Volt Typhoon suspected of exploiting Versa SD-WAN bug since June
ID: 7d7d0c02-e809-5389-b270-15a37f02c50e
STIX ID: report--7d7d0c02-e809-5389-b270-15a37f02c50e
Feed Name: The Register (Security)
Threat Score
A Beijing-backed APT group tracked as Volt Typhoon exploited a zero-day in Versa Director (CVE-2024-39717) to upload a modular credential‑harvesting web shell (VersaMem) against MSP/ISP customers via exposed management ports, enabling access to downstream networks; the exploitation was observed in the wild across multiple victims, CISA added the CVE to its KEV catalog, and Versa has released a patch and hardening guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
