Cisa
CISA Issues Update on RESURGE Malware Targeting Ivanti Devices
First seen 27 Feb 2026, 16:12 UTC
•



+6
•42.4
Export
Article Content
Browse articles
CISA has released updated findings on RESURGE, a malware implant exploiting CVE-2025-0282 to compromise Ivanti Connect Secure devices. This malware can remain undetected and utilize advanced evasion techniques for covert communication with attackers. The report builds on previous findings from March 2025 regarding RESURGE's capabilities.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2025-01-08
CVE-2025-0282 published and added to CISA KEV
2025-01-10
First public PoC for CVE-2025-0282
2025-03-28
CISA first documented RESURGE malware
2026-02-27
CISA released updated analysis on RESURGE malware
More articles in this cluster
Continue Reading
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
Chinese APT VerdantBamboo Exploits Brickstorm Malware for Long-term Network Access
VerdantBamboo's 18-Month Cyber Campaign Targets Managed Service Providers
Belgian State Security and Organizations Targeted by Cyberattacks