Desk live·
ForensicPost
Cloud/Exploitation/File 23-0724

Ivanti Zero-Day Breached 12 Norwegian Ministries; Four Kept off the Platform Escaped

A CVSS 10.0 authentication bypass in Ivanti Endpoint Manager Mobile was used against twelve Norwegian government ministries, exploited since at least April. The Prime Minister’s office, Defence, Justice and Foreign Affairs were not on that platform.

Constructed geometry · not a chart of case data
JurisdictionNorwayOslothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetNorwegian government ministries
ActorUnattributed
S. Rosler12 min readConfidence: high3 sources reviewed

On 24 July 2023 Norwegian authorities disclosed that twelve government ministries had been affected by exploitation of CVE-2023-35078, a zero-day in Ivanti Endpoint Manager Mobile. The flaw is an authentication bypass permitting unauthenticated remote API access, carrying a CVSS score of 10.0, and allows retrieval of user data such as names and phone numbers and modification of the server.

Reporting placed exploitation from at least April 2023, and a second zero-day was subsequently reported used in the same activity. The affected ministries shared an ICT platform operated by the government services agency; the Office of the Prime Minister, the Ministry of Defence, the Ministry of Justice and Public Security and the Ministry of Foreign Affairs were not on it.

The Exclusion List Is The Finding

We have argued at 26-0704 that a shared platform concentrates risk across everyone on it, and at 23-0818b that isolation is the control which quietly does the work. Those arguments are usually made from the damage.

Here the counterfactual is legible. Four ministries were judged sensitive enough to keep separate, and those four are exactly the four that were not affected. The judgement was made years earlier, for reasons of classification rather than resilience, and it functioned as a security control anyway.

Three Months Before Anyone Knew

Exploitation from April and disclosure in July means a quarter of a year in which a maximum-severity flaw was being used against a government and nobody outside the operation knew it existed.

We have recorded the same interval at 22-0527, where a flaw was reported to a vendor six weeks before it became public, and at 23-1010b. What distinguishes a zero-day is not the technical quality but the silence, and the silence is what we keep finding was the expensive part.

The Product Manages The Phones

Endpoint management software exists to control an organisation’s mobile devices — to enrol them, configure them and push policy. It therefore holds a directory of who works there and what they carry, and by design has authority over those devices.

We have recorded the same profile at 22-0118, where a self-service password tool was the entry, and at 23-0413. The systems that administer other systems are the highest-value targets in any estate, and they are consistently the least examined, because they are infrastructure rather than applications.

How we reported this

Compiled from contemporaneous reporting and vendor advisories, listed below. The observation that those four were excluded for classification reasons rather than resilience planning is this desk’s reading of the reported arrangement and is presented as such. No actor is named: reporting described an advanced persistent threat without public attribution to a state. No indicators are reproduced. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Ivanti rushes to patch zero-day used to breach Norway’s governmentTechCrunch
  2. Hackers exploited Ivanti zero-day to breach Norway’s governmentThe Record
  3. Ivanti Zero-Day Exploited by APT Since at Least April in Norwegian Government AttackSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary