If you thought China's Salt Typhoon was booted off critical networks, think again
ID: fc54a954-b1c3-5a68-8430-6510cbb3b6da
STIX ID: report--fc54a954-b1c3-5a68-8430-6510cbb3b6da
Feed Name: The Register (Security)
A multinational advisory warns that Salt Typhoon, a China-aligned persistent threat actor active since at least 2019, conducted widespread cyber-espionage against telecommunications, government, transportation, lodging, and military infrastructure—compromising backbone, PE and CE routers to geo-locate subscribers, capture traffic and recordings, and pivot across networks. The alert attributes operations to affiliated Chinese entities, lists commonly exploited CVEs (including CVE-2024-21887, CVE-2024-3400, CVE-2023-20273, CVE-2023-20198, CVE-2018-0171), describes persistence and lateral movement techniques, and notes participation by international agencies and private responders in remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
