Posts tagged ‘Threat Intelligence’

Research Lab Oct 6, 2026

When Convenience Becomes a Command Prompt: Five Critical RCEs in Dokploy

Versa’s security research team discovered and responsibly disclosed five critical Dokploy vulnerabilities, all rated CVSS 9.9, that let authenticated members escalate to host compromise. Learn how the flaws work, why upgrading to 0.29.13 matters, and how Versa IPS signatures block exploit attempts.

Read More
AI Thought Leadership Oct 5, 2026

From Reactive Patching to Continuous Hardening: Versa’s AI-Era Security Discipline

Versa’s secure software development practices are built for the AI era. Versa uses frontier cyber models in pre-merge security reviews, validates its software supply chain across dozens of security scanners, blocks any release with unresolved Critical or High-severity vulnerabilities, and requires engineer review of all AI-assisted code before merge.

Read More
Industry Insights Sep 30, 2026

Security Without Compromise: What the 2026 NSS Labs Cloud Network Firewall Tests Tell Us

The 2026 NSS Labs Comparative Test Report for Cloud Network Firewalls evaluated nine leading cloud-native and third-party firewalls under identical conditions, measuring security effectiveness, performance, TLS support, stability, and cost. As AI drives up encrypted traffic volumes and enables more evasive attacks, the results show that enterprises no longer have to trade protection against performance or cost. Versa NGFW earned NSS Labs’ “Recommended” rating for the second consecutive year, pairing 99.91% security effectiveness with the fastest rated throughput and the second-lowest cost per Mbps of any vendor tested.

Read More
Research Lab Sep 28, 2026

DLLHijackHunter: Validation-Driven Discovery and Confirmation of DLL Hijacking Paths on Windows

DLLHijackHunter is an open-source tool that finds real DLL hijacking vulnerabilities, not just theoretical ones. Its canary technique triggers the vulnerable program and captures proof the hijack worked, cutting through the noise of static scanners. Free on GitHub, it helps security teams focus on confirmed findings instead of guessing which candidates actually matter.

Read More
Security Sep 10, 2026

The New OWASP GenAI Top 10 and Why Network Security Matters

Almost every risk in the 2026 OWASP GenAI Top 10 leaves observable artifacts at the network layer. This post walks through all ten categories, real-world incidents behind each one, and the specific SASE controls (SWG, CASB, DLP, ZTNA, RBI) that catch what app-layer guardrails miss.

Read More
Security Jul 1, 2026

MITRE ATT&CK vs. MITRE ATLAS: Two Frameworks, One Expanding Threat Landscape

I have been in cyber security for over 25 years. And I have done my fair share of penetration testing/offensive security and I am quite familiar with the MITRE ATT&CK framework. Not long ago, I had the chance to dig into AI offensive security techniques hands-on. I assumed we would use the standard Kali-style hacking tools and follow the usual TTPs. I was wrong. We never fired up a Kali Linux instance or used a single tool from the past 30+ years. Instead, we learned how to trick the LLM into giving us information it was not supposed to. For…

Read More
Industry Insights May 13, 2026

CVE-2026-41940: Inside the cPanel/WHM Authentication Bypass

Introduction Hosting control panels operate with near-total authority over a server: websites, databases, DNS, email, and the account lifecycle are all driven from one place. That privilege makes them a high-value target—when a control-plane bug appears, compromise can extend far beyond a single site. CVE-2026-41940 is a pre-authentication bypass affecting WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared). In practical terms, it lets a remote, unauthenticated attacker reach administrator-level control without supplying valid credentials. Background: What Is cPanel/WHM? cPanel is a widely deployed, Linux-based hosting panel. WHM is the higher-privileged layer used by resellers and server administrators to…

Read More
Industry Insights May 11, 2026

The Ghost in the Leased Line: Unmasking MuddyWater, Surgical Cyber Arm

In the high-stakes theater of global geopolitics, the most effective weapons aren’t always missiles; sometimes, they are just few lines of code.

Read More
Industry Insights Apr 2, 2026

Identity Is the New Perimeter. Stryker Just Taught Us That the Hard Way.

A story on how an Iran-linked group wiped tens of thousands of Stryker’s devices A nation-state attack that changes every assumption we had For years, we have treated nation-state threats as a “Tier 1” problem — something reserved for defense contractors and the energy grid. The March 2026 attack on Stryker Corporation by Iran-linked group Handala officially kills that assumption. On March 11, 2026, Stryker’s corporate Microsoft environment was hit. Employees arrived to find their managed devices wiped out overnight through entirely legitimate Intune commands. Handala claimed 200,000+ systems affected; independent reporting confirms that tens of thousands were impacted. Stryker’s…

Read More
Industry Insights Mar 31, 2026

What is Workspace Security?

“What Is Workspace Security? Learn how Workspace Security, operating within the broader Secure Access Service Edge (SASE) framework, unites advanced security and networking technologies to safeguard users, devices, applications, and data. From enabling Zero Trust principles to incorporating tools like SWG, CASB, ZTNA, DLP, and DEM, explore how Workspace Security helps organizations protect distributed workforces while enabling productivity and collaboration. Discover why Versa is a leader in SASE innovation for modern enterprises.

Read More

Versa Security Bulletin: ConnectWise ScreenConnect Authentication Bypass and Path-Traversal Vulnerabilities

Versa Security Research Team
By Versa Security Research Team
Threat Research & Protection Team
March 8, 2024

CVEs: CVE-2024-1708; CVE-2024-1709 Summary On Feb. 13, 2024, ConnectWise was notified of two vulnerabilities in their remote access tool ScreenConnect. On Feb. 19, 2024, ConnectWise publicly disclosed two new high severity and critical vulnerabilities patched in its remote access tool ScreenConnect Version 23.9.8, with the following CVEs: CVE-2024-1708 Path-Traversal vulnerability (CWE-22) and CVE-2024-1709 Authentication Bypass vulnerability (CWE-288). These vulnerabilities can be exploited to deliver Remote Access Trojans (RATs), Ransomware, Cryptocurrency miners, Stealer malware and many others. CVE Description CVSSv3 Severity CVE-2024- 1709 (CWE-288) Authentication Bypass Using Alternate Path or Channel 10.0 Critical CVE-2024- 1708 (CWE-22) Improper Limitation of a Pathname to…

Versa Security Bulletin: Volt Typhoon Exploitation of N-Day and Zero-Day Vulnerabilities

Versa Security Research Team
By Versa Security Research Team
Threat Research & Protection Team
February 28, 2024

Summary This security bulletin focuses on understanding the sophisticated exploitation of critical n-day and zero-day vulnerabilities in VPN and other network devices by state-sponsored threat actors, reinforcing the urgency for organizations to prioritize patching vulnerabilities in appliances known to be targeted. The recent exploitation of the critical FortiOS vulnerability followed a disclosure by CISA and other federal agencies revealing that China-linked threat group Volt Typhoon has been known to exploit network appliances from several vendors including Fortinet. Fortinet released a blog post to coincide with the U.S. agencies’ advisory, which pointed to “the need for organizations to have a robust…

Versa Security Bulletin: Multiple Vulnerabilities Affecting Ivanti Connect Secure and Ivanti Policy Secure

Versa Security Research Team
By Versa Security Research Team
Threat Research & Protection Team
February 7, 2024

CVEs: CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 Summary Recently, Ivanti Connect Secure appliances have faced active exploitation through a series of linked vulnerabilities of high or critical severity. On January 10, 2024, Ivanti disclosed two new vulnerabilities in its Ivanti Connect Secure and Ivanti Policy Secure gateways: CVE-2023-46805 (high severity authentication bypass vulnerability) and CVE-2024-21887 (critical severity command injection vulnerability).

Versa Security Bulletin: Okta Customer Support Security Incident

Versa Security Research Team
By Versa Security Research Team
Threat Research & Protection Team
December 5, 2023

On October 20, 2023, Okta disclosed a security incident affecting their customer support management system. In a note following that disclosure Okta said that from September 28, 2023, to October 17, 2023, a threat actor gained unauthorized access to files inside Okta’s customer support system associated with 134 Okta customers, or less than 1% of Okta customers.

Modernizing Retail with Secure SD-WAN

Leo Jiao
By Leo Jiao
Sr. Systems Engineer. Versa Networks
November 2, 2023

In recent years we’ve witnessed transformative changes in both technology and the retail industry. The retail world has seen tremendous ups and downs over the past several years thanks to the impact of COVID. In addition to challenges such as store closures, reduced foot traffic, and supply chain problems, digital disruptions include an increasing shift to e-commerce and new types of cyber threats that have dramatically changed how people shop and how retail businesses should operate. In the technology world, numerous stunning innovations such as AI/ML-assisted network operations and threat detection are making people’s jaws drop because of their capabilities…

Versa Security Bulletin: Cisco IOS XE Web UI Privilege Escalation Vulnerability affecting upwards of 50k devices (patched)

Jayesh Gangadas Patel
By Jayesh Gangadas Patel
Principle Threat Researcher, Versa Networks
October 26, 2023

Summary On October 16, 2023, Cisco reported two new vulnerabilities in the web UI for its Cisco IOS XE operating system that runs many of its routers and switches, CVE-2023-20198 and CVE-2023-20273. These vulnerabilities were initially being exploited by unknown hackers and affected more than 10,000 devices at the time of its first known existence. However, in the following days the attack was leveraged to affect more than 50,000 devices, and that’s when a free software fix was identified by Cisco to keep a check on devices. Cisco released the updated version 17.9.4a on October 23 to fix the issue….

A Pragmatic View of Breaking and Inspecting SSL

Mark Harman
By Mark Harman
Sr. Systems Engineer, Versa Networks
October 11, 2023

SSL Break and Inspect (B&I) has always been a point of contention in the security world. On the one hand, we have the network security teams saying, “We should inspect everything on our network and not allow anything that we cannot inspect.”

Riding the Storm-0978:  Mitigating Trojanized Microsoft Office Exploits

Naganathan S J
By Naganathan S J
Staff Security Engineer - Research
July 28, 2023

Cyber criminal organization based out of Russia known as RomCom have been very active lately targeting Ukraine and its military. The threat actors were targeting European government officials with phishing emails containing lure documents around the current political situation.

Versa Networks Enterprise Firewall Sets the Industry Standard for Security Effectiveness, Performance and Value

Dan Maier
By Dan Maier
Chief Marketing Officer, Versa Networks
May 16, 2023

In a world where cybersecurity is of paramount importance, choosing the right enterprise firewall can make or break a company’s security posture. Versa Networks, the pioneer of single-vendor Unified Secure Access Service Edge (SASE) solutions, has recently emerged as a leading vendor in the highly competitive firewall market. In a groundbreaking independent test conducted by CyberRatings.org comparing eight leading firewall vendors, Versa Networks’ CSG5000 Next Generation Firewall garnered a remarkable 99.48% security effectiveness score and achieved top ‘AAA’ ratings in all categories. ‘AAA’ is the highest rating assigned by CyberRatings. In addition, Versa delivered the highest Rated Throughput and the lowest Price per…

Healthcare Means Security

Jon Taylor
By Jon Taylor
Director and Principal of Security, Versa Networks
January 12, 2023

Cybersecurity is crucial in all industries, but it is especially important in the healthcare sector. Let Versa Networks take you through the reasons cyber security is of upmost importance in healthcare, some scenarios of what can and has happened, and what Versa Networks can do to improve security in healthcare while increasing the security posture, reducing TCO, and easing the stress of the engineering staff through simplified management and reporting.


Recent Posts













Gartner Research Report

2026 Gartner® Magic Quadrant™ for SASE Platforms

Versa has for the fourth consecutive year been recognized in the 2026 Gartner Magic Quadrant for SASE Platforms1 and is one of only 12 vendors that met the criteria for inclusion based on the analysts’ evaluation of the VersaONE Universal SASE Platform.