logo

Salt Typhoon: An Analysis of Vulnerabilities Exploited by this State-Sponsored Actor

ID: 8c023f2a-136b-57be-836d-329d2e32b34a

STIX ID: report--8c023f2a-136b-57be-836d-329d2e32b34a

Feed Name: Tenable Blog

Threat Score
90/100

Date Published: 2025-01-23

Date Updated: 2026-05-01

Author: Scott Caveza

...
...

**Executive Summary:** Tenable Research examines Salt Typhoon, a PRC-affiliated APT that breached at least nine U.S. telecommunications companies in 2024, detailing exploited high-severity CVEs (e.g., CVE-2021-26855, CVE-2022-3236, CVE-2023-48788, CVE-2024-21887, CVE-2023-46805), post-compromise malware and persistence techniques, and providing detection and mitigation guidance including patching, hardening Cisco devices, and Tenable scanning recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.