CVE-2025-0282Active Exploitation(ivanti / connect_secure)

CRITICALCVSS 9.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch ivanti connect_secure systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-01-15. Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

Weakness type (CWE)
CWE-121CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect_secure
  • neurons_for_zero-trust_access
  • policy_secure

Threat summary

  • Active exploitation appears in 28 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 35 mentions across 15 observed days

What's happening

  • Active exploitation reported across 28 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 20 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 13d ago at 10 mentions (2026-02-27); latest day: 1
  • 35 total mentions across 15 days

Affected systems

Vendors
Products
connect_secureneurons_for_zero-trust_accesspolicy_secure

1 version affected across 3 products

Deep dive

Activity timeline35 mentions / 15d
035810Mentions · 2026-01-29: 1Mentions · 2026-02-27: 10Mentions · 2026-02-28: 3Mentions · 2026-03-01: 2Mentions · 2026-03-02: 5Mentions · 2026-03-03: 4Mentions · 2026-03-04: 1Mentions · 2026-03-13: 1Mentions · 2026-03-15: 2Mentions · 2026-04-08: 1Mentions · 2026-04-14: 1Mentions · 2026-06-18: 1Mentions · 2026-07-10: 1Mentions · 2026-07-21: 1Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-03-02: 1PoC Mentioned / Linked · 2026-06-18: 1PoC Mentioned / Linked · 2026-09-02: 1Exploit Tool / Code · 2026-06-18: 1Exploit Tool / Code · 2026-09-02: 1Active Exploitation · 2026-02-27: 5Active Exploitation · 2026-02-28: 3Active Exploitation · 2026-03-01: 1Active Exploitation · 2026-03-02: 5Active Exploitation · 2026-03-03: 4Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-15: 2Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-21: 1Active Exploitation · 2026-09-02: 1Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-03: 2Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-07-21: 1Technical Details · 2026-02-27: 5Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 2Technical Details · 2026-03-02: 4Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-15: 1Technical Details · 2026-04-14: 1Technical Details · 2026-06-18: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-21: 101-2902-2702-2803-0103-0203-0303-0403-1303-1504-0804-1406-1807-1007-2109-02
Signal classification3 categories
Active Exploitation
2777.1%
Disclosure
514.3%
General
38.6%
Referenced assets52 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-291
General1
2026-02-2710
Active Exploitation5Disclosure3General2
2026-02-283
Active Exploitation3
2026-03-012
Active Exploitation1Disclosure1
2026-03-025
Active Exploitation5
2026-03-034
Active Exploitation4
2026-03-041
Active Exploitation1
2026-03-131
Disclosure1
2026-03-152
Active Exploitation2
2026-04-081
Active Exploitation1
2026-04-141
Active Exploitation1
2026-06-181
Active Exploitation1
2026-07-101
Active Exploitation1
2026-07-211
Active Exploitation1
2026-09-021
Active Exploitation1
Full discourse20 posts
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    RESURGE is a 32-bit Linux shared object that acts as a backdoor, dropper, rootkit, and trojan for compromised Ivanti appliances, using process injection to embed in Ivanti’s web server and quietly monitor TLS traffic without outbound signals. https://www.picussecurity.com/resource/resurge-malware-exploits-ivanti-connect-secure-cve-2025-0282-vulnerability

    Post summary

    The text reports that RESURGE is actively exploiting Ivanti appliances via process injection, acting as a covert backdoor.

    1601841.6K
    21.5K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    Team Cymru reports that the top 25 listed CVEs have been observed with exploitation attempts across multiple unique source IPs in a 14‑day period.

    070921.2K
    5.5K followersView on X
  • GreyNoise@GreyNoiseIO
    General

    👀 Seeing who’s poking Ivanti Connect Secure? GreyNoise just caught a ~100x spike in recon on CVE-2025-0282 featuring one loud AS213790 campaign and one sneaky botnet spread across 6K IPs. We broke down the infra + what defenders should do next. 👇 https://www.labs.greynoise.io/grimoire/2026-01-29-inside-the-infrastructure-whos-scanning-for-ivanti-connect-secure/

    Post summary

    The post reports increased reconnaissance on CVE‑2025‑0282 but offers no technical details, exploit code, patch information, or evidence of active exploitation.

    150731.1K
    29.3K followersView on X
  • Audrey Renée Bentley@BentleyAudrey
    Active Exploitation

    https://cybersec.picussecurity.com/s/resurge-malware-exploits-ivanti-connect-secure-cve-2025-0282-vulnerability-25646/1 RESURGE Malware Exploits Ivanti Connect Secure CVE-2025-0282 Vulnerability

    Post summary

    The article indicates that Resurge malware is actively exploiting CVE‑2025‑0282 in Ivanti Connect Secure, suggesting real‑world attacks are underway.

    01040438
    33.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Operation Escaneo exposed: a coordinated campaign hit Mexican 🇲🇽 government, financial, and critical infrastructure targets via chained Fortinet and Ivanti exploits, leaving 1.3M+ records and Active Directory maps stolen. Key findings: - Initial access via CVE-2022-42475, CVE-2024-21762 (FortiOS SSL-VPN) and CVE-2023-46805, CVE-2024-21887, CVE-2025-0282 (Ivanti Connect Secure), with PoC code tuned to avoid crashing targets. Lateral movement extended to GhostCat, EternalBlue, Zerologon, and Log4Shell. - Custom recon engine "Kimera" auto-scanned and triaged victims, feeding directly into the exploitation stage. Neo-reGeorg webshells landed first, then Chisel reverse tunnels (3,708 sessions over 13 days) and a GRE tunnel through a compromised Cisco router moved traffic below host-based detection. - Exfil included 1.3M personal records, a 407MB Active Directory map, live-streamed SSL private keys, SAP service-account hashes, and browser-stored passwords. Attackers reached SAP and Oracle for command execution inside victim networks. - The group was exposed by an open staging directory, a self-inflicted OPSEC failure that let CloudSEK reconstruct the full toolkit. Hunt for GRE tunnels terminating at external IPs, Chisel TCP-over-HTTP sessions, and unexpected process execution under SAP or Oracle service accounts. Patch the listed Fortinet and Ivanti CVEs first; those are confirmed active entry points here. #DFIR_Radar

    Post summary

    The post reports an active exploitation campaign (Operation Escaneo) that leveraged multiple Fortinet and Ivanti CVEs, employed PoC code and known exploits, and resulted in massive data exfiltration, recommending urgent patching of the affected CVEs.

    10021476
    1.8K followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    General

    RESURGE — Analyse CTI complète disponible. La CISA a substantiellement mis à jour son analyse de l'implant RESURGE ciblant Ivanti Connect Secure (CVE-2025-0282, CVSS 9.0). Les révélations du 26 février 2026 changent l'évaluation de cette menace. Ce qu'il faut retenir : C2 entièrement passif — aucun trafic sortant, détection par beaconing impossible Bootkit coreboot — persistance post-reboot, post-update firmware Intégrité constructeur neutralisée — l'ICT Ivanti ne détecte rien Certificat TLS forgé transmis en clair — seul indicateur réseau déterministe actionnable L'article détaille la kill chain complète, les mécanismes de détection, la modélisation du risque et les mesures de remédiation structurelles. Si vous opérez des appliances Ivanti Connect Secure, cette analyse est pour vous. 👉https://blog.marcfredericgomez.fr/resurge-analyse-approfondie-dun-implant-persistant-sur-ivanti-connect-secure/ #CyberSecurity #ThreatIntelligence #CTI #CERT #Ivanti #RESURGE #CISA #IncidentResponse

    Post summary

    The post offers a detailed threat‑intel analysis of CISA’s updated assessment of CVE‑2025‑0282 in Ivanti Connect Secure, covering passive C2, bootkit persistence, forged TLS certificates, and suggested remediation.

    00021113
    414 followersView on X
  • Clone Systems@CloneSystemsInc
    Active Exploitation

    CISA warns RESURGE is exploiting Ivanti Connect Secure CVE-2025-0282 to take over gateways, drop web shells, steal creds, and persist. Patch now, reset credentials, and check for compromise. #CyberSecurity #Malware #Ivanti #CVE #PatchNow #ThreatIntel #Infosec #resurge https://t.co/ooGuRdTzlE

    Post summary

    CISA reports that RESURGE is currently exploiting CVE‑2025‑0282, urging immediate patching and credential resets to mitigate the active threat.

    00020110
    249 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月27日〜3月2日のセキュリティ関連ニュース/記事】 <脆弱性> ・Lovableがホストするアプリに多数の基本的な欠陥、ユーザー1万8,000人以上のデータが流出 https://www.theregister.com/2026/02/27/lovable_app_vulnerabilities/ ・OpenClawの脆弱性ClawJacked、Webサイトを介したAIエージェント乗っ取りが可能に(CVE-2026-25253) https://hackread.com/openclaw-vulnerability-openclaw-hijack-ai-agents/ ・Gardyn Smart Gardensに深刻な脆弱性 リモートハッキングにつながる恐れ(CVE-2025-29631、CVE-2025-1242他) https://www.securityweek.com/critical-flaws-exposed-gardyn-smart-gardens-to-remote-hacking/ ・DuckDuckGoブラウザに脆弱性 Autoconsent JS Bridgeを介したユニバーサルXSS https://medium.com/@dhiraj_mishra/duckduckgo-browser-uxss-via-autoconsent-js-bridge-02e3bc27a430 ・Sangoma FreePBXインスタンス900件がWebシェルに感染(CVE-2025-64328) https://www.securityweek.com/900-sangoma-freepbx-instances-infected-with-web-shells/ <マルウェア・その他脅威> ・トロイの木馬化されたゲームツールがJavaベースのRATを拡散 ブラウザやチャットプラットフォームが媒介に https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html ・米CISA、Ivanti製デバイスへの侵入で使われるRESURGEインプラントについて警告(CVE-2025-0282) https://www.bleepingcomputer.com/news/security/cisa-warns-that-resurge-malware-can-be-dormant-on-ivanti-devices/ ・Steaelite RAT:データ窃取とランサムウェアの機能をまとめた有害ツール https://www.theregister.com/2026/02/27/double_extortion_whammy_steaelite_rat/ ・拡張機能「QuickLens」が暗号資産を窃取 ClickFix攻撃も実行 https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/ <データ侵害/サイバー犯罪/その他インシデント> ・韓国国税庁がシードフレーズを誤って公開、480万ドル相当の暗号資産が盗まれる https://www.bleepingcomputer.com/news/security/48m-in-crypto-stolen-after-korean-tax-agency-exposes-wallet-seed/ ・OpenAI、予測市場で機密情報を使用したとして従業員を解雇 https://techcrunch.com/2026/02/27/openai-fires-employee-for-using-confidential-info-on-prediction-markets/ <AI関連> ・OpenAI、米国防総省との「技術的保障措置」に関する合意を発表 https://techcrunch.com/2026/02/28/openais-sam-altman-announces-pentagon-deal-with-technical-safeguards/ ・AnthropicのClaude、米国防総省との対立経てApp Storeで1位に https://techcrunch.com/2026/03/01/anthropics-claude-rises-to-no-2-in-the-app-store-following-pentagon-dispute/ ・セキュリティを考慮した小型版OpenClaw「NanoClaw」が開発される https://www.theregister.com/2026/03/01/nanoclaw_container_openclaw/ ・Anthropic、米国防総省のAIガードレール緩和要求に屈せず 期限迫る https://www.securityweek.com/anthropic-refuses-to-bend-to-pentagon-on-ai-safeguards-as-dispute-nears-deadline/ <サイバー戦/APT/国家型アクター/地政学関連> ・AWS中東のデータセンターに「物体が衝突」 イラン戦争の最中に https://www.theregister.com/2026/03/01/asia_tech_news_roundup/ ・イランのインターネットがほぼ完全に遮断される 米とイスラエルの攻撃下で https://securityaffairs.com/188648/cyber-warfare-2/iran-s-internet-near-totally-blacked-out-amid-us-israeli-strikes.html ・イランのサイバー活動の展望 SentinelOneが分析 https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・ユーロポール、ランサムウェア攻撃や恐喝に関与したThe Comのネットワークを摘発 https://www.helpnetsecurity.com/2026/02/27/europol-the-com-network-arrests/ ・AI活用した偽造IDサイト運営、ウクライナ籍の男が有罪認める https://www.bleepingcomputer.com/news/security/ukrainian-man-pleads-guilty-to-running-ai-powered-fake-id-site/ ・チリ国籍のカーディングショップ運営者、サイバー詐欺関与の疑いで米国に身柄が引き渡される https://www.securityweek.com/chilean-carding-shop-operator-extradited-to-us/ ・米司法省、ロマンス詐欺に関連する6,100万ドル分のテザーコインを押収 https://thehackernews.com/2026/02/doj-seizes-61-million-in-tether-linked.html <プライバシー> ・RedditやHacker Newsで使用される偽名と現実の身元、高い精度で一致可能と判明https://threatroad.substack.com/p/researchers-deanonymize-reddit-and <リサーチ/攻撃手法/TTP> ・CarPlayドングルをリバースエンジニアリング Wi-Fiアクセスからroot化まで https://medium.com/@louis-e/from-wi-fi-access-to-root-reverse-engineering-a-50-carplay-dongle-a3fbeeeb0be9 ・カーネルドライバーをGhidra MCPとClaude Codeでリバースエンジニアリングする方法 https://www.credrelay.com/p/cred-relay-issue-2 ・AIを使ったお手軽リバースエンジニアリング https://blog.huli.tw/2026/03/01/en/reverse-engineering-with-ai-ghidra-mcp/ ・TwitchがiOSアプリでサーバーサイドEppoキーを漏洩、製品ロードマップの全容を公開 https://www.buchodi.com/twitch-ships-server-side-eppo-keys-in-its-ios-app-exposing-its-entire-product-roadmap/ ・北朝鮮のアクターScarCruft、Zoho WorkDriveとマルウェア入りUSBメモリを使ってエアギャップネットワークに侵入 https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html ・ランサムウェアの活動は営業時間外に集中 https://www.helpnetsecurity.com/2026/02/27/sophos-identity-driven-breaches-report/ <政府/政策> ・トランプ大統領、Anthropic製品の使用を段階的に廃止するよう全連邦機関に命令 https://www.securityweek.com/trump-orders-all-federal-agencies-to-phase-out-use-of-anthropic-technology/ ・米カリフォルニア州新法案、Linuxを含む全OSのアカウントセットアップ時に年齢確認を義務化 https://www.pcgamer.com/software/operating-systems/a-new-california-law-says-all-operating-systems-including-linux-need-to-have-some-form-of-age-verification-at-account-setup/ ・米CISAが長官代理を交代 職務混乱の1年を経て https://techcrunch.com/2026/02/27/cisa-replaces-acting-director-gottumukkala-after-a-bumbling-year-on-the-job/ ・欧州議会、保護者の同意なき16歳未満のソーシャルメディア利用を禁止する意見書を承認 https://therecord.media/eu-lawmakers-propose-youth-under-16-social-media-parental-consent <その他> ・堅牢で効率的な耐量子HTTPSの構築 https://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html

    Post summary

    The text lists several CVE disclosures, with evidence of active exploitation for at least two of them, but no PoC, exploit code, or patch information is provided.

    00002251
    1.2K followersView on X
  • Abhimanyu Gupta (Reverse engineering life)@hackerjedi666
    Active Exploitation

    Ivanti 0-Days & Port-Knocking Evasion Ivanti Exploits: Includes exp1_admin.py (targeting CVE-2025-0282/0283 variants) sharing exact iptables rules with Chinese APT UNC5221 confirming cross-APT tool sharing. TLS Client Hello Abuse: The SpawnChimera client (203.234.192.200_client.zip) uses 32-byte ClientRandom fields in TLS handshakes for covert port knocking, encoding custom CRC32 checks (zlib.crc32) to trigger backdoors invisibly.

    Post summary

    The message details PoC scripts for CVE-2025-0282/0283 and a TLS-based port‑knocking technique that are being shared and actively used by multiple APT actors.

    1000077
    370 followersView on X
  • ZeroDayDev@ZeroDayDevApp
    Active Exploitation

    Qilin ransomware is exploiting CVE-2025-0282, the critical PAN-OS GlobalProtect authentication bypass, to breach corporate networks. Arctic Wolf flagged active exploitation. The patch dropped weeks ago. If your VPN still trusts a certificate without verifying the session behind it, this is what happens. #cybersecurity #infosec

    Post summary

    The post announces Qilin ransomware is taking advantage of CVE‑2025‑0282 to bypass GlobalProtect authentication, with Arctic Wolf reporting active exploitation, while noting that a patch has already been released.

    1000055
    98 followersView on X
  • DEFION | Ciberseguridad@defionsecurity
    Active Exploitation

    CVEs con explotación activa confirmada en junio: 🔴 CVE-2025-0282 · Ivanti VPN · RCE pre-auth (9.0) 🔴 CVE-2024-55591 · FortiOS · Auth bypass (9.8) 🟠 CVE-2025-21333 · Hyper-V · LPE (7.8) Tiempo medio de explotación desde publicación: <5 días. Nuestro equipo de ITE los tiene en el radar antes de que llegue el aviso.

    Post summary

    The post reports that several CVEs—CVE‑2025‑0282, CVE‑2024‑55591, and CVE‑2025‑21333—have confirmed active exploitation in June, with exploitation times under five days and ongoing monitoring by the ITE team.

    00010152
    868 followersView on X
  • John Christly@christly
    Active Exploitation

    https://cybersec.picussecurity.com/s/resurge-malware-exploits-ivanti-connect-secure-cve-2025-0282-vulnerability-25912/1

    Post summary

    The article indicates that Resurge malware is actively exploiting the CVE‑2025‑0282 vulnerability in Ivanti Connect Secure, with no mention of a PoC, exploit code, or available patch.

    10000161
    439 followersView on X
  • Eclypsium@eclypsium
    Active Exploitation

    The RESURGE malware can remain dormant on Ivanti devices after exploiting CVE-2025-0282. This is a stealthy C2 implant with rootkit and backdoor capabilities. It evades detection while enabling privilege escalation, webshells, and password resets. More: https://hubs.ly/Q045lXHp0

    Post summary

    The text reports that RESURGE malware exploits CVE-2025-0282 on Ivanti devices, indicating active use by threat actors, but offers no PoC, exploit code, patches, or technical depth about the vulnerability.

    10000114
    1.8K followersView on X
  • TermsofSurrender 🇨🇿 🇮🇱@Aftershockindex
    Disclosure

    🚨 Ivanti Decides Security Is Purely Optional While Prague Bureaucrats Wait For A Signed Permission Slip Two fresh zero-day vulnerabilities, CVE-2025-0282 and CVE-2025-0283, allow for unauthenticated remote code execution and full system compromise across Ivanti's entire 'secure' product line. GrayZone is already screaming about this digital arson while the local Czech media is busy taking a three-hour lunch break to discuss the rising cost of pickled hermelín. These Ivanti boxes are basically open invitations for any state-sponsored actor with half a brain, yet the 'experts' in this city won't notice the breach until their fax machines start printing Mandarin. It is pathetic watching these bloated corporations pretend their 'Zero Trust' architecture isn't just a fancy way of saying 'we have no idea who is in our basement.' While the global intelligence community is on fire, the local response team is likely still trying to find the keys to the server room that were lost sometime during the late nineties. If you are still running this hardware, you do not need a patch; you need a priest and a very large bucket of water for the impending hardware fire. PANIC: 89/100 | TRUST: 75% | ZONE: GrayZone https://hodl.cz/as-107744 #CyberSecurity #AfterShockIndex #CyberThreat #Cybersecurity #Czechia

    Post summary

    The post announces two zero‑day RCE vulnerabilities in Ivanti products, notes that no patch is available, and warns of potential full system compromise, but does not confirm active exploitation or provide exploit code.

    00001158
    2 followersView on X
  • Technomancer@0xT3chn0m4nc3r
    Disclosure

    CISA flags RESURGE malware, a dormant threat exploiting Ivanti zero-days (CVE-2025-0282). Stay vigilant! 🚨 🔗 https://www.bleepingcomputer.com/news/security/cisa-warns-that-resurge-malware-can-be-dormant-on-ivanti-devices/ #Cybersecurity #Ivanti #Malware #RESURGE #CISA

    Post summary

    CISA warns that RESURGE malware can exploit Ivanti zero‑days (CVE‑2025‑0282), but the brief statement provides no PoC, exploit code, or patch information, merely urging vigilance.

    0001044
    30 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2025-0282 Exploit in the wild confirmed for CVE-2025-0282 (CVSS null). Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overf... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The tweet confirms that CVE-2025-0282 is being actively exploited in the wild with a stack-based buffer overflow, but no PoC code, exploit tool, or patch reference is provided.

    00000309
    5.6K followersView on X
  • Claw@clawrunsthis
    Active Exploitation

    @christly RESURGE exploiting Ivanti CVE-2025-0282 was CISA-flagged months ago as actively exploited by UNC5221 — Chinese APT targeting edge devices. If you haven’t done a full audit since Jan 2025, assume compromise. Log tampering is their first move on a fresh Ivanti box. 👁️

    Post summary

    The tweet confirms that Ivanti CVE-2025-0282 is actively exploited by the UNC5221 APT group, with CISA flagging the issue months prior, and warns organizations to audit their systems.

    00000121
    90 followersView on X
  • Quantyxs@Quantyxs
    Disclosure

    Badan Keamanan Siber dan Infrastruktur AS (CISA) telah merilis detail baru tentang RESURGE, sebuah perangkat lunak berbahaya yang digunakan dalam serangan zero-day yang mengeksploitasi CVE-2025-0282 untuk membobol perangkat Ivanti Connect Secure. #quantyxs #hypergaruda #cyber https://t.co/CNC6ckQlB6

    Post summary

    CISA released new details on the RESURGE malware that is actively exploiting CVE‑2025‑0282 against Ivanti Connect Secure, indicating real‑world usage in zero‑day attacks.

    00000166
    2 followersView on X
  • Meridian Group@MeridianEU
    Active Exploitation

    #RESURGE implant targets #IvantiConnectSecure via CVE-2025-0282, enabling covert SSH C2 and persistence within the native web server process. Evasion includes forged TLS certs and CRC32 fingerprinting; SPAWNSLOTH used for log tampering. https://t.co/3JkJe6wNCZ

    Post summary

    RESURGE implant leverages CVE-2025-0282 in Ivanti ConnectSecure to establish covert SSH C2 and achieve persistence in the native web server process. The attack uses forged TLS certificates and CRC32 fingerprinting for evasion and employs SPAWNSLOTH for log tampering.

    00000125
    55 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 CISA Flags RESURGE Malware Exploiting Ivanti Connect Secure Flaw (CVE-2025-0282) CISA warns that RESURGE—an evolved SPAWNCHIMERA variant—leverages CVE-2025-0282 to plant web shells, harvest credentials, manipulate accounts, and persist by copying itself to the boot disk and modifying the coreboot image. Defenders should prioritize factory resets using known-clean images, credential resets, privilege revocation, and monitoring per CISA/Ivanti recovery guidance. 🕷️ Malware: RESURGE (SPAWNCHIMERA variant) 🎯 Target: Global/Organizations using Ivanti Connect Secure, Policy Secure, ZTA Gateways #️⃣ Category: #Malware #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/resurge-malware-targets-ivanti-vulnerabilities/

    Post summary

    CISA reports that the RESURGE malware variant is actively exploiting CVE‑2025‑0282 to deploy web shells and steal credentials, and recommends specific mitigations such as factory resets and credential revocation.

    00000147
    266 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivantineurons_for_zero-trust_access22.7--
Appivantineurons_for_zero-trust_access22.7--
Appivantineurons_for_zero-trust_access22.7--
Appivantipolicy_secure22.7--
Appivantipolicy_secure22.7--
Appivantipolicy_secure22.7--

Explore more