Salt Typhoon's Telecom Infiltration: A Two-Year Campaign in the Backbone
Salt Typhoon
TWO YEARS
INSIDE
Threat Intelligence
Threat Intelligence

Salt Typhoon’s Telecom Infiltration: A Two-Year Campaign in the Backbone

An account of Salt Typhoon's two-year infiltration campaign within the telecom backbone.
S2
SecureW2 Threat Intelligence
May 20, 2026
· 1 min read

An account of Salt Typhoon’s two-year infiltration campaign within the telecom backbone.

  • The campaign is described as spanning roughly two years.
  • It targeted infrastructure within the telecom backbone.
  • It is tracked as advanced persistent threat (APT) activity.

This briefing is part of SecureW2’s Cybersecurity Intelligence series, which tracks identity, certificate, and network-security events for the teams who have to respond to them.

S2

SecureW2 Threat Intelligence

SIGNAL's threat-intelligence desk tracks identity, certificate, and network-security events and translates them for the teams who have to respond. Reporting is independent of product marketing.

Keep Reading

The May 2026 AI Agent Framework RCE Wave: When Prompts Become Shells
BadHostCVE-2026-25592PraisonAI

PROMPTS
BECOME SHELLS

Cisco ISE Flaw: Read-Only Admin to Root, No Workarounds
CVE-2026-20147

READ-ONLY
TO ROOT

Get the brief before the breach.

SIGNAL decodes the week’s identity, certificate, and network-security events — for the IT and security teams who have to respond to them.

Weekly. No vendor fluff. Unsubscribe anytime.