Threat Intelligence Research: Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days
ID: beaecb00-03c7-52c2-bfb0-5e5755c511a7
STIX ID: report--beaecb00-03c7-52c2-bfb0-5e5755c511a7
Feed Name: SecurityScorecard Blog
SecurityScorecard STRIKE reports that Volt Typhoon (a China‑linked state‑sponsored threat actor) is leveraging compromised SOHO/network‑edge devices—primarily Cisco RV320/325 routers—to build covert infrastructure for data transfer and possible access to target networks; researchers observed communication between many Cisco devices and known Volt Typhoon IoCs across multiple regions, highlighted the risk posed by end‑of‑life devices, and recommended identifying vulnerable devices, upgrading unsupported hardware, and continuous monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
