/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software

Joseph Menn / Washington Post :

Washington Post Joseph Menn

Context & Ripple Effects

The reported intrusions extend a recurring pattern in the coverage: China-linked groups have previously targeted network infrastructure through device and software flaws, including attacks on Pulse Secure VPN customers in the US defense sector.

Later reporting characterized the ISP activity as the Salt Typhoon campaign’s pursuit of sensitive information and raised the possibility that compromised carrier networks reached wiretap-related systems. That makes the Versa flaw significant not simply as a vendor incident, but as a potential entry point into communications infrastructure.

First-order effects

  • Affected ISPs must identify and remove any attacker access, assess the exposed management and network environments, and apply mitigations for the Versa vulnerability.
  • Versa Networks faces urgent scrutiny from customers over its zero-day response, product hardening, and the visibility its tools provide into compromise.

Second-order effects

  • Other carriers using comparable network-management software are likely to accelerate threat hunting and patch validation, while security teams reassess the risk of software with privileged access to carrier operations.
  • The reported ISP breaches increase pressure for coordination among carriers, vendors, and US cyber agencies because a compromise at a communications provider can expose data and systems beyond the initial victim.

Third-order effects

  • If repeated exploitation of edge and network-management products persists, telecom security will increasingly be treated as critical-infrastructure and intelligence risk management rather than a conventional enterprise IT problem.
  • The sequence—from prior VPN-device exploitation to reported carrier intrusions—points to a durable contest over high-value network access points, with more emphasis on resilient architecture and rapid vendor vulnerability response.

The trend: State-linked cyber operations are concentrating on infrastructure providers whose privileged network position can yield broader intelligence access than attacks on individual organizations.

Discussion

  • @jfslowik Joe Słowik on x
    Great work from @BlackLotusLabs tracking likely #VoltTyphoon continued exploitation and infrastructure harvesting activity against ISPs/MSPs - between this and #KVbotnet work, these folks kicking some ass: https://blog.lumen.com/...
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Security researchers say they found evidence that Chinese government-linked hacking group Volt Typhoon used a zero-day to target ISPs in the U.S. and India. The goal was to steal the credentials of the ISPs downstream customers. https://techcrunch.com/...
  • @homelandgop @homelandgop on x
    🧵Every day we learn more about the lengths the Chinese Communist Party will go to exercise gray-zone aggression against America in cyberspace. 1/5 https://www.washingtonpost.com/ ...
  • @lumentechco Lumen on x
    Our threat research & operations arm @BlackLotusLabs leverages unmatched network visibility combined with machine learning algorithms to help keep the internet clean. Learn more about the recent discovery of a Zero-Day exploit attributed to #VoltTyphoon: https://blog.lumen.com/..…
  • @rekdt @rekdt on x
    How dare China allegedly hack into ISPs to spy on US citizens when any red-blooded American patriot knows all the same data of those US citizens is available for sale from the ISP, Google, or Facebook instead
  • @hackingbutlegal Jackie Singh on x
    This accusation from the Chinese Embassy in Washington in response to accusations that CCP-sponsored hackers are targeting US ISP's: “There are signs that in order to receive more congressional budgets and government contracts, the U.S. intelligence community and cybersecurity co…
  • @lawrenceabrams Lawrence Abrams on x
    Great research by @BlackLotusLabs on Volt Typhoon hackers exploiting the Versa Director zero-day to steal credentials/breach networks. Targeted ISPs, MSPs, and IT sector in the US and other countries.
  • @uuallan @uuallan on x
    As someone who has been inside telecom networks, going from “gathering intelligence” to shutting things down is just a matter of orders. Great reporting from ⁦@josephmenn⁩ https://www.washingtonpost.com/ ...
  • @ryanaraine Ryan Naraine on x
    “'Volt Typhoon' is actually a ransomware cybercriminal group who calls itself the ‘Dark Power’ and is not sponsored by any state or region,” said embassy spokesman Liu Pengyu. WaPo's @josephmenn with a banger of a quote! https://www.washingtonpost.com/ ...
  • @dakotaindc Dakota Cary on x
    For a criminal ransom crew, they don't seem to ever ask for money. Maybe China can elaborate on how much they have paid the group in the last 5 years? (in ransoms, of course) 😂 https://www.washingtonpost.com/ ...
  • @ryanaraine Ryan Naraine on x
    The high-risk vuln (CVE-2024-39717) was added to the CISA must-patch list over the weekend after Versa Networks confirmed zero-day exploitation @SecurityWeek Black Lotus Labs links exploitation to Volt Typhoon APT and says ISPs and MSPs are downstream targets 👇👇
  • @ryanaraine Ryan Naraine on x
    Black Lotus Labs documentation is live https://blog.lumen.com/... @BlackLotusLabs YARA rule for hunting https://github.com/...
  • @k_sec Kurt Baumgartner on x
    Black Lotus Labs has observed the zero-day exploitation of Versa Director servers, now assigned CVE-2024-39717, dating back to at least June 12, 2024. This exploitation campaign has remained highly targeted https://blog.lumen.com/...
  • @ericgeller Eric Geller on x
    Chinese govt hackers are exploiting a previously unknown @versanetworks flaw to spy on customers of US & foreign internet service providers, per @BlackLotusLabs. https://blog.lumen.com/... WaPo has more on “unusually aggressive and sophisticated” campaign: https://www.washingtonp…
  • r/cybersecurity r on reddit
    Chinese government hackers penetrate U.S. internet providers to spy
  • r/Intelligence r on reddit
    Chinese government hackers penetrate U.S. internet providers to spy
  • r/technews r on reddit
    Hackers infect ISPs with malware that steals customers' credentials |  Zero-day that was exploited since June to infect ISPs finally gets fixed.
  • r/technology r on reddit
    Chinese government hackers penetrate U.S. internet providers to spy