CISA Alerts on RESURGE Malware Exploiting Ivanti Connect Secure Zero-Days
ID: 92e16368-6c43-54cd-9935-50b91bf8b738
STIX ID: report--92e16368-6c43-54cd-9935-50b91bf8b738
Feed Name: GBHackers
Threat Score
**CISA Malware Analysis Report (RESURGE):** CISA documents a new malware family, RESURGE, actively exploiting the Ivanti Connect Secure CVE-2025-0282 zero-day to achieve persistent, stealthy access—modifying coreboot, dropping web shells, and enabling credential theft, account creation, password resets and privilege escalation—and provides YARA/SIGMA detection rules plus remediation guidance (factory resets, credential resets, and Ivanti recovery steps).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
