Chinese hackers breach more US telecoms via unpatched Cisco routers
ID: a58d39e8-d0d3-5791-8119-3667625a3226
STIX ID: report--a58d39e8-d0d3-5791-8119-3667625a3226
Feed Name: Bleeping Computer
Recorded Future's Insikt Group reports that China-linked Salt Typhoon (RedMike) has actively exploited CVE-2023-20198 and CVE-2023-20273 against internet-exposed Cisco IOS XE devices to breach multiple telecommunications providers globally, including U.S. carriers; attackers reconfigured compromised devices to create GRE tunnels for persistent access, with over 1,000 devices targeted and thousands of Cisco web UIs found exposed — defenders are urged to apply patches and avoid exposing admin interfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
