RESURGE Alert: New Malware Variant Exploiting Ivanti Vulnerability – Stay Secure!

CISA’s Malware Analysis Report introduces RESURGE, a new malware variant with impressive reboot survival skills and unique behavior-altering commands. It’s exploiting CVE-2025-0282 in Ivanti Connect Secure appliances. Stay ahead with detection signatures and avoid becoming the unwitting star of a cyber thriller featuring stack-based buffer overflow vulnerabilities!

Pro Dashboard

Hot Take:

CISA’s latest malware revelation, RESURGE, is the kind of cyber villain that doesn’t just crash the party—it sticks around to eat all the chips, and then changes the music playlist to something only it enjoys. This malware is like a bad houseguest that’s not only hard to kick out, but also redecorates your living room when you’re not looking!

Key Points:

  • RESURGE is a new malware variant identified by CISA, with traits from the notorious SPAWNCHIMERA.
  • It has a knack for surviving system reboots, ensuring its presence is felt long after the initial breach.
  • RESURGE exploits the CVE-2025-0282 vulnerability found in Ivanti Connect Secure appliances.
  • This vulnerability was added to CISA’s Known Exploited Vulnerabilities Catalog on January 8, 2025.
  • Detection tools and rules for RESURGE are available, including YARA rules and a SIGMA YAML file.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?