logo

Canada says Salt Typhoon hacked telecom firm via Cisco flaw

ID: 436ff5a7-72c5-52be-90a6-b95c9472a8c3

STIX ID: report--436ff5a7-72c5-52be-90a6-b95c9472a8c3

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-06-23

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The Canadian Centre for Cyber Security and the FBI report that the Chinese state-sponsored group 'Salt Typhoon' exploited the critical Cisco IOS XE vulnerability CVE-2023-20198 to compromise at least three network devices at a Canadian telecommunications provider in February 2025, retrieving running configurations and modifying one to create a GRE tunnel for traffic collection; the bulletin also links Salt Typhoon activity to prior breaches of multiple global telcos, highlights ongoing reconnaissance targeting telecoms and other sectors, and urges immediate edge-device hardening and patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.