New 0-Day Attacks Linked to China’s ‘Volt Typhoon’
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-39717 | Unrestricted File Upload in Versa Networks Versa Director Exploited by Volt Typhoon CVE-2024-39717 is an unrestricted file upload flaw (CWE-434) in the interface customization function of Versa Networks' Versa Director: the 'Change Favicon' option in the GUI accepts an uploaded file that merely ends in a .png extension, so a malicious file can masquerade as an image. Exploitation requires network access to the Director GUI and valid credentials for a Provider-Data-Center-Admin or Provider-Data-Center-System-Admin account (tenant-level users cannot reach the feature), which is why the 7.2 CVSS score includes 'high privileges required.' By planting a dangerous file disguised as a .png, an attacker gains a code-execution path on the Director server consistent with the flaw's high confidentiality, integrity and availability impact ratings. Any organization running Versa Director — particularly service providers and internet providers whose management interface is reachable from the internet — is potentially affected. Exploitation is confirmed in the wild: China-linked actor Volt Typhoon used the flaw as a zero-day against U.S. and global IT targets, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-23, and federal agencies were urged to patch by September 2024. Do: Apply Versa Networks' fix/mitigation instructions — CISA's required action is to apply vendor mitigations or discontinue use of the product if mitigations are unavailable — and meet the September 2024 federal remediation deadline if applicable. Restrict access to the Versa Director GUI to trusted management networks rather than exposing it to the internet, and audit and rotate credentials for Provider-Data-Center-Admin and Provider-Data-Center-System-Admin accounts, since the observed Volt Typhoon activity relied on valid high-privilege logins. Check Director systems for unexpected files uploaded through the Change Favicon feature that may be disguised as .png images. | 7.2 | 4% | KEV |
| moderate≈ low thousands of Versa Director deployments worldwide, of which only a small fraction are internet-exposed |
Full article756 words · extracted from krebsonsecurity.com · click to collapse
Malicious hackers are exploiting a zero-day vulnerability in Versa Director, a software product used by many Internet and IT service providers. Researchers believe the activity is linked to Volt Typhoon, a Chinese cyber espionage group focused on infiltrating critical U.S. networks and laying the groundwork for the ability to disrupt communications between the United States and Asia during any future armed conflict with China.

Image: Shutterstock.com
Versa Director systems are primarily used by Internet service providers (ISPs), as well as managed service providers (MSPs) that cater to the IT needs of many small to mid-sized businesses simultaneously. In a security advisory published Aug. 26, Versa urged customers to deploy a patch for the vulnerability (CVE-2024-39717), which the company said is fixed in Versa Director 22.1.4 or later.
Versa said the weakness allows attackers to upload a file of their choosing to vulnerable systems. The advisory placed much of the blame on Versa customers who “failed to implement system hardening and firewall guidelines…leaving a management port exposed on the internet that provided the threat actors with initial access.”
Versa’s advisory doesn’t say how it learned of the zero-day flaw, but its vulnerability listing at mitre.org acknowledges “there are reports of others based on backbone telemetry observations of a 3rd party provider, however these are unconfirmed to date.”
Those third-party reports came in late June 2024 from Michael Horka, senior lead information security engineer at Black Lotus Labs, the security research arm of Lumen Technologies, which operates one of the global Internet’s largest backbones.
In an interview with KrebsOnSecurity, Horka said Black Lotus Labs identified a web-based backdoor on Versa Director systems belonging to four U.S. victims and one non-U.S. victim in the ISP and MSP sectors, with the earliest known exploit activity occurring at a U.S. ISP on June 12, 2024.
“This makes Versa Director a lucrative target for advanced persistent threat (APT) actors who would want to view or control network infrastructure at scale, or pivot into additional (or downstream) networks of interest,” Horka wrote in a blog post published today.
Black Lotus Labs said it assessed with “medium” confidence that Volt Typhoon was responsible for the compromises, noting the intrusions bear the hallmarks of the Chinese state-sponsored espionage group — including zero-day attacks targeting IT infrastructure providers, and Java-based backdoors that run in memory only.
In May 2023, the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and the Cybersecurity Infrastructure Security Agency (CISA) issued a joint warning (PDF) about Volt Typhoon, also known as “Bronze Silhouette” and “Insidious Taurus,” which described how the group uses small office/home office (SOHO) network devices to hide their activity.
In early December 2023, Black Lotus Labs published its findings on “KV-botnet,” thousands of compromised SOHO routers that were chained together to form a covert data transfer network supporting various Chinese state-sponsored hacking groups, including Volt Typhoon.
In January 2024, the U.S. Department of Justice disclosed the FBI had executed a court-authorized takedown of the KV-botnet shortly before Black Lotus Labs released its December report.
In February 2024, CISA again joined the FBI and NSA in warning Volt Typhoon had compromised the IT environments of multiple critical infrastructure organizations — primarily in communications, energy, transportation systems, and water and wastewater sectors — in the continental and non-continental United States and its territories, including Guam.
“Volt Typhoon’s choice of targets and pattern of behavior is not consistent with traditional cyber espionage or intelligence gathering operations, and the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to OT [operational technology] assets to disrupt functions,” that alert warned.
In a speech at Vanderbilt University in April, FBI Director Christopher Wray said China is developing the “ability to physically wreak havoc on our critical infrastructure at a time of its choosing,” and that China’s plan is to “land blows against civilian infrastructure to try to induce panic.”
Ryan English, an information security engineer at Lumen, said it’s disappointing his employer didn’t at least garner an honorable mention in Versa’s security advisory. But he said he’s glad there are now a lot fewer Versa systems exposed to this attack.
“Lumen has for the last nine weeks been very intimate with their leadership with the goal in mind of helping them mitigate this,” English said. “We’ve given them everything we could along the way, so it kind of sucks being referenced just as a third party.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://krebsonsecurity.com/2024/08/new-0-day-attacks-linked-to-chinas-volt-typhoon/