cognitive cybersecurity intelligence

News and Analysis

Search

RESURGE Malware Exploits Ivanti Flaw with Rootkit and Web Shell Features

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed a new malware named RESURGE. Deployed in exploiting Ivanti Connect Secure appliances’ patched security flaw, RESURGE contains elements of the SPAWNCHIMERA malware but also distinctive commands. Linked to CVE-2025-0282 vulnerability affecting Ivanti versions, Google-owned Mandiant confirmed it was weaponized with UNC5337, a Chinese espionage group, using SPAWN malware. The RESURGE evolution enables insertion into files, web shell creations, and privileges escalation. CISA advises organizations to update to the latest Ivanti versions and reset all account credentials.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

What are business logic vulnerabilities?

Business logic vulnerabilities in software allow attackers to exploit flaws in design, enabling them to circumvent security measures and manipulate pricing, authentication, and other key