Find notable cyber news and cases, enriched with sources, timelines, and signals.

Salt Typhoon persistent espionage campaign targeting global networks

Campaign
First reported
Last updated
Happening score
H score 46
1 unique sources, 2 articles

Summary

Hide ▲

Salt Typhoon remains a long-running espionage campaign targeting telecommunications, government, transportation, lodging, and military infrastructure. A 13-country advisory said the group has been active since at least 2019, gains access through exposed Cisco, Ivanti, and Palo Alto Networks edge devices, and then uses router changes, GRE tunnels, ACL edits, and TACACS+ traffic capture to retain access and steal credentials. Reporting cited in the advisory says the activity has affected 600+ organizations across 80 countries, including 200 in the U.S. A later analysis added 45 previously unreported domains tied to Salt Typhoon and UNC4841, with infrastructure dating back to May 2020 and overlap with CVE-2023-2868.

Related Happenings

China-nexus hijacked-device proxy network campaign

Campaign
H score43 First: 23.04.2026 15:28 Last: 23.04.2026 15:28 Sources 1

About this happening: NCSC-UK and international partners warned on 2026-04-23 that China-nexus hackers are using large-scale proxy networks built from hijacked consumer devices, including *...

Storm-1175 high-velocity exploit campaign

Campaign
H score59 First: 06.04.2026 19:56 Last: 06.04.2026 19:56 Sources 1

About this happening: Storm-1175 is running a high-velocity exploit campaign that rapidly turns access into Medusa ransomware deployment, creating risk of data exfiltration and encrypte...

Red Menshen telecom espionage campaign

Campaign
H score33 First: 26.03.2026 19:40 Last: 26.03.2026 19:40 Sources 1

About this happening: A China-nexus Red Menshen operation has sustained covert access in telecom networks across the Middle East and Asia, increasing the risk of government espion...

MuddyWater U.S. network intrusion campaign targeting banks, airports, and a software company arm

Campaign
H score42 First: 06.03.2026 12:23 Last: 06.03.2026 12:23 Sources 1

About this happening: MuddyWater (Seedworm) is running a state-linked intrusion campaign that has embedded itself in U.S. banks, airports, a non-profit, and an Israeli software company arm,...

Middle East retaliatory hacktivist DDoS campaign

Campaign
H score29 First: 04.03.2026 19:21 Last: 04.03.2026 19:21 Sources 1

About this happening: A retaliatory hacktivist DDoS campaign has surged across the Middle East, creating broad disruption risk for government and public-infrastructure targets. Research...

Timeline

  1. 28.08.2025 17:04 3 articles · 10mo ago

    Salt Typhoon targets exposed edge devices across global telecom and critical networks

    Campaign Scope Update

    Authorities from 13 countries said Salt Typhoon continued targeting telecommunications, government, transportation, lodging, and military infrastructure networks, with initial access gained through exposed Cisco, Ivanti, and Palo Alto Networks edge devices and follow-on activity that included router modification, GRE tunnels, ACL changes, and TACACS+ traffic capture for credential theft and lateral movement. The campaign was also linked to three Chinese entities and described as active since at least 2019, with reporting that the activity has affected 600+ organizations across 80 countries, including 200 in the U.S.

    Show sources