A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://veriti.ai/blog/vulnerable-villain-when-hackers-get-hacked/
https://www.crowdstrike.com/blog/anatomy-of-alpha-spider-ransomware/