Latest / Tech Talks With Kinsoft / Ivanti Zero-Days Breach the EU Commission & Dutch Govt
Transcript
- 0:00welcome to tech talks with kinsoft glad to be
- 0:02here so today we're looking at something that
- 0:04honestly it feels a bit like a movie script it
- 0:08really does yeah because the very software designed
- 0:12to be you know this ultimate digital bodyguard
- 0:15for places like the European Commission and the
- 0:17Dutch government. It just became the exact weapon
- 0:21used to break into them. Yeah, it's a massive
- 0:23twist. Right. And our mission for this show is
- 0:25simple. We take a stack of your sources like
- 0:28articles, technical research, advisory notes,
- 0:31and we extract the most important nuggets of
- 0:33knowledge out of them. Exactly. We do the heavy
- 0:35lifting of reading and synthesizing. So you,
- 0:38the listener, get a shortcut to staying well
- 0:40informed without that dreaded information overload.
- 0:43And today's sources are painting a very, very
- 0:45tense picture. Yeah, tense is an understatement.
- 0:48We're looking at emergency warnings from national
- 0:50security agencies across the U .S., Canada, Singapore,
- 0:54and the U .K. Wow, so globally. Yeah, globally.
- 0:57They are all sounding the alarm over a highly
- 1:00coordinated wave of cyber attacks. And they're
- 1:03targeting a specific piece of software used by
- 1:06major organizations to manage and secure their
- 1:09mobile devices. Right off the bat, that feels
- 1:11incredibly counterintuitive. Oh, absolutely.
- 1:13Like if these systems are specifically built
- 1:15to enforce security on our phones, isn't it incredibly
- 1:17ironic that they are the very things letting
- 1:20the attackers in? It is, but... It really comes
- 1:23down to the immense power these platforms hold.
- 1:26Right. The specific software in the crosshairs
- 1:28today is called Ivanti Endpoint Manager Mobile,
- 1:32or EPMM. Okay. EPM. Yeah. And to understand the
- 1:36vulnerability, we first need to understand the
- 1:38mechanism of what an MDM, a mobile device management
- 1:41platform, actually does. Okay. Break that down
- 1:44for us. Basically, organizations use EPMM to
- 1:46control their entire fleet of smartphones and
- 1:48tablets. So if I'm, say, working for a government
- 1:51agency and I'm using a company -issued phone,
- 1:53EPMM is like the invisible hand controlling what
- 1:56I can and cannot do. That's a really good way
- 1:58to look at it, yeah. Yeah. It dictates your app
- 2:00settings, monitors compliance, and... It can
- 2:04even remotely wipe the device if you lose it
- 2:06on a train. Oh, wow. Okay. It acts as the central
- 2:09brain enforcing security rules across the whole
- 2:12mobile network. Right. But because it has absolute
- 2:16authority over thousands of remote devices, it
- 2:19requires a constant open line of communication
- 2:22to the outside world. Which means it has to be
- 2:24exposed. Exactly. I mean, it can't hide behind
- 2:26a massive internal firewall if it needs to, you
- 2:29know, talk to an employee's phone while they're
- 2:31sitting in a coffee shop in another country.
- 2:33Precisely. That is exactly why they are such
- 2:35high value targets. Makes sense. And this brings
- 2:38us to the core issue. There are two specific
- 2:40vulnerabilities discovered in late January. Tract
- 2:43is CVE -2026 -1281 and CVE -2026 -1340. OK, those
- 2:50are the exact designations. Right. And, you know,
- 2:52cybersecurity scales rank threats from 1 to 10
- 2:55based on their severity. Yeah. These two flaws
- 2:58sit at a 9 .8. A 9 .8 out of 10. I know a 9 .8
- 3:01sounds terrifying on paper, but... What does
- 3:04that actually mean in practice? Like, why isn't
- 3:07it a 5 or a 6? Well, a 9 .8 essentially means
- 3:11the vulnerability allows for unauthenticated
- 3:14remote code execution. Okay, let's break those
- 3:16terms down for a second. Unauthenticated means?
- 3:19It means the attacker doesn't need to steal a
- 3:21username. Oh, wow. Yeah, they don't need to guess
- 3:24a password, and they don't need to intercept
- 3:26a two -factor authentication code. Nothing at
- 3:28all? Nothing. They need absolutely zero credentials
- 3:31to interact with the system. I admit, I hear
- 3:33terms like code injection and remote code execution
- 3:36thrown around a lot. But how does someone actually
- 3:39force a secure server to run their malicious
- 3:41commands without even logging in first? So the
- 3:44mechanism is actually a flaw in how the software
- 3:47processes input. Okay. Normally, a system expects
- 3:50specific data in specific fields, like entering
- 3:53your name into a form. Right. But with a code
- 3:55injection vulnerability, the software fails to
- 3:58sanitize or separate the data from the underlying
- 4:01system commands. So, an attacker sends a carefully
- 4:05crafted message to the server. And instead of
- 4:09reading it as data, the server's back end gets
- 4:11confused. It thinks it's an instruction. Exactly.
- 4:14It reads it as an administrative command. It
- 4:16just blindly executes whatever the attacker typed.
- 4:19Okay, let me see if I can picture this physically.
- 4:20Go for it. So an edge device like EPMM is essentially
- 4:24the bouncer at the club's front door, right?
- 4:26Yeah. But with a 9 .8 vulnerability, the bouncer
- 4:29isn't just letting people in with that ID. The
- 4:32bouncer is actively handing out master keys to
- 4:35the whole building. That's a great analogy. It's
- 4:37actually a bit like a secure corporate building
- 4:39that has an automated pneumatic tube system on
- 4:42the outside wall for employees to drop off work
- 4:45orders. Oh, right. Because it's Internet facing.
- 4:47Exactly. That pneumatic tube has to be accessible
- 4:50from the street. So anyone walking by can drop
- 4:53something in. Right. And the flaw is that the
- 4:56automated sorting room inside the building doesn't
- 4:58check who sent the capsule. Yes, exactly. An
- 5:01attacker just drops in a forged work order that
- 5:04says, you know, fire the security guards and
- 5:06send. the vault combination to this external
- 5:08address. And the internal system just processes
- 5:11it automatically? It processes it with the highest
- 5:14level of authority. That is the reality of unauthenticated
- 5:17remote code execution. That is just wild. It
- 5:21is. And, you know, the UK NHS Digital's National
- 5:25Cybersecurity Operations Centre, the CSOC, they
- 5:29emphasize this in their advisory. What did they
- 5:31say? They pointed out that edge devices like
- 5:33EPMM are internet -facing by design. Attackers
- 5:36know this. Right. They know it's sitting right
- 5:38there on the perimeter. Yeah, which is why vulnerabilities
- 5:40here are rapidly weaponized at zero days. The
- 5:43target is just sitting out there in the open.
- 5:45Right. So since we know the front door was left
- 5:47wide open, who exactly sneaked inside before
- 5:50the vendor could get a patch out in late January?
- 5:53Well, the confirmed victims include some very
- 5:55high -profile government entities. Like who?
- 5:58We have verified breaches within the Dutch government,
- 6:01specifically, and somewhat ironically, the Dutch
- 6:04Data Protection Authority. Wait, the Data Protection
- 6:07Authority itself? Yes, the AP and also the Judicial
- 6:10Council. You really can't write that kind of
- 6:11irony. The data protectors got their data stolen.
- 6:14Pretty much. But I want to dig into what was
- 6:17actually stolen here. According to the country's
- 6:20State Secretary for Justice and Security, attackers
- 6:23viewed work -related data of the employees. Right.
- 6:27We are talking about names, business email addresses,
- 6:30and phone numbers. Yeah, that's the extent of
- 6:33the compromised data that was publicly confirmed.
- 6:36You know, for you listening right now, it might
- 6:38be incredibly easy to shrug that off. Oh, for
- 6:40sure. You hear government data breach, and you
- 6:42immediately expect, like, stolen state secrets
- 6:45or classified documents. Names and phone numbers
- 6:49sound like they just walked off with a corporate
- 6:50phone book. Yeah, it doesn't sound that scary.
- 6:53Right. Why is a stolen phone book treated as
- 6:55a national security incident? So taking a step
- 6:58back to look at modern attack chains changes
- 7:01the perspective completely here. Okay. A corporate
- 7:03phone book belonging to a government's data protection
- 7:06authority is an absolute goldmine. A goldmine
- 7:09for what? It provides the exact blueprint a threat
- 7:13actor needs. For highly targeted spear phishing
- 7:16campaigns. Oh, I see. So it's not the end goal.
- 7:19It's the reconnaissance phase. Exactly. It's
- 7:21the crucial first step. Right. Imagine an attacker
- 7:23wants to compromise a senior judge. Right. If
- 7:26they send a generic malicious email, it gets
- 7:29flagged by spam filters or just ignored. Sure.
- 7:31But now, because they have the EPMM data, they
- 7:34know exactly who works in which department, what
- 7:37their email is and what their mobile number is.
- 7:39So they can make it. Super convincing. Incredibly
- 7:42convincing. They can text an employee saying,
- 7:44you know, this is Dave from IT. Your EPMM mobile
- 7:47profile is failing to sync. Click this link to
- 7:50re -authenticate. Wow. And because the employee
- 7:53knows they actually use EPMM and the text is
- 7:56coming to their specific work device, they are
- 7:58infinitely more likely to click it. It weaponizes
- 8:01their own organizational context against them.
- 8:04Exactly. The psychological manipulation becomes
- 8:06much more effective. And that's why the theft
- 8:08of basic directory information is treated with
- 8:11emergency severity. That makes a lot of sense.
- 8:13The Dutch government wasn't the only major European
- 8:17entity caught in this wave, though. No, they
- 8:19weren't. The European Commission was also targeted.
- 8:21Yes. On January 30, 2026, CERT -EU. that's the
- 8:26cybersecurity team for all EU institutions, they
- 8:29detected an intrusion on the European Commission's
- 8:32central infrastructure. Specifically, the infrastructure
- 8:35managing their mobile devices. Right. Now, they
- 8:38didn't explicitly name Ivanti EPMM in their initial
- 8:42public statement. Oh, they didn't? No. But reading
- 8:45through the industry consensus, it's widely understood
- 8:47that they were dealing with the exact same platform.
- 8:49The timing and the nature of the compromise were
- 8:52identical. Right. The mechanics of the attack
- 8:54were the same. And the commission acknowledged
- 8:56that the intrusion may have resulted in access
- 8:58to staff names and mobile numbers, just like
- 9:01the Dutch breach. Exactly. But I want to pause
- 9:03here because the timeline of the European Commission
- 9:06story is completely wild compared to a typical
- 9:10government data breach. It really is. The timeline
- 9:13is arguably the most crucial takeaway from this
- 9:15entire campaign. CERT -EU detected the intrusion,
- 9:19and the Commission's security teams moved with
- 9:22staggering speed. They ensured the incident was
- 9:25contained, the vulnerability was isolated, and
- 9:27the entire system was completely cleaned within
- 9:30exactly nine hours. Nine hours. Nine hours. I
- 9:34want to highlight this for you, the listener,
- 9:35because context is everything here. When we usually
- 9:39read reports about major network intrusions,
- 9:41the dwell time, which is the amount of time an
- 9:44attacker sits inside a network before being discovered,
- 9:47is typically measured in weeks, right? Weeks,
- 9:49if not months. The global median dwell time often
- 9:53hovers around two to three weeks. And for sophisticated
- 9:56state -sponsored actors, they can remain undetected
- 9:59for hundreds of days. Wow. So detecting, containing
- 10:02and cleaning an intrusion on a massive governmental
- 10:05infrastructure in nine hours is exceptional.
- 10:08And because of that incredible speed, no actual
- 10:11mobile devices were compromised. Right. The attackers
- 10:13broke into the central management server. They
- 10:15might have scraped that contact list we talked
- 10:17about, but they were kicked out before they could
- 10:19pivot and push any malicious commands down to
- 10:22the actual smartphones. The containment prevented
- 10:24the worst case scenario. If the attackers had
- 10:27more time, they could have used the server's
- 10:29authority to silently install spyware on every
- 10:32single government -issued phone. Which is terrifying.
- 10:35Truly. And it really shifts how we have to think
- 10:37about cybersecurity. You know, in a world where
- 10:39zero days are inevitable, where your time to
- 10:43containment is the difference between a leaked
- 10:44phone book and a total network takeover. Absolutely.
- 10:48Fast detection and rapid containment are what
- 10:51saved the EC from an unrecoverable compromise.
- 10:54But let's look at the practical reality for everyone
- 10:56else. Nine hours is incredibly fast for the European
- 10:59Commission. But what about the organizations
- 11:01that didn't catch it on day one? Yeah, that's
- 11:04the big question. Can they just install the late
- 11:06January patch from Avanti, run the newly released
- 11:09detection script, and sleep soundly? The short
- 11:12answer is a resounding no. Really? Just patching
- 11:16isn't enough? No. The Dutch National Cybersecurity
- 11:18Center, the NCSC -NL, issued very stark advice
- 11:22regarding this. They explicitly warned organizations
- 11:25that even if you patched quickly, you must assume
- 11:28compromise. Assume compromise. Let's unpack that.
- 11:32Does that mean even if I patched my system the
- 11:35minute the update came out, I have to operate
- 11:38under the assumption that someone already broke
- 11:40in? Yes. You have to operate under that assumption
- 11:42because threat actors may have already exploited
- 11:45the system and wiped their tracks. They wiped
- 11:47their tracks. Oh, absolutely. They delete the
- 11:49access logs. They remove the initial malware
- 11:51they used to break in. They know you were going
- 11:54to run a detection script eventually. Right.
- 11:56So if an IT admin runs a detection tool and it
- 11:59comes back clean, that doesn't actually mean
- 12:02the system was never hacked. It just means the
- 12:04threat actor might be exceptionally good at digital
- 12:07housekeeping. The absence of evidence is not
- 12:10evidence of absence. That is a chilling thought.
- 12:13So if patching just fixes the broken lock but
- 12:16the attacker is already inside the house, what
- 12:18are the actionable steps? The NCSCNL laid out
- 12:21strict advice, right? They did. First, you are
- 12:24required to change all passwords for every single
- 12:27account present on that system. Okay, change
- 12:29all passwords. Because if the attackers were
- 12:30inside, you have to assume they scraped the entire
- 12:33credential database. That makes sense. The second
- 12:36step is even more critical and often overlooked.
- 12:39You must renew the private keys in use on the
- 12:42system. Wait, private keys? How do they factor
- 12:44into this? Private keys are cryptographic files
- 12:48used to authenticate secure communications. Right.
- 12:51Like between the server and the mobile devices.
- 12:53Okay. If an attacker steals those private keys,
- 12:56they can essentially forge legitimate connection.
- 12:59They can impersonate the server itself. So even
- 13:01if I change the human passwords and patch the
- 13:04flaw, if I don't renew those cryptographic keys,
- 13:07the attacker just walks right back in disguised
- 13:09as the server. Exactly. You have to burn the
- 13:11old cryptographic locks and install completely
- 13:13new ones. Wow. And finally, they heavily advise
- 13:17monitoring internal traffic originating from
- 13:20that ePMM system, looking for signs of lateral
- 13:22movement. Right, lateral movement. That's when
- 13:25the attacker uses the compromised server as a
- 13:27lily pad to... jump deeper into the network.
- 13:30Exactly. And to prove this isn't just a one -off
- 13:32anomaly, this product family is a continuous
- 13:35high -value target. Yeah, I want to remind the
- 13:37listener about the historical context here. We
- 13:40saw very similar flaws in EPMM hacked 12 Norwegian
- 13:43agencies back in 2023. Yep. And it didn't stop
- 13:46there. In May 2025, CERT -EU reported two other
- 13:50Ivanti EPMM zero days exploited in the wild.
- 13:54Right. Which were later tied to a suspected China
- 13:56nexus threat actor targeting multiple global
- 13:59sectors. Healthcare, finance, defense. It was
- 14:01a huge deal. A massive deal. So synthesizing
- 14:04all these takeaways for you, the listener. We
- 14:06really see the danger of internet -facing edge
- 14:09devices. Absolutely. And when dealing with CVSS
- 14:119 .80 days, patching is merely the baseline.
- 14:14The true defense lies in rapid detection like
- 14:17the EC's nine -hour containment and adopting
- 14:19an assume -compromise posture. That is the new
- 14:22reality. Now, if you're looking to fortify your
- 14:24own network and want to discuss your security
- 14:26and IT needs, make sure to visit www .kinsoft
- 14:29.com .au. And as we wrap up, I want to leave
- 14:32you with a final lingering question to ponder.
- 14:35Okay, let's hear it. As organizations push more
- 14:37and more security enforcement to the edge of
- 14:39their networks to protect remote workers and
- 14:41mobile devices, are we actually just moving our
- 14:44most valuable, vulnerable targets outside the
- 14:47safety of the castle walls? Wow. That is definitely
- 14:50something to think about. Thank you for listening,
- 14:52and we'll catch you on the next episode.