logo

Chinese Volt Typhoon hackers exploited Versa zero-day to breach ISPs, MSPs

ID: 3ee7277e-bc12-5252-97f4-775325d1cadc

STIX ID: report--3ee7277e-bc12-5252-97f4-775325d1cadc

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-08-27

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Volt Typhoon exploited a zero-day in Versa Director (CVE-2024-39717) by abusing the GUI custom icon upload feature to plant a Java web shell ('VersaMem') that steals credentials and can execute in-memory Java bytecode; Black Lotus Labs observed exploitation via compromised SOHO devices starting June 12, 2024. Affected Director versions include 21.2.3, 22.1.2, and 22.1.3; Versa released 22.1.4 as a fix and recommends upgrading, restricting HA ports (4566/4570), checking /var/versa/vnms/web/custom_logo and /tmp/.temp.data for artifacts, reviewing firewall/hardening guidance, and auditing accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.