logo

CISA Alerts on RESURGE Malware Exploiting Ivanti Connect Secure Zero-Days

ID: 92e16368-6c43-54cd-9935-50b91bf8b738

STIX ID: report--92e16368-6c43-54cd-9935-50b91bf8b738

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**CISA Malware Analysis Report (RESURGE):** CISA documents a new malware family, RESURGE, actively exploiting the Ivanti Connect Secure CVE-2025-0282 zero-day to achieve persistent, stealthy access—modifying coreboot, dropping web shells, and enabling credential theft, account creation, password resets and privilege escalation—and provides YARA/SIGMA detection rules plus remediation guidance (factory resets, credential resets, and Ivanti recovery steps).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.