Light

Episode #1031 Quiz

How Salt Typhoon Gets In
Date: 2025-06-24 | Length: 2.75 hrs | Episode page at twit.tv

About this episode

Episode 1031 details China’s Salt Typhoon cyber espionage exploiting outdated Cisco IOS XE vulnerabilities, notably CVE-2018-0171 (CVSS 9.8) and CVE-2023-20198 (CVSS 10.0), to infiltrate telecom providers for years. Attackers obtained credentials, pivoted between networks, modified device configs, and exfiltrated data via remote packet captures, highlighting critical patching failures and insecure management policies.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what is the primary reason Salt Typhoon was able to maintain persistent access to multiple telecommunications networks for years?
Question 2: What Cisco device configuration modification technique did Salt Typhoon use to evade detection and access other network devices?
Question 3: Regarding the 2023 CVE-2023-20198 vulnerability exploited by Salt Typhoon, what is its CVSS score and what does that imply about its severity?
Question 4: What key failure in Cisco's device design philosophy does the episode critique as contributing to Salt Typhoon's success?
Question 5: What operational capabilities were observed by Cisco Talos in Salt Typhoon's custom tool 'JumbledPath' used on compromised Cisco devices?
Cancel