meta_pixel
Tapesearch Logo
Log in
CyberWire Daily

Velvet Ant's silent invasion. [Research Saturday]

CyberWire Daily

N2K Networks, Inc.

News, Tech News, Daily News, Technology

4.81.1K Ratings

🗓️ 2 November 2024

⏱️ 20 minutes

🧾️ Download transcript

Summary

This week, we are joined by, Amnon Kushnir from Sygnia, who is sharing their work on "China-Nexus Threat Group ‘Velvet Ant’ Leverages a Zero-Day to Deploy Malware on Cisco Nexus Switches." In early 2024, Sygnia observed the ‘Velvet Ant’ threat group exploiting a zero-day vulnerability (CVE-2024-20399) to infiltrate Cisco Switch appliances and operate undetected within enterprise networks. This attack enables threat actors to escape Cisco’s command interface and install malware directly on the device’s OS, bypassing standard security tools. The incident underscores the risks posed by third-party appliances and the importance of enhanced monitoring and threat detection to counter advanced persistent threats. The research can be found here: China-Nexus Threat Group ‘Velvet Ant’ Leverages a Zero-Day to Deploy Malware on Cisco Nexus Switches Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript

Click on a timestamp to play from that location

0:00.0

You're listening to the Cyberwire Network, powered by N2K.

0:09.7

Around every entry point and every clever attacker, Vectra sees the attacks others can't.

0:18.6

How?

0:19.4

Vectra has AI on it.

0:21.6

Vectra's AI attacks signal intelligence, tells security teams where to focus, what matters.

0:27.6

It wades through thousands of individual threat events, so you don't have to.

0:32.6

Attackers infiltrating your network?

0:34.6

Vectra has AI on it.

0:36.6

Attackers compromising your identities. Vectra has AI on it. Attackers compromising your identities.

0:39.5

Vectra has AI on it.

0:41.8

Vectra AI, the integrated signal powering your XDR.

0:46.3

Visit Vectra.aI slash show me to learn more.

0:50.4

That's VECTRA.a.a.a.i slash show me to learn more. That's V-E-C-T-R-A-D-A-I-S-Sh-M-E-T-R-A-I-S-SH-M-E-T-R-M-E-T-R-E-L-E-E-R-E-R-E-R-E-R-E-R-E-R-E-R-E-R-E-R-E-R-E-R-E-R-R-E-R-R-E-R-R Hello everyone and welcome to the CyberWires Research Saturday.

1:11.3

I'm Dave Bittner, and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities,

1:18.8

solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace.

1:24.6

Thanks for joining us.

1:31.3

Thank you. cyberspace. Thanks for joining us. What started as an incident with another threat actor evolved into another incident

1:38.4

with another threat actor in the same environment. So it was an interesting turnoff of events, I would say.

1:47.8

That's Amnam Kushner, director of incident response at Signea.

1:52.3

The research we're discussing today is titled China Nexus Threat Group Velvet Ant

1:57.0

leverages a Zero Day to deploy malware on Cisco Nexus switches.

2:09.6

And then we came across Velvet Ant as part of our post-British monitoring and research.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from N2K Networks, Inc., and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of N2K Networks, Inc. and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.