Salt Typhoon remains active, hits more telecom networks via Cisco routers
ID: 29616b99-d20d-5ea5-8ae7-6e8d73f2719f
STIX ID: report--29616b99-d20d-5ea5-8ae7-6e8d73f2719f
Feed Name: CyberScoop
Salt Typhoon (aka RedMike), a Chinese nation-state actor, is actively exploiting two critical Cisco IOS XE vulnerabilities (CVE-2023-20198 and CVE-2023-20273) to create accounts and gain root on internet-exposed routers used by telecom providers worldwide. Recorded Future observed compromised Cisco devices communicating with Salt Typhoon infrastructure across multiple telecom networks — including U.S. providers — and the campaign demonstrates large scale, targeted intrusions against critical communications infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
