The Persistent Threat of Salt Typhoon: Tracking Exposures of Potentially Targeted Devices
Salt Typhoon, a Chinese state-sponsored threat actor, has been targeting major telecommunications providers worldwide by exploiting vulnerabilities in network devices. This analysis tracks global exposures of internet-facing devices associated with Salt Typhoon activity over six months, including Sophos Firewalls, Cisco IOS XE WebUIs, Ivanti Connect Secure, and Fortinet FortiClient EMS systems. Overall combined exposure decreased by 25%, with Sophos Firewall interfaces showing the largest reduction. Cisco IOS XE was the only platform with increased exposure. Geographically, most exposures remain concentrated in the United States, except for Sophos XG Firewall exposures in Germany. The persistence of exposed devices raises questions about remediation efforts and organizational responses to these threats.
Pulse ID: 680c3c41a960b91fa23ec72d
Pulse Link: https://otx.alienvault.com/pulse/680c3c41a960b91fa23ec72d
Pulse Author: AlienVault
Created: 2025-04-26 01:52:01
Be advised, this data is unverified and should be considered preliminary. Always do further verification.