Posts tagged ‘Threat Intelligence’
When Convenience Becomes a Command Prompt: Five Critical RCEs in Dokploy
Versa’s security research team discovered and responsibly disclosed five critical Dokploy vulnerabilities, all rated CVSS 9.9, that let authenticated members escalate to host compromise. Learn how the flaws work, why upgrading to 0.29.13 matters, and how Versa IPS signatures block exploit attempts.
From Reactive Patching to Continuous Hardening: Versa’s AI-Era Security Discipline
Versa’s secure software development practices are built for the AI era. Versa uses frontier cyber models in pre-merge security reviews, validates its software supply chain across dozens of security scanners, blocks any release with unresolved Critical or High-severity vulnerabilities, and requires engineer review of all AI-assisted code before merge.
Security Without Compromise: What the 2026 NSS Labs Cloud Network Firewall Tests Tell Us
The 2026 NSS Labs Comparative Test Report for Cloud Network Firewalls evaluated nine leading cloud-native and third-party firewalls under identical conditions, measuring security effectiveness, performance, TLS support, stability, and cost. As AI drives up encrypted traffic volumes and enables more evasive attacks, the results show that enterprises no longer have to trade protection against performance or cost. Versa NGFW earned NSS Labs’ “Recommended” rating for the second consecutive year, pairing 99.91% security effectiveness with the fastest rated throughput and the second-lowest cost per Mbps of any vendor tested.
DLLHijackHunter: Validation-Driven Discovery and Confirmation of DLL Hijacking Paths on Windows
DLLHijackHunter is an open-source tool that finds real DLL hijacking vulnerabilities, not just theoretical ones. Its canary technique triggers the vulnerable program and captures proof the hijack worked, cutting through the noise of static scanners. Free on GitHub, it helps security teams focus on confirmed findings instead of guessing which candidates actually matter.
The New OWASP GenAI Top 10 and Why Network Security Matters
Almost every risk in the 2026 OWASP GenAI Top 10 leaves observable artifacts at the network layer. This post walks through all ten categories, real-world incidents behind each one, and the specific SASE controls (SWG, CASB, DLP, ZTNA, RBI) that catch what app-layer guardrails miss.
MITRE ATT&CK vs. MITRE ATLAS: Two Frameworks, One Expanding Threat Landscape
I have been in cyber security for over 25 years. And I have done my fair share of penetration testing/offensive security and I am quite familiar with the MITRE ATT&CK framework. Not long ago, I had the chance to dig into AI offensive security techniques hands-on. I assumed we would use the standard Kali-style hacking tools and follow the usual TTPs. I was wrong. We never fired up a Kali Linux instance or used a single tool from the past 30+ years. Instead, we learned how to trick the LLM into giving us information it was not supposed to. For…
CVE-2026-41940: Inside the cPanel/WHM Authentication Bypass
Introduction Hosting control panels operate with near-total authority over a server: websites, databases, DNS, email, and the account lifecycle are all driven from one place. That privilege makes them a high-value target—when a control-plane bug appears, compromise can extend far beyond a single site. CVE-2026-41940 is a pre-authentication bypass affecting WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared). In practical terms, it lets a remote, unauthenticated attacker reach administrator-level control without supplying valid credentials. Background: What Is cPanel/WHM? cPanel is a widely deployed, Linux-based hosting panel. WHM is the higher-privileged layer used by resellers and server administrators to…
The Ghost in the Leased Line: Unmasking MuddyWater, Surgical Cyber Arm
In the high-stakes theater of global geopolitics, the most effective weapons aren’t always missiles; sometimes, they are just few lines of code.
Identity Is the New Perimeter. Stryker Just Taught Us That the Hard Way.
A story on how an Iran-linked group wiped tens of thousands of Stryker’s devices A nation-state attack that changes every assumption we had For years, we have treated nation-state threats as a “Tier 1” problem — something reserved for defense contractors and the energy grid. The March 2026 attack on Stryker Corporation by Iran-linked group Handala officially kills that assumption. On March 11, 2026, Stryker’s corporate Microsoft environment was hit. Employees arrived to find their managed devices wiped out overnight through entirely legitimate Intune commands. Handala claimed 200,000+ systems affected; independent reporting confirms that tens of thousands were impacted. Stryker’s…
What is Workspace Security?
“What Is Workspace Security? Learn how Workspace Security, operating within the broader Secure Access Service Edge (SASE) framework, unites advanced security and networking technologies to safeguard users, devices, applications, and data. From enabling Zero Trust principles to incorporating tools like SWG, CASB, ZTNA, DLP, and DEM, explore how Workspace Security helps organizations protect distributed workforces while enabling productivity and collaboration. Discover why Versa is a leader in SASE innovation for modern enterprises.
Company Updates
Ransomware and What It Could Cost You
By Jon Taylor
Director and Principal of Security, Versa Networks
October 17, 2022
Read more to find out more about the actual cost of ransomware.
Industry Insights
The State of Cloud Security in 2022
By The Versa Team
SASE Technical Professionals
October 17, 2022
What does a data breach say about your company? We surveyed 600 IT professionals to see how important cloud security is in 2022. Here’s what they said.
Research Lab
Blackcat/ALPHV Ransomware and What To Do
By Versa Threat Research Lab
Versa Networks
April 27, 2022
The FBI, chief investigating agency of the U.S., has triggered an alert concluding that more than 60 organizations worldwide have been a victim of the sophisticated ransomware attack by Blackcat also known as ALPHV/Noberus. The ransomware first came to light when the investigation revealed it to be the first ransomware using the memory-safe programming language RUST, known for its improved performance. Many of the developers of Blackcat are linked with more popular ransomware groups Darkside and Blackmatter who large groups with the experience to carry out operations with a well-established network to support logistics. The advantage of using the RUST…
Research Lab
How Often Do Americans Snoop Online?
By The Versa Team
SASE Technical Professionals
April 26, 2022
Whether it’s scouring social media feeds of professionals, family, friends, or strangers, curiosity fills our minds with questions about others we’d prefer not to ask. But how often?
Research Lab
Surveying American Business Owners on Data Breaches
By The Versa Team
SASE Technical Professionals
March 16, 2022
Data breaches are on the rise, but are companies properly prepared for this growing threat? We surveyed 1,200 business owners to find out.
Industry Insights
Defense Against Web Threats in the Modern Era
By Amelie Sutsakhan
Product Marketing Manager, Versa Networks
April 20, 2021
Cyberattacks have been ranked as the fastest growing crime in the US. Secure Web Gateway (SWG), one of the five components of Secure Access Service Edge (SASE) is key to protecting users from web-based threats while applying and enforcing security policies consistently.
Research Lab
Detect Zero-Day Exploits in Microsoft’s Exchange Server
By Versa Threat Research Lab
Versa Networks
March 9, 2021
Last week, Microsoft released an important blog that details that details how HAFNIUM, a state-sponsored threat actor operating out of China, exploited Microsoft Exchange Servers with zero-day exploits along with other code execution vulnerabilities in the Sharepoint software. Microsoft advises that these patches are only intended to be a temporary fix. Customers are still required to update their software to the latest version and apply any relevant security patches to their server.
Research Lab
Unpacking the SolarWinds Supply Chain Attack
By Jayesh Gangadas Patel
Principle Threat Researcher, Versa Networks
January 12, 2021
The SolarWinds attack leaves many unanswered questions and the most prominent amongst them is the question of how the attacker entered internal systems of SolarWinds network and was able to infiltrate and move inconspicuously across the development chain. The malware was able to camouflage its activity among the highly secure network of the prominent organization for an extended period of time, evading all their security detection and prevention defenses. In this particular blog, our team will mainly focus on the chain of events that occurred, and the evasive methods employed to remain completely stealthy despite moving around and compromising a highly secure network environment.
Research Lab
SUPERNOVA: the Invisible Explosion That Caught the Industry Off Guard
By Winny Thomas
Principal Security Architect
December 29, 2020
On December 13, 2020, FireEye reported a global campaign that targeted a large sector of industries by threat actors who inserted malicious code within a software component used by the popular network management software SolarWinds. It is not yet known how the threat actors managed to gain access to the development environment in which they added and distributed this malicious code as part of an update to the software. This trojanized version of the dynamic-link library (DLL) has been given the name ‘Sunburst’ by FireEye. Surprisingly enough, researchers have found evidence of the presence of a second backdoor in the SolarWinds product.
Research Lab
The NSA’s Top 25 Most Exploited Vulnerabilities
By Winny Thomas
Principal Security Architect
December 23, 2020
The National Security Agency published a list of 25 CVEs (Common Vulnerabilities and Exposures) that were most exploited by threat actors in recent times. Some of these CVE’s were used to deliver malicious software that allowed monitoring remote networks, maintaining continued access to remote networks, and, in some cases, using these CVEs to pivot to other systems within the internal network. For example, CVE-2019-11510 was used to gain access to sensitive VPN information of user accounts and then use the credentials to deliver ransomware like Sodinokibi. Similarly, CVE-2019-0803 was used to establish a backdoor to gain and maintain access to…
Subscribe to the Versa Blog
Recent Posts
What Enterprises Really Want from SASE Consolidation
By Kevin SheuOctober 5, 2026
How Versa Sovereign SASE Answers the EU Technological Sovereignty Package
By Dhiraj SehgalSeptember 29, 2026
Topics
Top Tags
Gartner Research Report
2026 Gartner® Magic Quadrant™ for SASE Platforms
Versa has for the fourth consecutive year been recognized in the 2026 Gartner Magic Quadrant for SASE Platforms1 and is one of only 12 vendors that met the criteria for inclusion based on the analysts’ evaluation of the VersaONE Universal SASE Platform.



