logo

More victims of China's Salt Typhoon crew emerge: Telcos just now hit via Cisco bugs

ID: 51af1eee-4d24-501f-bf78-03df32195a26

STIX ID: report--51af1eee-4d24-501f-bf78-03df32195a26

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-02-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Recorded Future's Insikt Group reports that the China-linked Salt Typhoon (RedMike) actor scanned and attempted to exploit over 1,000 internet-facing Cisco devices and successfully compromised at least seven unpatched routers/switches across global telecommunications providers and other organizations in Dec 2024–Jan 2025 by chaining CVE-2023-20198 and CVE-2023-20273 to escalate to root and establish persistent GRE tunnels, exposing sensitive communications and network data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.