The Chinese state-sponsored group Salt Typhoon has targeted Canadian telecommunication companies, exploiting a critical Cisco vulnerability to breach devices. Authorities warn that such attacks are likely to continue, emphasizing the importance of network defense and remediation efforts. #SaltTyphoon #CVE-2023-20198
Keypoints
- Salt Typhoon exploited the CVE-2023-20198 flaw to target Canadian telecom providers in February 2025.
- The vulnerability allows attackers to escalate privileges and perform remote attacks on Cisco devices.
- Several network devices were compromised, enabling traffic interception and configuration modifications.
- Canadian organizations, especially critical infrastructure, remain vulnerable due to delayed patching.
- Salt Typhoon has targeted multiple industries worldwide, with ongoing reconnaissance and potential supply chain risks.