Canada says Salt Typhoon hacked telecom firm via Cisco flaw

Canada says Salt Typhoon hacked telecom firm via Cisco flaw

The Chinese state-sponsored group Salt Typhoon has targeted Canadian telecommunication companies, exploiting a critical Cisco vulnerability to breach devices. Authorities warn that such attacks are likely to continue, emphasizing the importance of network defense and remediation efforts. #SaltTyphoon #CVE-2023-20198

Keypoints

  • Salt Typhoon exploited the CVE-2023-20198 flaw to target Canadian telecom providers in February 2025.
  • The vulnerability allows attackers to escalate privileges and perform remote attacks on Cisco devices.
  • Several network devices were compromised, enabling traffic interception and configuration modifications.
  • Canadian organizations, especially critical infrastructure, remain vulnerable due to delayed patching.
  • Salt Typhoon has targeted multiple industries worldwide, with ongoing reconnaissance and potential supply chain risks.

Read More: https://www.bleepingcomputer.com/news/security/canada-says-salt-typhoon-hacked-telecom-firm-via-cisco-flaw/