WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts (TLP:CLEAR) CISA Releases Update to its Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) CISA Releases Update to its Malware Analysis Report on RESURGE Malware Associated with Ivanti Connect Secure

TLP:CLEAR

Author: Chase Snow

Created: Thursday, March 5, 2026 - 13:29

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: CISA recently released an update to its Malware Analysis Report (MAR) involving RESURGE malware, providing network defenders with deeper technical insights and enhanced tools to identify, mitigate, and respond to this threat. CISA’s updated analysis reveals that RESURGE can remain latent on systems until a remote actor attempts to connect to the compromised device. As such, CISA assesses that RESURGE may be dormant and undetected on Ivanti Connect Secure devices, continuing to pose an active threat.

The original MAR highlighted RESURGE’s capabilities to modify files, manipulate integrity checks, and deploy a web shell to the Ivanti boot disk. CISA’s updated analysis expands on RESURGE’s sophisticated network-level evasion and authentication techniques, including the use of advanced cryptographic methods and forged Transport Layer Security certificates to enable covert communications.

Analyst Note: RESURGE malware has been associated with the exploitation of a stack-based overflow vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateways (CVE-2025-0282). For utilities that use any of the Ivanti Connect Secure appliances mentioned, WaterISAC urges users and administrators to implement the “Mitigation Instructions for CVE-2025-0282”, as well as the listed actions outlined in CISA’s published alert.

Original Source: https://www.cisa.gov/news-events/analysis-reports/ar25-087a

Mitigation Recommendations:

  • CISA Mitigation Instructions for CVE-2025-0282
  • Security Advisory Ivanti Connect Secure, Policy Secure & ZTA Gateways (CVE-2025-0282, CVE-2025-0283)

Related WaterISAC PIRs: 6, 7, 7.1, 10, 12

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar