A China-linked threat group known as Velvet Ant has exploited a zero-day vulnerability (CVE-2024-20399) in Cisco Nexus switches to gain unauthorized control and evade detection. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability, along with security flaws in Dahua IP cameras and Linux Kernel, to its Known Exploited Vulnerabilities catalog. The exploitation of these vulnerabilities highlights ongoing cybersecurity threats posed by Chinese threat actors, particularly in relation to critical infrastructure and technology systems.
Chinese Hackers Exploit Zero-Day Cisco Switch Flaw to Gain System Control https://t.co/Qf1fTFl30y #cybersecurity
China-Linked ‘Velvet Ant’ Hackers Exploited Zero-Day to Deploy Malware on Cisco Nexus Switches #cybersecurity https://t.co/DOUQLj8G7x
China-linked APT Velvet Ant exploited zero-day to compromise Cisco switches: https://t.co/DDQPqkuXkd by Security Affairs #infosec #cybersecurity #technology #news