China’s Salt Typhoon hackers targeting Cisco devices used by telcos, universities
ID: b26b7f10-9d0e-5a7d-b590-973e6ba0f637
STIX ID: report--b26b7f10-9d0e-5a7d-b590-973e6ba0f637
Feed Name: The Record from Recorded Future News
Recorded Future’s Insikt Group detailed a Salt Typhoon campaign (attributed to Chinese state-linked actors) that in Dec–Jan scanned and attempted to compromise over 1,000 Cisco devices associated with telecommunications providers worldwide, successfully compromising at least seven devices across the U.S., South Africa, Italy and Thailand. The attackers exploited CVE-2023-20198 and CVE-2023-20273 to gain and escalate access, reconfigured devices for persistence, and allegedly accessed call records of high-profile political figures; U.S. agencies and the Treasury have taken notice and imposed sanctions related to the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
