logo

Volt Typhoon suspected of exploiting Versa SD-WAN bug since June

ID: 7d7d0c02-e809-5389-b270-15a37f02c50e

STIX ID: report--7d7d0c02-e809-5389-b270-15a37f02c50e

Feed Name: The Register (Security)

Threat Score
92/100

Date Published: 2024-08-27

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A Beijing-backed APT group tracked as Volt Typhoon exploited a zero-day in Versa Director (CVE-2024-39717) to upload a modular credential‑harvesting web shell (VersaMem) against MSP/ISP customers via exposed management ports, enabling access to downstream networks; the exploitation was observed in the wild across multiple victims, CISA added the CVE to its KEV catalog, and Versa has released a patch and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.