A significant number of exploitation attempts targeting a recently disclosed vulnerability in Ivanti Endpoint Manager Mobile (EPMM) have been linked to a single IP address associated with bulletproof hosting services from PROSPERO. Threat intelligence firm GreyNoise recorded 417 exploitation sessions from eight unique source IP addresses between February 1 and February 9, 2026, with an estimated 346 of these sessions traced to the identified IP. This highlights the concentrated threat posed by specific hosting infrastructures in cybersecurity. The findings emphasize the importance of monitoring and mitigating risks stemming from such sources.
Want More Context? 🔎
