Silk Typhoon targeting IT supply chain
ID: dc7f998c-7790-5d1f-ab85-8e1b70af516b
STIX ID: report--dc7f998c-7790-5d1f-ab85-8e1b70af516b
Feed Name: Microsoft Security
Microsoft Threat Intelligence details Silk Typhoon — a well-resourced Chinese state-aligned espionage actor — describing how the group exploits zero-days and unpatched remote management, VPN, and cloud-related products, abuses stolen API keys and credentials to access downstream customer tenants, moves laterally into cloud environments (including targeting Entra/AADConnect and service principals), and exfiltrates sensitive email and SharePoint data; the report provides observed CVEs, IoCs, detection queries, and specific mitigation and hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
