惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
云风的 BLOG
云风的 BLOG
IT之家
IT之家
C
Check Point Blog
T
The Blog of Author Tim Ferriss
S
SegmentFault 最新的问题
人人都是产品经理
人人都是产品经理
H
Hackread – Cybersecurity News, Data Breaches, AI and More
美团技术团队
M
MIT News - Artificial intelligence
Jina AI
Jina AI
Blog — PlanetScale
Blog — PlanetScale
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Microsoft Security Blog
Microsoft Security Blog
G
Google Developers Blog
F
Fortinet All Blogs
V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
MyScale Blog
MyScale Blog
爱范儿
爱范儿
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)

DomainTools Investigations | SecuritySnacs

Cybersecurity Reading List - Week of 2026-08-17 SecuritySnack - Account Farmers and Sellers Scarcity Scams SecuritySnack - Hijacking Corporate Sessions Cybersecurity Reading List - Week of 2026-06-01 Cybersecurity Reading List - Week of 2026-05-04 DPRK Contagious Interview: Developer Workflow Compromise The AI Frame Campaign Continues Cybersecurity Reading List - Week of 2026-04-06 SecuritySnack - OpenAI Anti-Ads Malware SecuritySnack - CloudFlare Anti-Security For Phishing Cybersecurity Reading List - Week of 2026-03-02 SecuritySnack - Idolized Crypto Scams Cybersecurity Reading List - Week of 2026-02-02 SecuritySnack: Phishing Interviews Pay to Lose: Dubious Online Gambling Games SecuritySnack: Repo The Repo - NPM Phishing Banker Trojan Targeting Indonesian and Vietnamese Android Users SecuritySnack: 18+E-Crime Cybersecurity Reading List - Week of 2026-01-05 Hunting for Malware Networks TrickBot the Unperturbed Silicon Valley Bank B2B2C Supply Chain Attack: Hotel’s Booking Accounts Compromised to Target Customers .GA Moves Away from FreeNom Cybersecurity Reading List - Week of 2025-03-04 Cybersecurity Reading List - Week of 2025-06-16 Cybersecurity Reading List - Week of 2025-05-19 "airdrop" Domain Bloom Cybersecurity Reading List - Week of 2025-04-21
Salt Typhoon - Research Brief
DomainTools · 2026-01-05 · via DomainTools Investigations | SecuritySnacs

Executive Summary: 

  • PRC cyber threat actors dubbed "Salt Typhoon" (as well as FamousSparrow and GhostEmperor) appear to be focused on infiltrating Internet Service Providers (ISPs) at this time.
    • Why is this important? “If hackers gained access to service providers’ core routers, it would leave them in a powerful position to steal information, redirect internet traffic, install malicious software or pivot to new attacks.”
  • Unlike similar threat actor groups that include the name "Typhoon," Salt Typhoon looks to be geared towards intelligence collection as opposed to creating backdoors for the purpose of being an Advanced Persistent Threat (APT.)
  • Suggestions for network defense include
    • Identify and mitigate living off the land techniques that could provide threat actors with an opportunity to infiltrate an enterprise network. (CISA resource)
    • Locate and remove or isolate unused and/or unpatchable legacy systems.
  • Potential link to “shadow C2 infrastructure”
    • By having access to the Internet Service Provider of an enterprise network, a threat actor could manipulate the network from the inside.


Highlights:

- Binary Defense revealed details of how it uncovered PRC state-sponsored cyber actors inside a global aerospace engineering firm's network where they had been snooping around for four months. 

- "I can't really comment on the connection between the incidents, but I can say that given the uptick in Chinese-linked attacks against critical infrastructure supply chains, ISPs, and core internet devices there is a clear strategy at play where attackers are aiming to identity and exploit logical choke points in our society to take control of the flow of information and supplies," Binary Defense Director of Security Research John Dwyer told The Register today when asked about a possible Salt Typhoon connection.

- As recently as August, another Typhoon gang — Volt Typhoon — was accused of hiding in American networks after exploiting a high-severity bug in Versa's SD-WAN software.

- WSJ article states Salt Typhoon threat actors attempt to gain critical data from broadband service providers, has been going on for months and has been linked to China by U.S. government investigators. The reason for targeting broadband providers, in particular, is to take control of those providers’ systems and, from there, access their data and possibly launch a separate cyberattack from within their networks.  

- CISA Executive Assistant Director for Cybersecurity Jeff Greene told us the agency is aware of the report of the compromised ISPs, and said that China is known to be infiltrating all manner of critical targets, who have compromised the IT environments across multiple critical infrastructure sectors and organizations.

- China's Salt Typhoon cyber spies spotted deep inside US ISPs
Activity is confirmed, govt aid provided.
No advisory on mitigations for customers at this time

Resources:

Chinese spies spent months inside aerospace engineering firm's network via legacy IT
(The Register, 18 September 2024)
https://www.theregister.com/2024/09/18/chinese_spies_found_on_us_hq_firm_network

China's Salt Typhoon cyber spies are deep inside US ISPs
(The Register, 25 September 2024)
https://www.theregister.com/2024/09/25/chinas_salt_typhoon_cyber_spies

China-Linked Hackers Breach U.S. Internet Providers in New ‘Salt Typhoon’ Cyberattack
(The Wall Street Journal, 26 September 2024)
https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835

China-linked APT group Salt Typhoon compromised some U.S. internet service providers (ISPs)
(Security Affairs, 26 September 2024) – see graphic below
https://securityaffairs.com/168941/apt/salt-typhoon-china-linked-threat-actors-breached-us-isp.html 

Salt Typhoon Cyberattack Targets U.S. Broadband Service Provider
(TeleCompetitor, 27 September 2024)
https://www.telecompetitor.com/salt-typhoon-cyberattack-targets-u-s-broadband-service-providers/

Image Source: China-linked APT group Salt Typhoon compromised some U.S. internet service providers (ISPs) Security Affairs, 26 September 2024

Cybersecurity Reading List - Week of 2026-06-01

Commentary followed by links to cybersecurity articles and resources that caught our interest internally.

SecuritySnack - Hijacking Corporate Sessions

A sophisticated AiTM phishing kit bypassing traditional MFA to steal Microsoft 365 session cookies. Get the full breakdown and IOCs.

Cybersecurity Reading List - Week of 2026-05-04

Systems thinking, biolistics, and the danger of mop-up science in infosec — plus this month's reading on ransomware, RPKI exploits, cPanel, and LLM pollution.