -- when it is found out they've built something highly unsafe/dangerously broken -- happens. I don't see the difference.
Nextgrid•36m ago
The purpose of cybersecurity products and companies is not to sell security. It's to sell the illusion of security to (often incompetent) execs - which is perfectly fine because the market doesn't actually punish security breaches so an illusion is all that's needed. It is an insanely lucrative industry selling luxury-grade snake oil.

Actual cybersecurity isn't something you can just buy off-the-shelf and requires skill and making every single person in the org to give a shit about it, which is already hard to achieve, and even more so when you've tried for years to pay them as little as you can get away with.

cortesoft•30m ago
It's also selling box checks for various certifications.
sebstefan•1h ago
I didn't see that exploit showing up on Hackernews so here it is

https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-En...

Ivanti doesn't explain how this happened or what mistake led to this exploit being created.

rezhaze88•1h ago
There is some dark amusement about an MDM and general enterprise management and security systems being used as the attack vector. Ivanti in particular has proven itself to be swiss cheese as of late, and would be bankrupt if people cared about security rather than it being a compliance/insurance checkbox that truly _nobody_ cares about in practice.

Semi-related: with the recent much-touted cybersecurity improvements of AI models (as well as the general recent increase in tensions and conflicts worldwide) I wonder just how much the pace of attacks will increase, and whether it’ll prove to be a benefit or a disadvantage over time. Government sponsored teams were already combing through every random weekend project and library that somehow ended in node or became moderately popular, but soon any dick and tom will be able to do it at scale for a few bucks. On the other hand, what’s being exploited tends to get patched in time - but this can take quite a while, especially when the target is some random side project on github last updated 4 years ago.

My gut feeling is that there will be a lot more exploitation everywhere, and not much upside for the end consumer (who didn’t care about state level actors anyway). Probably a good idea to firewall aggressively and minimize the surface area that can be attacked in the first place. The era of running any random vscode extension and trust-me-bro chrome extension is likely at an end. I’m also looking forward to being pwned by wifi enabled will-never-be-updated smart appliances that seem to multiply by the year.

chillax•1h ago
Related: Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) https://labs.watchtowr.com/someone-knows-bash-far-too-well-a...
ddtaylor•43m ago
I think there is an easier substitution attack since there is shell expansion occuring. I will toy with it later today.
pixl97•1h ago
>We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure.

“We are aware” and “very limited” are likely (in our opinion, this is probably not fact, etc, etc) to be doing a significant amount of lifting.

For avoidance of doubt, the following versions of Ivanti EPMM are patched:

None

----

Ah, this company is a security joke as most software security companies are.

javcasas•52m ago
"We are aware" can mean "we are taking this very seriously and have seen very little so far" or it can mean "after covering our eyes and plugging our ears we are seeing and hearing very little of this problem".
moepstar•48m ago
If you're aware of the sheer number of exploits that can work around or without authentication against anything Ivanti, it has to be the latter.
pipo234•22m ago
And "a very limited number" may mean "though we pretend to be a big company, we have a limited number of customers and while they all pay licence fees, most are not actually using the product in production."
goopypoop•25m ago
thank god they're dormant eh

Is HubSpot aggressive about collections?

https://old.reddit.com/r/hubspot/comments/1r0a00z/hubspot_collections_after_cancelling_question/
1•waldopat•59s ago•0 comments

Windows 11 vs. Ubuntu Linux Performance for Intel Core Ultra X7 Panther Lake

https://www.phoronix.com/review/windows-linux-panther-lake
1•rbanffy•1m ago•0 comments

Show HN: ClawSec an open-source, community-driven secure skill suite

https://github.com/prompt-security/clawsec
1•abutbul•2m ago•0 comments

Tutorial – What is a variational autoencoder?

https://jaan.io/what-is-variational-autoencoder-vae-tutorial/
1•teleforce•2m ago•0 comments

Show HN: Ayder Crash Sandbox – SIGKILL durability proof (per-visitor container)

https://ayder.xyz/sandbox/4e6c7c40
1•Aydarbek•3m ago•1 comments

Show HN: Context Lens – See what's inside your AI agent's context window

https://github.com/larsderidder/context-lens
1•theredbeard•4m ago•0 comments

Continuous AI in practice: What developers can automate today with agentic CI

https://github.blog/ai-and-ml/generative-ai/continuous-ai-in-practice-what-developers-can-automat...
1•alhazrod•4m ago•0 comments

Hard-braking events as indicators of road segment crash risk

https://research.google/blog/hard-braking-events-as-indicators-of-road-segment-crash-risk/
1•aleyan•4m ago•0 comments

Opus 4.6, Codex 5.3, and the post-benchmark era

https://www.interconnects.ai/p/opus-46-vs-codex-53
1•pretext•6m ago•0 comments

Volvo Proposes 100-Mile Plug-In Hybrids for Drivers with Range Anxiety

https://www.thedrive.com/news/volvo-proposes-100-mile-plug-in-hybrids-as-a-bridge-for-drivers-wit...
1•PaulHoule•9m ago•1 comments

Intel Releases QATlib 26.02 with New APIs for Zero-Copy DMA

https://www.phoronix.com/news/Intel-QATlib-26.02
1•rbanffy•9m ago•0 comments

Ct. of App. of Tenn. rules Nashville shooter docs must be open for inspection

https://www.courtlistener.com/opinion/10784211/clata-renee-brewer-v-metropolitan-government-of-na...
1•pcaharrier•9m ago•0 comments

Show HN: Airut – Sandboxed Claude Code sessions over email

https://github.com/airutorg/airut
1•hardsnow•10m ago•0 comments

A Brief History of App Icons from Apple's Creator Studio

https://blog.jim-nielsen.com/2026/history-of-creator-studio-icons/
1•ulrischa•10m ago•0 comments

Formal model of time entry (aggregation → composition)

https://github.com/VoxleOne/FunctionalUniverse/blob/main/docs/history-entry-mechanism.md
1•voxleone•12m ago•0 comments

World Models and the Data Problem in Robotics

https://joeljang.github.io/world-models-for-robotics
1•gmays•14m ago•0 comments

Artemis II Races China to Get Astronauts to the Moon

https://spectrum.ieee.org/artemis-ii-launch-nasa-orion
1•rbanffy•15m ago•0 comments

effect.app

https://effect.app
1•helloplanets•15m ago•0 comments

Show HN: Stop tracking time, start reconstructing work (with anker)

https://github.com/charemma/anker
1•charemma•16m ago•0 comments

The Only Thing Standing Between Humanity and AI Apocalypse Is Claude?

https://www.wired.com/story/the-only-thing-standing-between-humanity-and-ai-apocalypse-is-claude/
1•bpedro•16m ago•1 comments

A55d2c8dd2e136de9e334bcbe030bc2e

https://gist.github.com/jewe8ham/a55d2c8dd2e136de9e334bcbe030bc2e
1•graefsw•18m ago•0 comments

Show HN: Pyrig – One command to set up a production-ready Python project

https://github.com/Winipedia/pyrig
1•Winipedia•18m ago•0 comments

Guidelines for Contributing with AI

https://github.com/qdrant/qdrant/pull/8076/files
2•generall•19m ago•0 comments

Ultrarunners in Secondhand Trainers

https://www.theguardian.com/global-development/2026/feb/09/ultrarunners-rickshaw-drivers-madagasc...
2•slow_typist•20m ago•0 comments

Design Basics for Developers

https://www.designlanguage.xyz/about
1•charlesiv•21m ago•0 comments

Stop abusing Bernoulli when describing lift

https://boards.straightdope.com/t/stop-abusing-bernoulli-when-describing-lift/647933
1•the-mitr•22m ago•0 comments

We Forked Supabase Because Self-Hosted Postgres Is Broken

https://vela.simplyblock.io/blog/vela-open-source/
7•yrashk•22m ago•0 comments

If we do not work together, we will not survive

https://camplight.net/evergreen/if-we-do-not-work-together-we-will-not-survive/
3•altras•23m ago•1 comments

Algos, Bias, Due Process, & You

https://suffolklitlab.org/algos-bias-due-process-you/
1•m-hodges•24m ago•0 comments

Show HN: Chaos Agents – Run chaos experiments with agents

https://github.com/system32-ai/chaos-agents
1•debarshri•24m ago•0 comments