Cisco Confirms Salt Typhoon Exploitation in Telecom Hits
ID: 332d1290-cd74-5287-938e-9d8332b36fdb
STIX ID: report--332d1290-cd74-5287-938e-9d8332b36fdb
Feed Name: Dark Reading
Date Published: 2025-02-21
Date Updated: 2026-05-05
Author: Kristina Beek, Associate Editor, Dark Reading
Cisco confirmed that Salt Typhoon (a sophisticated Chinese APT) exploited CVE-2018-0171 and used stolen credentials to compromise major U.S. telecommunications providers (including T‑Mobile, AT&T, and Verizon), maintaining long-term access enabling configuration exfiltration, pivoting, and modification; Cisco also reported that the actor is abusing additional known CVEs (CVE-2023-20198, CVE-2023-20273, CVE-2024-20399) and recommends immediate patching and improved credential hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
