DiscoverSANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation
SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation

SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation

Update: 2025-09-23
Share

Description



CISA Reports Ivanti EPMM Exploit Sightings

Two different organizations submitted backdoors to CISA, which are believed to have been installed using Ivanti vulnerabilities patched in May.

https://www.cisa.gov/news-events/analysis-reports/ar25-261a

Lastpass Observes Impersonation on GitHub

Lastpass noted a number of companies being impersonated via fake GitHub repositories in order to trick victims to download Mac malware.

https://blog.lastpass.com/posts/attack-targeting-macs-via-github-pages

Oracle Scheduler Ransomware

Ransomware has been discovered that gained access to systems via an exposed Oracle Database Scheduler service.

https://labs.yarix.com/2025/09/elons-proxima-black-shadow-related-ransomware-attack-via-oracle-dbs-external-jobs/
Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation

SANS Stormcast Tuesday, September 23rd, 2025: Ivanti EPMM Exploit; GitHub Impersonation

Dr. Johannes B. Ullrich