logo

Salt Typhoon remains active, hits more telecom networks via Cisco routers

ID: 29616b99-d20d-5ea5-8ae7-6e8d73f2719f

STIX ID: report--29616b99-d20d-5ea5-8ae7-6e8d73f2719f

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2025-02-13

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Salt Typhoon (aka RedMike), a Chinese nation-state actor, is actively exploiting two critical Cisco IOS XE vulnerabilities (CVE-2023-20198 and CVE-2023-20273) to create accounts and gain root on internet-exposed routers used by telecom providers worldwide. Recorded Future observed compromised Cisco devices communicating with Salt Typhoon infrastructure across multiple telecom networks — including U.S. providers — and the campaign demonstrates large scale, targeted intrusions against critical communications infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.