Connect with us

Tech

National CERT Warns of Active Attacks on Ivanti Mobile Systems

Published

on



Pakistan’s National Computer Emergency Response Team has issued a high-severity advisory warning of active exploitation of critical zero-day vulnerabilities affecting on-premises systems of Ivanti Endpoint Manager Mobile.

According to the advisory, the vulnerabilities allow attackers to remotely execute malicious code without authentication, giving them full control over affected systems. Ivanti has confirmed the flaws, while one of the vulnerabilities has also been added to the Known Exploited Vulnerabilities catalogue maintained by the Cybersecurity and Infrastructure Security Agency, confirming real world exploitation.

National CERT said the flaws carry a critical CVSS score of 9.8 and pose serious risks to confidentiality, integrity and system availability. Successful exploitation could allow attackers to access sensitive mobile device data, disrupt mobile management operations and potentially pivot into wider enterprise or government networks.

The advisory stated that the affected products include Ivanti Endpoint Manager Mobile on premises appliances across versions 12.5.0.0 through 12.7.0.0 and earlier releases. Other Ivanti products, including Ivanti Neurons for MDM, Ivanti Endpoint Manager and Ivanti Sentry, are not impacted.

According to National CERT, the vulnerabilities stem from improper input handling that enables code injection. The exploits are described as weaponized, with a high risk of attackers installing persistent backdoors on compromised systems.

Indicators of compromise highlighted in the advisory include suspicious web requests, unexpected command execution, unauthorized administrator account creation, changes to security policies and the presence of unknown scripts or binaries on the appliance.

Internet facing Ivanti EPMM systems were identified as being at the highest risk, particularly within government departments, critical infrastructure operators and organizations managing sensitive or regulated mobile data.

National CERT has directed all affected organizations to immediately apply Ivanti’s emergency RPM patches across all systems, including high availability deployments. The advisory stressed that patching is mandatory and the only complete remediation available.

While temporary measures such as network isolation, firewall restrictions and enhanced monitoring can reduce exposure, the advisory warned that organizations should assume compromise if systems were exposed and left unpatched.

National CERT also advised affected entities to conduct forensic audits, restrict unnecessary external access and activate incident response plans to prevent long term operational, regulatory and security impacts.





Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

NextSense Smartbuds Wireless EEG Earbuds With Brain-Sensing Tech For A Better Night’s Sleep

Published

on



The new NextSense Smartbuds are designed to close the gap between devices that passively track sleep and a device that actively intervenes for a better night’s sleep.



Source link

Continue Reading

Tech

JazzWorld Drives AI-Led Transformation Through Strategic Partnership with MoITT at Indus AI Week 2026

Published

on



JazzWorld, Pakistan’s leading digital services company, has partnered with the Ministry of Information Technology and Telecommunication (MoITT) for Indus AI Week 2026. The partnership will support national AI capacity-building, public-sector pilots, and local language model development.

The collaboration places JazzWorld at the forefront of Pakistan’s evolving AI ecosystem, convening policymakers, industry leaders, technologists, and innovators to shape a shared vision for AI-driven economic growth, competitiveness, and institutional transformation. Indus AI Week serves as a strategic forum to align national priorities with next-generation technologies capable of delivering measurable impact across sectors.

Aamir Ibrahim, Chief Executive Officer of JazzWorld, during a panel titled “Expert Led Strategic Dialogue: Designing AI Native Government” stated “AI is a multiplier, not a buzzword. Pakistan’s opportunity is to move from being an AI taker to an AI maker, and that requires execution, not just rhetoric. At JazzWorld, we are embedding AI into everyday decision-making, productivity, and customer experience, backed by pragmatic business cases, strong governance, and relevant upskilling. With our renewed focus and the appointment of a Chief AI Officer, we are moving decisively from experimentation to scale and setting the pace for Pakistan’s AIled future.”

Aamer Ejaz, Chief Artificial Intelligence Officer at JazzWorld, speaking during a fireside chat titled “Building Competitive AI Ecosystems without Losing Sovereignty,” added: “In a globally connected AI economy, sovereignty is about strategic choices, not isolation. You can be sovereign where it matters through the right infrastructure, policy frameworks, and data governance. AI must be driven by real use cases, real customers, and real value. At JazzWorld, our focus is on building a responsible, commercially viable AI ecosystem that remains open to global innovation while protecting local data, language, and context.”

Fatima Akhtar, Vice President Communications and ESG at JazzWorld, underscored the importance of responsible AI deployment and eliminating digital divides. “Language plays a pivotal role in bridging the digital usage gap identified by the GSMA—one in which women are disproportionately represented. Large Language Models can be a powerful enabler in overcoming this barrier, ensuring women’s meaningful inclusion in the digital economy.”

The event reflected JazzWorld’s broader ambition to build a comprehensive AI ecosystem spanning platforms, talent, governance, partnerships, and innovation pipelines — accelerating Pakistan’s transition toward a high-value, AI-driven digital economy.

During the event, JazzWorld showcased the depth of its operational AI capabilities across consumer and enterprise platforms, financial services, cloud infrastructure, digital ecosystems, and next-generation applications through its platforms like JazzCash, Tamasha, ROX, SIMOSA, and the chatbot SIA. The showcase demonstrated how AI is being embedded across multiple segments to enhance decision-making, personalization at scale, operational efficiency, and new value creation.

As Pakistan’s leading digital services company, JazzWorld reaffirmed its strategic focus on embedding AI as a foundational layer across all platforms and services, enabling smarter systems, scalable innovation, and sustained digital growth.





Source link

Continue Reading

Tech

Meta Quest 4 VR Headset Candidate Design Surfaces

Published

on



Published rendered that claimed to be based off prototype headsets point to what the Meta Quest 4 or lightweight alternative headset could actually look like.



Source link

Continue Reading

Trending