CyberzSOC

Publication detail
← Back to advisories & guidance

MAR-25993211-r1.v2 Ivanti Connect Secure (RESURGE) ↗ source

March 28, 2025 CISA Analysis Report

Summary

Malware Analysis Report 2026-02-26 This report is provided "as is" for informational purposes only. The Department of Homeland Security (DHS) does not provide any warranties of any kind regarding any information contained herein. The DHS does not endorse any commercial product or service referenced in this bulletin or otherwise. The Cybersecurity and Infrastructure Security Agency (CISA) updated this MAR on Feb. 26, 2026, to provide deeper technical insight into RESURGE to provide network defenders with enhanced understanding and tools to identify, mitigate, and respond to RESURGE. CISA’s updated analysis shows that RESURGE can remain latent on systems until a remote actor attempts to connect to the compromised device. Because of this, CISA assesses that RESURGE may be dormant and undetected to identify RESURGE samples and to implement the actions in CISA Mitigation Instructions for CVE-2025-0282 and Alert CISA Releases Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-0282 9.0 Critical Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.