Ivanti’s Invasion: CISA Sounds Alarm on RESURGE Malware Mayhem
CISA warns of RESURGE malware exploiting an Ivanti flaw, CVE-2025-0282. This sneaky malware acts like a digital Swiss Army knife, with functions ranging from rootkit to tunneler. It even creates web shells to keep its virtual ninja-like presence undetected. Just when you thought your systems were safe, RESURGE is here to crash the party.

Hot Take:
Looks like RESURGE is back from its villainous vacation, and it’s hungry for Ivanti appliances! This malware doesn’t just sneak into your system; it brings its own toolkit for a full-blown cyber party. Batten down the hatches, because RESURGE is ready to turn your security into Swiss cheese—complete with exploitation holes.
Key Points:
- CISA warns about the new malware, RESURGE, targeting vulnerabilities in Ivanti Connect Secure (ICS) appliances.
- RESURGE is an advanced malware that creates web shells, bypasses integrity checks, and modifies files.
- The vulnerability, CVE-2025-0282, allows remote code execution, while CVE-2025-0283 enables privilege escalation.
- Ivanti has issued updates to address these critical and high-severity vulnerabilities.
- RESURGE also includes a variant of SPAWNSLOTH for log tampering, making detection more challenging.
Already a member? Log in here