China's Volt Typhoon Exploits Zero-Day in Versa's SD-WAN Director Servers
ID: fa6aaff1-b89e-5fc4-b366-3c0f3b573e98
STIX ID: report--fa6aaff1-b89e-5fc4-b366-3c0f3b573e98
Feed Name: Dark Reading
Threat Score
Volt Typhoon actors have been exploiting a zero-day (CVE-2024-39717) in Versa Director (pre-22.1.4) to upload a bespoke web shell, "VersaMem," that captures plaintext credentials and loads in-memory Java modules; exploitation has been active since at least June against managed service, ISP, and IT victims, prompting Versa patches, mitigation guidance, and CISA listing the flaw in its Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
