Sources: China-linked hackers penetrated deep into two big US ISPs and several smaller ones in recent months, using a zero-day flaw in Versa Networks software
Later reporting characterized the ISP activity as the Salt Typhoon campaign’s pursuit of sensitive information and raised the possibility that compromised carrier networks reached wiretap-related systems. That makes the Versa flaw significant not simply as a vendor incident, but as a potential entry point into communications infrastructure.
First-order effects
Affected ISPs must identify and remove any attacker access, assess the exposed management and network environments, and apply mitigations for the Versa vulnerability.
Versa Networks faces urgent scrutiny from customers over its zero-day response, product hardening, and the visibility its tools provide into compromise.
Second-order effects
Other carriers using comparable network-management software are likely to accelerate threat hunting and patch validation, while security teams reassess the risk of software with privileged access to carrier operations.
The reported ISP breaches increase pressure for coordination among carriers, vendors, and US cyber agencies because a compromise at a communications provider can expose data and systems beyond the initial victim.
Third-order effects
If repeated exploitation of edge and network-management products persists, telecom security will increasingly be treated as critical-infrastructure and intelligence risk management rather than a conventional enterprise IT problem.
The sequence—from prior VPN-device exploitation to reported carrier intrusions—points to a durable contest over high-value network access points, with more emphasis on resilient architecture and rapid vendor vulnerability response.
The trend: State-linked cyber operations are concentrating on infrastructure providers whose privileged network position can yield broader intelligence access than attacks on individual organizations.
Great work from @BlackLotusLabs tracking likely #VoltTyphoon continued exploitation and infrastructure harvesting activity against ISPs/MSPs - between this and #KVbotnet work, these folks kicking some ass: https://blog.lumen.com/...
NEW: Security researchers say they found evidence that Chinese government-linked hacking group Volt Typhoon used a zero-day to target ISPs in the U.S. and India. The goal was to steal the credentials of the ISPs downstream customers. https://techcrunch.com/...
🧵Every day we learn more about the lengths the Chinese Communist Party will go to exercise gray-zone aggression against America in cyberspace. 1/5 https://www.washingtonpost.com/ ...
Our threat research & operations arm @BlackLotusLabs leverages unmatched network visibility combined with machine learning algorithms to help keep the internet clean. Learn more about the recent discovery of a Zero-Day exploit attributed to #VoltTyphoon: https://blog.lumen.com/..…
How dare China allegedly hack into ISPs to spy on US citizens when any red-blooded American patriot knows all the same data of those US citizens is available for sale from the ISP, Google, or Facebook instead
This accusation from the Chinese Embassy in Washington in response to accusations that CCP-sponsored hackers are targeting US ISP's: “There are signs that in order to receive more congressional budgets and government contracts, the U.S. intelligence community and cybersecurity co…
Great research by @BlackLotusLabs on Volt Typhoon hackers exploiting the Versa Director zero-day to steal credentials/breach networks. Targeted ISPs, MSPs, and IT sector in the US and other countries.
As someone who has been inside telecom networks, going from “gathering intelligence” to shutting things down is just a matter of orders. Great reporting from @josephmenn https://www.washingtonpost.com/ ...
“'Volt Typhoon' is actually a ransomware cybercriminal group who calls itself the ‘Dark Power’ and is not sponsored by any state or region,” said embassy spokesman Liu Pengyu. WaPo's @josephmenn with a banger of a quote! https://www.washingtonpost.com/ ...
For a criminal ransom crew, they don't seem to ever ask for money. Maybe China can elaborate on how much they have paid the group in the last 5 years? (in ransoms, of course) 😂 https://www.washingtonpost.com/ ...
The high-risk vuln (CVE-2024-39717) was added to the CISA must-patch list over the weekend after Versa Networks confirmed zero-day exploitation @SecurityWeek Black Lotus Labs links exploitation to Volt Typhoon APT and says ISPs and MSPs are downstream targets 👇👇
Black Lotus Labs has observed the zero-day exploitation of Versa Director servers, now assigned CVE-2024-39717, dating back to at least June 12, 2024. This exploitation campaign has remained highly targeted https://blog.lumen.com/...
Chinese govt hackers are exploiting a previously unknown @versanetworks flaw to spy on customers of US & foreign internet service providers, per @BlackLotusLabs. https://blog.lumen.com/... WaPo has more on “unusually aggressive and sophisticated” campaign: https://www.washingtonp…