logo

CISA Warns of RESURGE Malware Exploiting 0-Days to Breach Ivanti Connect Secure Devices

ID: 0d956db4-9c3d-5155-87cf-bc7775bfe31f

STIX ID: report--0d956db4-9c3d-5155-87cf-bc7775bfe31f

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive Summary:** A newly discovered malware variant called RESURGE is actively exploiting a critical Ivanti Connect Secure zero-day (CVE-2025-0282) to gain persistent, stealthy control of VPN gateway devices; the malware combines rootkit/bootkit persistence, credential harvesting, web shells, and log-tampering (SPAWNSLOTH) to maintain long-term access and evade detection, prompting a CISA warning and recommendations including factory resets, credential resets, and isolation of affected devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.