Latest Ivanti bug, paired with malware, earns an alert from CISA
ID: b630dbd4-d1e7-54d6-a9ec-ba6167c0ffd0
STIX ID: report--b630dbd4-d1e7-54d6-a9ec-ba6167c0ffd0
Feed Name: The Record from Recorded Future News
Threat Score
**Executive Summary:** CISA reports that suspected China-linked espionage actors have actively exploited Ivanti CVE-2025-0282 to deploy Resurge (aka Spawn) malware on Connect Secure and related appliances; the malware enables persistence, credential theft, account creation, privilege escalation, log tampering, and bypass of Ivanti integrity checks, prompting agency guidance to factory-reset devices and rotate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
