Which vendor is going to declare a happy little vulnerability this week rather than a zero day?

We have a winner already - CVE-2023-35078, zero day in #MobileIron aka Ivanti Endpoint Manager Mobile

Exploitation in the wild. #threatintel
https://forums.ivanti.com/s/article/KB-Remote-unauthenticated-API-access-vulnerability-CVE-2023-35078

⚠️ Regarding the #MobileIron vulnerability ⚠️

Patches are out for 11.8.1.1, 11.9.1.1 and 11.10.0.2. It also applies to unsupported and EOL versions.

It's a serious zero day vulnerability which is very easy to exploit, where Ivanti are trying to hide it for some reason - this will get mass internet swept. I'd strongly recommend upgrading, and if you can’t get off EOL, switch off the appliance.

Heise have picked up on the #MobileIron zero day. It's under active exploitation, Ivanti have put security information behind a paywall portal and hidden exploitation information behind a non-disclosure agreement.

Ivanti are also a security vendor.

cc @wdormann https://www.heise.de/news/Ivanti-schliesst-Zero-Day-Luecke-in-MobileIron-9225583.html

Ivanti schließt Zero-Day-Lücke in MobileIron

Ein Update soll Angriffe auf das Mobile Device Management mit MobileIron verhindern.

heise online
What is this nonsense. They have a public security blog.. that they’re not using as soon as they have a security issue in their own back garden.
Ivanti argue they are “practicing responsible disclosure protocols” by trying to hide a zero day in their own product, MobileIron, and lock technical details behind non-disclosure agreements to avoid people understanding the severity of their fail. https://therecord.media/ivanti-urges-customers-to-apply-patch
Ivanti urges customers to apply patch for exploited MobileIron vulnerability

The IT giant Ivanti is urging customers to apply a patch for a vulnerability in a product used by dozens of governments around the world.

@GossiTheDog
Briefly looked at MobileIron for a MDM solution some years ago. For some reason we went with something else.
So glad we did, neverending pwnage of that thing ever since . 😳