83% of observed Ivanti EPMM exploitation (CVE-2026-1281) traces to one bulletproof IP that isn't on any published IOC list. The IPs that are? VPN exits with zero Ivanti activity. We broke down who's actually doing this ⬇️ https://www.greynoise.io/blog/active-ivanti-exploitation
If you have a fediverse account, you can quote this note from your own instance. Search https://infosec.exchange/users/greynoise/statuses/116047942661766828 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
RE: https://infosec.exchange/@greynoise/116047942661766828
FWIW, if you were using the #GAYINT block list for your Ivanti RMM system, that IP on the bulletproof AS200593 would have been blocked. 
