83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure
One IP address on PROSPERO's impregnable hosting infrastructure is responsible for a substantial portion of the exploitation attempts that target a recently revealed security weakness in Ivanti Endpoint Manager Mobile (EPMM).
Between February 1 and February 9, 2026, 417 exploitation sessions from 8 distinct source IP addresses were observed, according to threat intelligence firm GreyNoise. An estimated 346 exploitation sessions, or 83% of all attempts, have started from 193.24.123[.]42.
One of the two critical security flaws in EPMM, CVE-2026-1281 (CVSS scores: 9.8), and CVE-2026-1340, which an attacker might use to accomplish unauthenticated remote code execution, are the targets of the nefarious activity. Ivanti admitted late last month that it was aware of only a small number of ...

