China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains
The Silk Typhoon hacking group, linked to China and previously behind Microsoft Exchange zero-day attacks, is now targeting IT supply chains, abusing stolen API keys, remote management tools, and cloud applications to infiltrate corporate networks.
The group is exploiting stolen API keys and credentials from IT service providers, launching zero-day attacks on Ivanti VPN, Palo Alto Networks, and Citrix NetScaler, and shifting from on-prem environments to cloud applications like Microsoft 365, OneDrive, and SharePoint to exfiltrate data.
Organizations must strengthen API security, enforce least privilege access, and monitor cloud environments to mitigate these growing supply chain threats.
Read more: https://thehackernews.com/2025/03/china-linked-silk-typhoon-expands-cyber.html
#Cybersecurity #SupplyChainSecurity #CloudSecurity #ThreatIntelligence #ChinaAPT #Infosec #databreach #DFIR #APIsecurity