Posts tagged ‘Threat Intelligence’
When Convenience Becomes a Command Prompt: Five Critical RCEs in Dokploy
Versa’s security research team discovered and responsibly disclosed five critical Dokploy vulnerabilities, all rated CVSS 9.9, that let authenticated members escalate to host compromise. Learn how the flaws work, why upgrading to 0.29.13 matters, and how Versa IPS signatures block exploit attempts.
From Reactive Patching to Continuous Hardening: Versa’s AI-Era Security Discipline
Versa’s secure software development practices are built for the AI era. Versa uses frontier cyber models in pre-merge security reviews, validates its software supply chain across dozens of security scanners, blocks any release with unresolved Critical or High-severity vulnerabilities, and requires engineer review of all AI-assisted code before merge.
Security Without Compromise: What the 2026 NSS Labs Cloud Network Firewall Tests Tell Us
The 2026 NSS Labs Comparative Test Report for Cloud Network Firewalls evaluated nine leading cloud-native and third-party firewalls under identical conditions, measuring security effectiveness, performance, TLS support, stability, and cost. As AI drives up encrypted traffic volumes and enables more evasive attacks, the results show that enterprises no longer have to trade protection against performance or cost. Versa NGFW earned NSS Labs’ “Recommended” rating for the second consecutive year, pairing 99.91% security effectiveness with the fastest rated throughput and the second-lowest cost per Mbps of any vendor tested.
DLLHijackHunter: Validation-Driven Discovery and Confirmation of DLL Hijacking Paths on Windows
DLLHijackHunter is an open-source tool that finds real DLL hijacking vulnerabilities, not just theoretical ones. Its canary technique triggers the vulnerable program and captures proof the hijack worked, cutting through the noise of static scanners. Free on GitHub, it helps security teams focus on confirmed findings instead of guessing which candidates actually matter.
The New OWASP GenAI Top 10 and Why Network Security Matters
Almost every risk in the 2026 OWASP GenAI Top 10 leaves observable artifacts at the network layer. This post walks through all ten categories, real-world incidents behind each one, and the specific SASE controls (SWG, CASB, DLP, ZTNA, RBI) that catch what app-layer guardrails miss.
MITRE ATT&CK vs. MITRE ATLAS: Two Frameworks, One Expanding Threat Landscape
I have been in cyber security for over 25 years. And I have done my fair share of penetration testing/offensive security and I am quite familiar with the MITRE ATT&CK framework. Not long ago, I had the chance to dig into AI offensive security techniques hands-on. I assumed we would use the standard Kali-style hacking tools and follow the usual TTPs. I was wrong. We never fired up a Kali Linux instance or used a single tool from the past 30+ years. Instead, we learned how to trick the LLM into giving us information it was not supposed to. For…
CVE-2026-41940: Inside the cPanel/WHM Authentication Bypass
Introduction Hosting control panels operate with near-total authority over a server: websites, databases, DNS, email, and the account lifecycle are all driven from one place. That privilege makes them a high-value target—when a control-plane bug appears, compromise can extend far beyond a single site. CVE-2026-41940 is a pre-authentication bypass affecting WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared). In practical terms, it lets a remote, unauthenticated attacker reach administrator-level control without supplying valid credentials. Background: What Is cPanel/WHM? cPanel is a widely deployed, Linux-based hosting panel. WHM is the higher-privileged layer used by resellers and server administrators to…
The Ghost in the Leased Line: Unmasking MuddyWater, Surgical Cyber Arm
In the high-stakes theater of global geopolitics, the most effective weapons aren’t always missiles; sometimes, they are just few lines of code.
Identity Is the New Perimeter. Stryker Just Taught Us That the Hard Way.
A story on how an Iran-linked group wiped tens of thousands of Stryker’s devices A nation-state attack that changes every assumption we had For years, we have treated nation-state threats as a “Tier 1” problem — something reserved for defense contractors and the energy grid. The March 2026 attack on Stryker Corporation by Iran-linked group Handala officially kills that assumption. On March 11, 2026, Stryker’s corporate Microsoft environment was hit. Employees arrived to find their managed devices wiped out overnight through entirely legitimate Intune commands. Handala claimed 200,000+ systems affected; independent reporting confirms that tens of thousands were impacted. Stryker’s…
What is Workspace Security?
“What Is Workspace Security? Learn how Workspace Security, operating within the broader Secure Access Service Edge (SASE) framework, unites advanced security and networking technologies to safeguard users, devices, applications, and data. From enabling Zero Trust principles to incorporating tools like SWG, CASB, ZTNA, DLP, and DEM, explore how Workspace Security helps organizations protect distributed workforces while enabling productivity and collaboration. Discover why Versa is a leader in SASE innovation for modern enterprises.
Research Lab
Versa Security Bulletin: ConnectWise ScreenConnect Authentication Bypass and Path-Traversal Vulnerabilities
By Versa Security Research Team
Threat Research & Protection Team
March 8, 2024
CVEs: CVE-2024-1708; CVE-2024-1709 Summary On Feb. 13, 2024, ConnectWise was notified of two vulnerabilities in their remote access tool ScreenConnect. On Feb. 19, 2024, ConnectWise publicly disclosed two new high severity and critical vulnerabilities patched in its remote access tool ScreenConnect Version 23.9.8, with the following CVEs: CVE-2024-1708 Path-Traversal vulnerability (CWE-22) and CVE-2024-1709 Authentication Bypass vulnerability (CWE-288). These vulnerabilities can be exploited to deliver Remote Access Trojans (RATs), Ransomware, Cryptocurrency miners, Stealer malware and many others. CVE Description CVSSv3 Severity CVE-2024- 1709 (CWE-288) Authentication Bypass Using Alternate Path or Channel 10.0 Critical CVE-2024- 1708 (CWE-22) Improper Limitation of a Pathname to…
Research Lab
Versa Security Bulletin: Volt Typhoon Exploitation of N-Day and Zero-Day Vulnerabilities
By Versa Security Research Team
Threat Research & Protection Team
February 28, 2024
Summary This security bulletin focuses on understanding the sophisticated exploitation of critical n-day and zero-day vulnerabilities in VPN and other network devices by state-sponsored threat actors, reinforcing the urgency for organizations to prioritize patching vulnerabilities in appliances known to be targeted. The recent exploitation of the critical FortiOS vulnerability followed a disclosure by CISA and other federal agencies revealing that China-linked threat group Volt Typhoon has been known to exploit network appliances from several vendors including Fortinet. Fortinet released a blog post to coincide with the U.S. agencies’ advisory, which pointed to “the need for organizations to have a robust…
Research Lab
Versa Security Bulletin: Multiple Vulnerabilities Affecting Ivanti Connect Secure and Ivanti Policy Secure
By Versa Security Research Team
Threat Research & Protection Team
February 7, 2024
CVEs: CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 Summary Recently, Ivanti Connect Secure appliances have faced active exploitation through a series of linked vulnerabilities of high or critical severity. On January 10, 2024, Ivanti disclosed two new vulnerabilities in its Ivanti Connect Secure and Ivanti Policy Secure gateways: CVE-2023-46805 (high severity authentication bypass vulnerability) and CVE-2024-21887 (critical severity command injection vulnerability).
Company Updates, Research Lab
Versa Security Bulletin: Okta Customer Support Security Incident
By Versa Security Research Team
Threat Research & Protection Team
December 5, 2023
On October 20, 2023, Okta disclosed a security incident affecting their customer support management system. In a note following that disclosure Okta said that from September 28, 2023, to October 17, 2023, a threat actor gained unauthorized access to files inside Okta’s customer support system associated with 134 Okta customers, or less than 1% of Okta customers.
Company Updates
Modernizing Retail with Secure SD-WAN
By Leo Jiao
Sr. Systems Engineer. Versa Networks
November 2, 2023
In recent years we’ve witnessed transformative changes in both technology and the retail industry. The retail world has seen tremendous ups and downs over the past several years thanks to the impact of COVID. In addition to challenges such as store closures, reduced foot traffic, and supply chain problems, digital disruptions include an increasing shift to e-commerce and new types of cyber threats that have dramatically changed how people shop and how retail businesses should operate. In the technology world, numerous stunning innovations such as AI/ML-assisted network operations and threat detection are making people’s jaws drop because of their capabilities…
Company Updates, Research Lab
Versa Security Bulletin: Cisco IOS XE Web UI Privilege Escalation Vulnerability affecting upwards of 50k devices (patched)
By Jayesh Gangadas Patel
Principle Threat Researcher, Versa Networks
October 26, 2023
Summary On October 16, 2023, Cisco reported two new vulnerabilities in the web UI for its Cisco IOS XE operating system that runs many of its routers and switches, CVE-2023-20198 and CVE-2023-20273. These vulnerabilities were initially being exploited by unknown hackers and affected more than 10,000 devices at the time of its first known existence. However, in the following days the attack was leveraged to affect more than 50,000 devices, and that’s when a free software fix was identified by Cisco to keep a check on devices. Cisco released the updated version 17.9.4a on October 23 to fix the issue….
Industry Insights
A Pragmatic View of Breaking and Inspecting SSL
By Mark Harman
Sr. Systems Engineer, Versa Networks
October 11, 2023
SSL Break and Inspect (B&I) has always been a point of contention in the security world. On the one hand, we have the network security teams saying, “We should inspect everything on our network and not allow anything that we cannot inspect.”
Industry Insights
Riding the Storm-0978: Mitigating Trojanized Microsoft Office Exploits
By Naganathan S J
Staff Security Engineer - Research
July 28, 2023
Cyber criminal organization based out of Russia known as RomCom have been very active lately targeting Ukraine and its military. The threat actors were targeting European government officials with phishing emails containing lure documents around the current political situation.
Company Updates
Versa Networks Enterprise Firewall Sets the Industry Standard for Security Effectiveness, Performance and Value
By Dan Maier
Chief Marketing Officer, Versa Networks
May 16, 2023
In a world where cybersecurity is of paramount importance, choosing the right enterprise firewall can make or break a company’s security posture. Versa Networks, the pioneer of single-vendor Unified Secure Access Service Edge (SASE) solutions, has recently emerged as a leading vendor in the highly competitive firewall market. In a groundbreaking independent test conducted by CyberRatings.org comparing eight leading firewall vendors, Versa Networks’ CSG5000 Next Generation Firewall garnered a remarkable 99.48% security effectiveness score and achieved top ‘AAA’ ratings in all categories. ‘AAA’ is the highest rating assigned by CyberRatings. In addition, Versa delivered the highest Rated Throughput and the lowest Price per…
Industry Insights
Healthcare Means Security
By Jon Taylor
Director and Principal of Security, Versa Networks
January 12, 2023
Cybersecurity is crucial in all industries, but it is especially important in the healthcare sector. Let Versa Networks take you through the reasons cyber security is of upmost importance in healthcare, some scenarios of what can and has happened, and what Versa Networks can do to improve security in healthcare while increasing the security posture, reducing TCO, and easing the stress of the engineering staff through simplified management and reporting.
Subscribe to the Versa Blog
Recent Posts
What Enterprises Really Want from SASE Consolidation
By Kevin SheuOctober 5, 2026
How Versa Sovereign SASE Answers the EU Technological Sovereignty Package
By Dhiraj SehgalSeptember 29, 2026
Topics
Top Tags
Gartner Research Report
2026 Gartner® Magic Quadrant™ for SASE Platforms
Versa has for the fourth consecutive year been recognized in the 2026 Gartner Magic Quadrant for SASE Platforms1 and is one of only 12 vendors that met the criteria for inclusion based on the analysts’ evaluation of the VersaONE Universal SASE Platform.



