The Persistent Threat of Salt Typhoon: Tracking Exposures of Potentially Targeted Devices
ID: de016929-9a89-5f81-993b-1277108d0abc
STIX ID: report--de016929-9a89-5f81-993b-1277108d0abc
Feed Name: Censys Blog
Date Published: 2025-04-25
Date Updated: 2026-04-27
Author: Ivonne Francia; The Censys Research Team
This report examines Salt Typhoon (aka FamousSparrow/RedMike/UNC2286) activity and the global exposure of internet-facing network devices tied to their campaigns, analyzing high-severity vulnerabilities (Sophos XG CVE-2022-3236, Cisco IOS XE CVE-2023-20198/20273, Ivanti CVE-2023-46805/CVE-2024-21887, FortiClient EMS CVE-2023-48788), six-month exposure trends (overall exposure down ~25% driven by Sophos reductions but Cisco exposures slightly up), geographic concentrations (notably U.S. and Germany), and operational risks from both active exploitation and credential theft that can enable persistent access to telecommunications and government networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
