The attacks, which began no later than June 12 and are likely ongoing, allow the threat actors to install "VersaMem,” the name Lumen gave to a custom web shell that gives remote administrative control of Versa Director systems.
Black Lotus didn’t identify any of the affected ISPs, MSPs, or downstream customers.
The vulnerability resides in the Versa Director, a virtualization platform that allows ISPs and managed service providers to manage complex networking infrastructures from a single dashboard, researchers from Black Lotus Labs, the research arm of security firm Lumen, said
https://blog.lumen.com/taking-the-crossroads-the-versa-director-zero-day-exploitation/