industryThe Ransomware Era (2020-Present) Daily Briefing Landmark Event

    Critical Ivanti Zero-Day Vulnerabilities Exploited Amid Widespread Breaches

    Saturday, January 31, 2026

    Critical Ivanti Zero-Day Vulnerabilities Exploited Amid Widespread Breaches

    On January 31, 2026, Ivanti disclosed two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM), identified as CVE-2026-1281 and CVE-2026-1340. These vulnerabilities, which allow unauthenticated remote code execution, have been actively exploited in the wild. With a CVSS score of 9.8, organizations are urged to apply patches immediately to mitigate potential risks. This alarming disclosure comes at a time when the cybersecurity landscape is already strained, highlighted by a significant data breach at TriZetto affecting healthcare providers in multiple states, exposing sensitive patient data. Additionally, the ShinyHunters ransomware group has claimed responsibility for breaching high-profile targets, including Match Group and Panera Bread, further emphasizing the need for vigilance against evolving cyber threats. The recent hack of Trust Wallet, linked to a supply chain attack, exemplifies the growing complexity of threats facing both consumers and businesses today.

    Also In Security Today

    • TriZetto Data Breach: Ongoing fallout from a breach at TriZetto has affected numerous healthcare providers, compromising sensitive data of thousands of individuals in Oregon. Source
    • Ransomware Attacks: The ShinyHunters ransomware group has breached multiple high-profile targets, including Match Group and Panera Bread, exposing tens of millions of records through social engineering tactics. Source
    • Trust Wallet Hack: Trust Wallet has reported a supply chain attack that led to the theft of around $8.5 million in cryptocurrency, exploiting compromised developer secrets. Source

    Analyst's Take

    Today's news underscores a critical moment in cybersecurity as two high-severity vulnerabilities in Ivanti's software pose immediate risks to organizations relying on mobile device management. The ongoing data breaches at TriZetto and the ShinyHunters ransomware attacks highlight the persistent threat landscape that organizations face. Defenders must prioritize patch management and invest in robust security training to combat social engineering tactics effectively. As cyber threats become increasingly sophisticated, a proactive approach in vulnerability management and incident response is essential for safeguarding sensitive data and maintaining operational integrity.

    Sources

    Ivanti vulnerability ransomware data breach healthcare Trust Wallet