TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

GreyNoise Detects Active Exploitation of Silk Typhoon-Linked CVEs

2025-03-06 · Read original ↗

ATT&CK techniques detected

5 predictions
T1190Exploit Public-Facing Application
96%
"##ing ips - proxylogon ssrf attempt - adb attempt - web crawler ip count - 52 ( past 24 hours ) - 2, 199 ( past 30 days ) cve - 2021 - 44228 ( log4shell rce ) top 3 source countries - united states - iran - india top 3 behaviors of exploiting ips - apache log4j rce attempt - web …"
T1190Exploit Public-Facing Application
91%
"house select committee on the chinese communist party ( ccp ) holding a hearing on march 5, the same day microsoft released its report, on the growing risks posed by chinese state - sponsored hacking. greynoise confirms exploitation in the wild greynoise analyzed cves linked to s…"
T1190Exploit Public-Facing Application
68%
"##8, and cve - 2024 - 3400. - monitor greynoise intelligence – use greynoise tags and filtering to detect and block ips engaged in malicious activity related to these cves. - reduce exposure – - disable unnecessary internet - facing services. - implement strong authentication ( s…"
T1190Exploit Public-Facing Application
47%
"greynoise detects active exploitation of silk typhoon - linked cves key takeaways - greynoise has detected active exploitation by more than 90 unique threat ips in the past 24 hours across cves linked to the chinese cyber espionage group, silk typhoon ( hafnium ). - greynoise is …"
T1588.006Vulnerabilities
33%
"greynoise detects active exploitation of silk typhoon - linked cves key takeaways - greynoise has detected active exploitation by more than 90 unique threat ips in the past 24 hours across cves linked to the chinese cyber espionage group, silk typhoon ( hafnium ). - greynoise is …"

Summary

Silk Typhoon-linked CVEs are under active exploitation. GreyNoise observed 90+ threat IPs exploiting them in the past 24 hours, following Microsoft’s report on the group's evolving tactics.