Frequency
17
occurrences
First Seen
June 10, 2026
Last Seen
September 9, 2026
Related Threat Clusters
-
ChocoPoC Malware Targets Cybersecurity Researchers via Trojanized GitHub Exploits
A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…
10 articles · Updated July 1, 2026 -
Ivanti Sentry Vulnerabilities Allow Remote Code Execution and Admin Access
Ivanti has patched two critical vulnerabilities in its Sentry secure mobile gateway, formerly MobileIron Sentry. The first, CVE-2026-10520, is an OS command injection flaw allowing remote code execution with root…
38 articles · Updated June 10, 2026 -
Ivanti Discloses Critical Authentication Bypass Vulnerabilities
On September 8, 2026, Ivanti disclosed multiple vulnerabilities affecting its Endpoint Manager Mobile (EPMM), Neurons for ITSM, and Sentry products. Two critical CVEs, CVE-2026-83527 and CVE-2026-18851, allow for…
3 articles · Updated September 9, 2026
Recent Intelligence Reports
- Ivanti's September Patch Day Drops Two Authentication Bypasses — Tech.Yahoo · September 9, 2026
- Ivanti's September Patch Day Drops Two Authentication Bypasses — Forkast.News · September 9, 2026
- Dont Eat The Chocopocs How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits — www.sekoia.com · July 2, 2026
- ChocoPoc malware delivered via trojanized exploits on GitHub — Bleepingcomputer · July 1, 2026
- New ChocoPoC malware targets researchers via trojanized PoC exploits — Bleepingcomputer · July 1, 2026
- ChocoPoc malware delivered via trojanized exploits on GitHub — Bleepingcomputer · July 1, 2026
- Max severity Ivanti Sentry vulnerability now exploited in attacks — Bleepingcomputer · June 11, 2026
- Ivanti patches critical Sentry flaws that lead to full device takeover — Csoonline · June 10, 2026