Belgian State Security breached via Ivanti: supplier risk in the spotlight
Between May 2025 and spring 2026, attackers exploited two critical flaws (CVSS 9.8) in Ivanti EPMM, a mobile device management platform, to steal names, mobile numbers and email addresses of Belgian State Security staff; the same campaign also hit the European Commission and several Dutch institutions. No classified data leaked, but the incident shows that a single exposed management tool is enough to get in. Mixity maps your internet-facing systems, monitors critical patches and shortens your time to update.
Read article →





