The FBI, along with cybersecurity agencies from the United States, the United Kingdom, Canada, Germany, Italy, Japan, and other allied nations, has publicly identified a Chinese government-backed hacking group known as Salt Typhoon. This cyber espionage campaign has targeted over 600 organizations across more than 80 countries, including at least 200 U.S. companies. The attacks have primarily focused on telecommunications networks but have also extended to transport, military, and government agencies. Salt Typhoon exploited vulnerabilities in products from Cisco, Ivanti, Palo Alto Networks, and Citrix NetScaler, with the latter's critical zero-day remote code execution flaw (CVE-2025-7775) remaining unpatched in over 28,000 instances worldwide. The group’s activities included infiltrating networks, stealing personal data of millions of Americans, surveilling private communications, and tracking individuals globally. An international coalition has formally called out three Chinese private technology companies for their alleged involvement in facilitating these cyberattacks. More than 20 government agencies have issued a joint cyber advisory urging companies and governments to actively hunt for and defend against Salt Typhoon threat actors. The FBI and partner agencies continue to share technical details to assist organizations in protecting their systems from this ongoing threat.
CISA, FBI, NSA Warn of Chinese 'Global Espionage System': https://t.co/82jQuFYq7q by darkreading #infosec #cybersecurity #technology #news
Transport, telecoms, military, and government agencies have been targeted by the Salt Typhoon group, and things might only get worse. https://t.co/6tl5TfxqOH
International coalition calls out three Chinese companies over hacking campaign https://t.co/XFOLSN4zdv https://t.co/XFOLSN4zdv