logo

Salt Typhoon Exploits Cisco Devices in Telco Infrastructure

ID: 5db7dfde-2315-573e-bf7a-2c9721bd612b

STIX ID: report--5db7dfde-2315-573e-bf7a-2c9721bd612b

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-02-14

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Salt Typhoon (also tracked as RedMike/UNC2286) has been observed exploiting two Cisco IOS XE vulnerabilities (CVE-2023-20198 and CVE-2023-20273) to compromise over a thousand network devices across telcos, ISPs, and universities globally; the group used GRE tunnels for persistence and data exfiltration, posing significant risk to critical communications infrastructure and sensitive research networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.