Find notable cyber news and cases, enriched with sources, timelines, and signals.

RESURGE malware analysis update adds stealth, TLS, and C2 findings on Ivanti Connect Secure

Technical Analysis
First reported
Last updated
Happening score
H score 27
2 unique sources, 2 articles

Summary

Hide ▲

New technical findings on RESURGE sharpen detection of a stealthy implant that can hide on Ivanti Connect Secure devices and enable covert SSH-based command-and-control. The update matters because the malware can remain dormant, evade routine monitoring, and use forged TLS certificates and other network-level tricks to communicate. Defenders are being directed to use IOCs, detection signatures, and CVE-2025-0282 mitigations to identify or contain affected systems.

Related Happenings

CISA-led joint advisory on Russian router targeting

Public Sector Action
H score32 First: 14.07.2026 15:00 Last: 14.07.2026 15:00 Sources 1

About this happening: CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...

CISA recommends continuous secrets scanning and stronger key management after GitHub leak

Defensive Guidance
H score26 First: 13.07.2026 18:03 Last: 13.07.2026 18:03 Sources 1

About this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...

Ivanti EPMM patch release for CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821

Security Patch Release
H score66 First: 07.05.2026 18:20 Last: 07.05.2026 18:20 Sources 1

About this happening: Ivanti released a security update for on-prem Endpoint Manager Mobile (EPMM) covering CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821. The patch addresses high-seve...

Latest development: 07.05.2026 20:55

Ivanti released fixes for CVE-2026-5786, CVE-2026-5787, CVE-2026-5788, and CVE-2026-7821 in Endpoint Manager Mobile (EPMM). The updates apply only to on-prem EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1, and Ivanti said the issues are not present in Ivanti Neurons for MDM, Ivanti EPM, Ivanti Sentry, or other Ivanti products.

BPFDoor Linux backdoor with HTTPS-hidden trigger packets

Malware Activity
H score23 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A newly disclosed BPFDoor variant is hiding trigger packets inside HTTPS traffic and using ICMP between infected hosts, making the Linux backdoor harder to detect...

Ivanti Connect Secure zero-day exploitation (CVE-2025-0282)

Vulnerability
H score33 First: 27.02.2026 17:57 Last: 27.02.2026 17:57 Sources 1

How related: According to researchers at incident response company Mandiant, the critical CVE-2025-0282 vulnerability was exploited as a zero-day since mid-December 2024 by a threat actor linked to China, tracked internally as UNC5221.

About this happening: CVE-2025-0282 in Ivanti Connect Secure was exploited as a zero-day starting in mid-December 2024, creating a breach path for affected appliances. The exploitation...

Timeline

  1. 26.02.2026 02:00 2 articles · 4mo ago

    Updated RESURGE Malware Analysis and Defender Guidance

    Technical Analysis Update

    CISA released an updated Malware Analysis Report on RESURGE that adds network-level evasion and authentication techniques, advanced cryptographic methods, and forged TLS certificates, while warning that the implant may remain dormant and undetected on Ivanti Connect Secure devices and directing defenders to use IOCs, detection signatures, and mitigation guidance for CVE-2025-0282.

    Show sources