Volt Typhoon suspected of exploiting Versa SD-WAN bug since June

August 27, 2024 at 01:38PM China’s Volt Typhoon exploited a critical bug affecting Versa’s SD-WAN customers using Versa Director, planting custom web shells to harvest credentials on networks. Lumen Technologies linked this to the new malware, VersaMem. Versa has issued a patch and recommends customers to upgrade, but the vulnerability was already exploited, attributed to … Read more

Chinese Volt Typhoon Exploits Versa Director Flaw, Targets U.S. and Global IT Sectors

August 27, 2024 at 10:33AM Volt Typhoon, a China-based cyber espionage group, has been linked with exploiting a high-severity security flaw in Versa Director. The attacks targeted U.S. and non-U.S. victims in ISP, MSP, and IT sectors. The flaw allows malicious file uploads, potentially leading to large-scale supply chain attacks. Recommendations include security mitigations and … Read more

Chinese Volt Typhoon hackers exploited Versa zero-day to breach ISPs, MSPs

August 27, 2024 at 10:05AM Chinese hacking group Volt Typhoon exploited a zero-day vulnerability in Versa Director to upload a destructive webshell, allowing them to steal credentials and breach corporate networks. Versa has released an advisory outlining impacted versions and the recommended upgrade to fix the issue. Lumen’s Black Lotus Labs identified the exploit and … Read more

CISA Urges Federal Agencies to Patch Versa Director Vulnerability by September

August 24, 2024 at 03:42AM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a medium-severity vulnerability, CVE-2024-39717, impacting Versa Director to its Known Exploited Vulnerabilities catalog. Threat actors could upload a malicious file through the “Change Favicon” feature. Agencies are advised to apply vendor-provided fixes by September 13, 2024. CISA also highlighted other … Read more