In a new cyber espionage campaign, China’s Volt Typhoon is suspected of exploiting a high-severity vulnerability in Versa SD-WAN software, posing a significant threat to U.S. critical infrastructure. The flaw, tracked as CVE-2024-39717, has allowed attackers to plant credential-harvesting web shells on affected networks. Doug Britton, Chief Strategy Officer at RunSafe Security, explains that this attack aligns with Volt Typhoon’s known tactics of targeting edge systems to infiltrate and exploit critical infrastructure. Britton emphasizes the urgency for secure-by-design approaches to mitigate such risks and future-proof technologies against both known and unknown vulnerabilities.
Perspectives on XSS Vulnerabilities with RunSafe’s CTO
XSS vulnerabilities are a 30-year-old security flaw that won't go away. Recently, CISA and the FBI sounded the alarm on cross-site scripting - but why now? And could AI make the problem even worse? Shane Fry, CTO at RunSafe Security, and industry experts weighed in on...