The Persistent Threat of Salt Typhoon: Tracking Exposures of Potentially Targeted Devices
Essential information
- Published
- 26/04/2025 01:52
- Modified
- 28/04/2025 08:52
- Tags
- 2025-04-26 CVE-2022-3236 CVE-2023-20198 CVE-2023-20273 CVE-2023-46805 CVE-2023-48788 CVE-2024-21887 chinese state-sponsored cisco ios xe exposure tracking fortinet forticlient ems ivanti connect secure masol rat network devices shadowpad sophos firewall telecommunications vulnerability exploitation
- Related entities
- 1 intrusion sets (apt), 16 techniques (mitre), 3 malware, 4 others
Description
Salt Typhoon, a Chinese state-sponsored threat actor, has been targeting major telecommunications providers worldwide by exploiting vulnerabilities in network devices. This analysis tracks global exposures of internet-facing devices associated with Salt Typhoon activity over six months, including Sophos Firewalls, Cisco IOS XE WebUIs, Ivanti Connect Secure, and Fortinet FortiClient EMS systems. Overall combined exposure decreased by 25%, with Sophos Firewall interfaces showing the largest reduction. Cisco IOS XE was the only platform with increased exposure. Geographically, most exposures remain concentrated in the United States, except for Sophos XG Firewall exposures in Germany. The persistence of exposed devices raises questions about remediation efforts and organizational responses to these threats.