Silk Typhoon shifted to specifically targeting IT management companies
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) |
Full article636 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Chinese state-backed espionage group started targeting third-party IT services in late 2024, Microsoft researchers said.
Listen to this article
0:00
Learn more.
The Chinese state-backed threat group Silk Typhoon shifted tactics in late 2024 to broaden access and enable follow-on attacks against downstream customers of its initial targets, Microsoft Threat Intelligence said in a blog released Wednesday.
The Chinese espionage group, which is also known as APT27, has abused stolen API keys and credentials for privileged access management, cloud-based application providers and data management companies to intrude networks operated by state and local governments and organizations in the IT sector.
“After successfully compromising a victim, Silk Typhoon uses the stolen keys and credentials to infiltrate customer networks where they can then abuse a variety of deployed applications, including Microsoft services and others, to achieve their espionage objectives,” Ann Johnson, corporate vice president at Microsoft Security, said in a LinkedIn post.
Silk Typhoon has performed reconnaissance aided by using stolen API keys and leaked corporate passwords found on publicly-accessible sites like GitHub. This has allowed them to access administrative accounts and steal data from edge devices.
Microsoft Threat Intelligence said it observed Silk Typhoon gained access through password-spray attacks, zero-day exploits, and unpatched third-party services. Recently, the threat group exploited a critical, zero-day vulnerability — CVE-2025-0282 — in Ivanti Pulse Connect VPN.
Silk Typhoon has primarily set its sights on gaining access to IT providers, identity management platforms, privileged access management and remote monitoring and management tools, researchers said.
The group moves from on-premises to cloud environments by stealing Active Directory credentials, accessing passwords in key vaults, and targeting Entra Connect servers, a tool organizations use to synchronize on-premises Active Directory databases with Entra ID, to escalate privileges.
Microsoft Threat Intelligence also observed Silk Typhoon abusing OAuth applications with administrative permissions to steal email, OneDrive and SharePoint data via MSGraph.
The threat group’s technical prowess, displayed by its ability to pivot quickly and exploit vulnerabilities with efficiency, gives it “one of the largest targeting footprints among Chinese threat actors,” Microsoft Threat Intelligence said in the blog.
Researchers link Silk Typhoon to attacks targeting IT services, managed service providers, and organizations in the energy, healthcare, higher education, legal, defense and government sectors.
Microsoft released its latest research on Silk Typhoon as a flurry of unsealed indictments charged 12 Chinese nationals for their alleged involvement in a vast espionage campaign, including multiple attacks on U.S. government agencies. Two alleged members of Silk Typhoon, Yin Kecheng and Zhou Shuai, were among those indicted by federal prosecutors on Wednesday.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/silk-typhoon-targets-it-services/