logo

The Persistent Threat of Salt Typhoon: Tracking Exposures of Potentially Targeted Devices

ID: de016929-9a89-5f81-993b-1277108d0abc

STIX ID: report--de016929-9a89-5f81-993b-1277108d0abc

Feed Name: Censys Blog

Threat Score
85/100

Date Published: 2025-04-25

Date Updated: 2026-04-27

Author: Ivonne Francia; The Censys Research Team

...
...

This report examines Salt Typhoon (aka FamousSparrow/RedMike/UNC2286) activity and the global exposure of internet-facing network devices tied to their campaigns, analyzing high-severity vulnerabilities (Sophos XG CVE-2022-3236, Cisco IOS XE CVE-2023-20198/20273, Ivanti CVE-2023-46805/CVE-2024-21887, FortiClient EMS CVE-2023-48788), six-month exposure trends (overall exposure down ~25% driven by Sophos reductions but Cisco exposures slightly up), geographic concentrations (notably U.S. and Germany), and operational risks from both active exploitation and credential theft that can enable persistent access to telecommunications and government networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.