Researchers reported that internet-facing devices tied to Salt Typhoon, a Chinese state-sponsored threat actor linked to intrusions in telecommunications and government environments, remain widely exposed even after a modest overall decline in attack surface. Tracking six months of exposure data for Sophos Firewall, Cisco IOS XE Web UI, Ivanti Connect Secure, and Fortinet FortiClient EMS showed a combined 25% reduction, driven largely by a sharp drop in Sophos Firewall exposure, while Ivanti and Fortinet changed little and a substantial number of systems remained reachable from the internet.
The reporting also found that Cisco IOS XE was the only monitored platform to post a net increase in exposure, underscoring continued risk around internet-facing edge infrastructure that can provide direct access into internal networks. Analysts cautioned that attribution remains difficult and confirmed Salt Typhoon indicators are limited, but said the affected technologies should remain high-priority because the group has been associated not only with vulnerability exploitation but also with the use of stolen credentials in some Cisco-related incidents; most observed exposures were concentrated in the United States, while Sophos Firewall exposure was concentrated in Germany.

Map this exposure pattern across your cloud, code, and identities.
7 events from the most recent confirmed update back to the earliest known activity.
As of April 22, 2025, Censys observed Germany leading exposed Sophos Firewall instances with 38,787, versus 16,589 in the United States, while the United States had 7,778 exposed Cisco IOS XE Web UIs.
By April 2025, Censys found combined exposure across the tracked platforms had fallen 25% since October 2024, driven mainly by a drop of more than 70,000 exposed Sophos Firewall interfaces. Cisco IOS XE was the only tracked platform to increase, while Ivanti Connect Secure and FortiClient EMS declined slightly.
Talos observed that in most incidents involving Cisco devices, attackers gained access through stolen credentials rather than vulnerability exploitation, indicating patched internet-facing devices could still remain at risk.
Censys began a six-month analysis window tracking internet exposure of Sophos Firewall, Cisco IOS XE Web UI, Ivanti Connect Secure, and Fortinet FortiClient EMS systems associated in public reporting with Salt Typhoon targeting.
Ivanti Connect Secure and Policy Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 were identified as enabling authentication bypass and elevated command execution, respectively.
Cisco IOS XE vulnerabilities CVE-2023-20198 and CVE-2023-20273 were publicly identified as flaws that can be chained to gain full control of vulnerable devices via the Web UI.
Recorded Future reported that RedMike, identified here with Salt Typhoon, attempted to exploit more than 1,000 internet-facing Cisco network devices worldwide, primarily at telecommunications providers, using CVE-2023-20198 and CVE-2023-20273. After exploitation, the actor changed device configurations and established GRE tunnels for persistence.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.