Posts tagged ‘Threat Intelligence’

Research Lab Oct 6, 2026

When Convenience Becomes a Command Prompt: Five Critical RCEs in Dokploy

Versa’s security research team discovered and responsibly disclosed five critical Dokploy vulnerabilities, all rated CVSS 9.9, that let authenticated members escalate to host compromise. Learn how the flaws work, why upgrading to 0.29.13 matters, and how Versa IPS signatures block exploit attempts.

Read More
AI Thought Leadership Oct 5, 2026

From Reactive Patching to Continuous Hardening: Versa’s AI-Era Security Discipline

Versa’s secure software development practices are built for the AI era. Versa uses frontier cyber models in pre-merge security reviews, validates its software supply chain across dozens of security scanners, blocks any release with unresolved Critical or High-severity vulnerabilities, and requires engineer review of all AI-assisted code before merge.

Read More
Industry Insights Sep 30, 2026

Security Without Compromise: What the 2026 NSS Labs Cloud Network Firewall Tests Tell Us

The 2026 NSS Labs Comparative Test Report for Cloud Network Firewalls evaluated nine leading cloud-native and third-party firewalls under identical conditions, measuring security effectiveness, performance, TLS support, stability, and cost. As AI drives up encrypted traffic volumes and enables more evasive attacks, the results show that enterprises no longer have to trade protection against performance or cost. Versa NGFW earned NSS Labs’ “Recommended” rating for the second consecutive year, pairing 99.91% security effectiveness with the fastest rated throughput and the second-lowest cost per Mbps of any vendor tested.

Read More
Research Lab Sep 28, 2026

DLLHijackHunter: Validation-Driven Discovery and Confirmation of DLL Hijacking Paths on Windows

DLLHijackHunter is an open-source tool that finds real DLL hijacking vulnerabilities, not just theoretical ones. Its canary technique triggers the vulnerable program and captures proof the hijack worked, cutting through the noise of static scanners. Free on GitHub, it helps security teams focus on confirmed findings instead of guessing which candidates actually matter.

Read More
Security Sep 10, 2026

The New OWASP GenAI Top 10 and Why Network Security Matters

Almost every risk in the 2026 OWASP GenAI Top 10 leaves observable artifacts at the network layer. This post walks through all ten categories, real-world incidents behind each one, and the specific SASE controls (SWG, CASB, DLP, ZTNA, RBI) that catch what app-layer guardrails miss.

Read More
Security Jul 1, 2026

MITRE ATT&CK vs. MITRE ATLAS: Two Frameworks, One Expanding Threat Landscape

I have been in cyber security for over 25 years. And I have done my fair share of penetration testing/offensive security and I am quite familiar with the MITRE ATT&CK framework. Not long ago, I had the chance to dig into AI offensive security techniques hands-on. I assumed we would use the standard Kali-style hacking tools and follow the usual TTPs. I was wrong. We never fired up a Kali Linux instance or used a single tool from the past 30+ years. Instead, we learned how to trick the LLM into giving us information it was not supposed to. For…

Read More
Industry Insights May 13, 2026

CVE-2026-41940: Inside the cPanel/WHM Authentication Bypass

Introduction Hosting control panels operate with near-total authority over a server: websites, databases, DNS, email, and the account lifecycle are all driven from one place. That privilege makes them a high-value target—when a control-plane bug appears, compromise can extend far beyond a single site. CVE-2026-41940 is a pre-authentication bypass affecting WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared). In practical terms, it lets a remote, unauthenticated attacker reach administrator-level control without supplying valid credentials. Background: What Is cPanel/WHM? cPanel is a widely deployed, Linux-based hosting panel. WHM is the higher-privileged layer used by resellers and server administrators to…

Read More
Industry Insights May 11, 2026

The Ghost in the Leased Line: Unmasking MuddyWater, Surgical Cyber Arm

In the high-stakes theater of global geopolitics, the most effective weapons aren’t always missiles; sometimes, they are just few lines of code.

Read More
Industry Insights Apr 2, 2026

Identity Is the New Perimeter. Stryker Just Taught Us That the Hard Way.

A story on how an Iran-linked group wiped tens of thousands of Stryker’s devices A nation-state attack that changes every assumption we had For years, we have treated nation-state threats as a “Tier 1” problem — something reserved for defense contractors and the energy grid. The March 2026 attack on Stryker Corporation by Iran-linked group Handala officially kills that assumption. On March 11, 2026, Stryker’s corporate Microsoft environment was hit. Employees arrived to find their managed devices wiped out overnight through entirely legitimate Intune commands. Handala claimed 200,000+ systems affected; independent reporting confirms that tens of thousands were impacted. Stryker’s…

Read More
Industry Insights Mar 31, 2026

What is Workspace Security?

“What Is Workspace Security? Learn how Workspace Security, operating within the broader Secure Access Service Edge (SASE) framework, unites advanced security and networking technologies to safeguard users, devices, applications, and data. From enabling Zero Trust principles to incorporating tools like SWG, CASB, ZTNA, DLP, and DEM, explore how Workspace Security helps organizations protect distributed workforces while enabling productivity and collaboration. Discover why Versa is a leader in SASE innovation for modern enterprises.

Read More

The SolarWinds Hack: Understanding SolarStorm’s SUNBURST Backdoor

Jayesh Gangadas Patel
By Jayesh Gangadas Patel
Principle Threat Researcher, Versa Networks
December 21, 2020

FireEye recently provided information about the widespread attack campaign registered against components of the SolarWinds Orion platform. The SolarWinds Orion platform has a huge customer base of 300,000 clients and issued this advisory on Sunday, December 20th. In this blog post, we will focus on answering specific questions that organizations may have regarding the Solarwinds attack.

Emotet: The Silent, Pervasive Villain / The Return of Emotet: Time to Watch Out

The Versa Team
By The Versa Team
SASE Technical Professionals
April 23, 2020

After several weeks of quiet, especially during the Christmas holidays, the Emotet malware bot is up and running again, and it seems stronger and smarter. Several IT security firms have reported seeing phishing emails delivering Emotet via malicious Word documents and even delayed holiday e-greetings. Cyber-attackers using Emotet seem to have used this brief hiatus to improve the malware’s social engineering abilities, with almost a fourth of infected emails being sent as replies to existing email threads. Designed initially as a banking malware, the Emotet Trojan was first identified by security researchers in 2014. The malware delivery botnet spreads itself…

CVE-2020-0796 – A Potential SMB Attack in the Horizon

Winny Thomas
By Winny Thomas
Principal Security Architect
April 15, 2020

Server Message Block or SMB is a protocol used extensively by windows. It allows windows computers to communicate, locate file servers, locate and communicate with windows networks services and even communicate with other operating systems that understand the SMB protocol. The latest version of SMB is SMB version 3 which is affected. Over the years numerous vulnerabilities were discovered in the protocol which were actively exploited and used by malware authors to build ransomware, cryptominers, SCADA malware etc. MS08-067 saw the rise of the Conficker worm, MS10-061 was used by the infamous Stuxnet malware and MS17-061 was used by ransomware’s…

COVID-19 Ransomware Analysis

Winny Thomas
By Winny Thomas
Principal Security Architect
April 9, 2020

Versa Security Lab recently analyzed couple of malware samples which arrives on a computer through phishing emails containing documents with embedded link which eventually leads to the download of the malware. Some of these may arrive through websites pretending to provide information on the recent Corona virus outbreak. The past few months have seen several malicious webservers and domains being set up, purportedly serving information on the Covid-19 virus outbreak. Most of these sites are hosts to ransomware and other malware types. In this blog we are going to look at one sample which encrypts files contents and updates the…

New Report Reveals Top 10 Cryptomining Malware for 2018

The Versa Team
By The Versa Team
SASE Technical Professionals
December 17, 2018

Disruptive technologies, like blockchain, usher in new market opportunities, like cryptomining.  Whenever there is a growing trend, with the potential for financial gain, cyber criminals will invariably find ways to disrupt and distort these markets. Cryptomining is highly compute-intensive, using computer resources, such as CPU cycles, to mine “cryptocurrency”. Miners are paid for solving CPU intensive cryptographic challenges that validate each block of a transaction added to a cryptocurrency’s blockchain. They are paid a certain amount of cryptocurrency into their cryptocurrency wallet as commission for validating a transaction. . Anywhere there is a profit to be made, capable people will…

Fake Flash Updates Mine Monero Under the Hood

The Versa Team
By The Versa Team
SASE Technical Professionals
October 25, 2018

The recent surge in cryptomining is providing cyber criminals with more vectors to attack, at the expense of legitimate users. This year has seen a huge increase in the deployment of numerous malwares, with cryptominers as primary or secondary payloads. Cryptominers are becoming easy targets, that allow attackers to go a step further to disguise themselves as the miner in the form of a flash update. Palo Alto Networks reported a list of collected samples, some dating back to August 2018[1]. The author further adds that installers from the Adobe website were legitimate, and the malicious ones were mostly Windows…

GandCrab Ransomware

The Versa Team
By The Versa Team
SASE Technical Professionals
October 4, 2018

Ransomware is a form of malicious software that latches onto a system and encrypts the files within it, making them inaccessible to the user. The attackers behind this malicious activity typically demand payment in terms of currency (crypto or cash) in return for the keys to decrypt the files.  A recent ransomware which has become viral since January 2018 is named GandCrab. This ransomware is believed to be distributed as a Ransomware-as-a-Service [2,3]. GandCrab initially differentiated from other ransomware by demanding a ransom in DASH [7] cryptocurrency. The developers behind GandCrab have been continuously updating and releasing improved versions, with…

FIN7 — the New Avatar

Winny Thomas
By Winny Thomas
Principal Security Architect
November 2, 2017

Fin7 is a cybercrime group that employs spear phishing attacks to deliver malware that uses fileless malware techniques, sophisticated evasions and persistence. They mostly target the financial sector. In this blog, we are going to take a high-level look at one such sample seen in the wild, which employs several layers of obfuscated JScript, powershell and DLL embedded within a Microsoft Word document. The sample analyzed has the MD5 hash 29a3666cee0762fcd731fa663ebc0011. Through a series of deeply embedded base64 encoded scripts, obfuscated code and use of powershell, this strain achieves stealth and evasion. The document arrives as an email attachment in…

Apache Tomcat Remote Code Execution Vulnerability (CVE-2017-12617)

The Versa Team
By The Versa Team
SASE Technical Professionals
October 18, 2017

Several Security Vulnerability have been patched in recently in Apache Tomcat. The list of fixed flaws recently addressed also included code execution vulnerabilities. Apache Tomcat is the most widely used web application server, with over one million downloads per month and over 70% penetration in the enterprise datacenter. The Apache Tomcat development team publicly disclosed the presence of a remote code execution vulnerability, tracked as CVE-2017-12617, affecting the popular web application server. The Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 are affected. The vulnerability is classified as “important” severity, has been…

Apache: Failed to Harden in 2017

The Versa Team
By The Versa Team
SASE Technical Professionals
October 10, 2017

Apache’s gaps has been in news for quite a while, and this has led to the massive milestone of Equifax being compromised to the tune of 143 million records. This has been a difficult year for Apache, with so many vulnerabilities being reported. Refer to the link for a list of Apache vulnerabilities reported in 2017.  Though previous years also accounted for large chunks of Apache vulnerability, this year it has been in news for two particular vulnerabilities, CVE-2017-5638 (which led to the compromise of user data through the Equifax breach) and CVE-2017-9805 (due to the fact that the public…


Recent Posts













Gartner Research Report

2026 Gartner® Magic Quadrant™ for SASE Platforms

Versa has for the fourth consecutive year been recognized in the 2026 Gartner Magic Quadrant for SASE Platforms1 and is one of only 12 vendors that met the criteria for inclusion based on the analysts’ evaluation of the VersaONE Universal SASE Platform.