CISA Warns of RESURGE Malware Exploiting 0-Days to Breach Ivanti Connect Secure Devices
ID: 0d956db4-9c3d-5155-87cf-bc7775bfe31f
STIX ID: report--0d956db4-9c3d-5155-87cf-bc7775bfe31f
Feed Name: cybersecurityNews.com
**Executive Summary:** A newly discovered malware variant called RESURGE is actively exploiting a critical Ivanti Connect Secure zero-day (CVE-2025-0282) to gain persistent, stealthy control of VPN gateway devices; the malware combines rootkit/bootkit persistence, credential harvesting, web shells, and log-tampering (SPAWNSLOTH) to maintain long-term access and evade detection, prompting a CISA warning and recommendations including factory resets, credential resets, and isolation of affected devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
