New 0-Day Attacks Linked to China’s ‘Volt Typhoon’
ID: addaf4a4-d1e9-59c4-a054-32c9071dfd5b
STIX ID: report--addaf4a4-d1e9-59c4-a054-32c9071dfd5b
Feed Name: Krebs on Security
**Versa Director zero‑day exploited by suspected Volt Typhoon:** Researchers from Black Lotus Labs observed in‑the‑wild exploitation of CVE-2024-39717 allowing arbitrary file upload and web-based backdoors on multiple ISP/MSP systems beginning in June 2024. The activity is attributed with medium confidence to the Chinese APT known as Volt Typhoon, which targets critical communications infrastructure and pre-positions for lateral movement; Versa issued a patch (Versa Director 22.1.4+) and urged customers to harden exposed management ports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
