Back Finance.Biggo CISA Orders Federal Agencies to Patch Five Exploited Flaws by October 11 Amid Flax ...
Federal civilian agencies have until October 11 to remediate five security vulnerabilities that a China-linked threat actor is actively exploiting to break into critical infrastructure networks, the U.S. Cybersecurity and Infrastructure Security Agency said Thursday.
The agency added the flaws to its Known Exploited Vulnerabilities (KEV) catalog after confirming in-the-wild abuse by Flax Typhoon, a hacking group that U.S. authorities have long associated with Beijing. The directive carries a binding operational requirement for federal departments to apply vendor patches or stop using the affected software entirely.
The five newly cataloged vulnerabilities span a broad range of widely deployed enterprise products. The most severe is CVE-2015-3306, an improper access control flaw in ProFTPD with a CVSS score of 10.0, the maximum possible rating. Remote attackers can exploit the weakness to read and write arbitrary files through the site cpfr and site cpto commands.
CVE-2021-3199, rated 9.8, is a path traversal issue in ONLYOFFICE Docs that enables remote code execution when JSON Web Token authentication is in use. An attacker can trigger the flaw by inserting a "/.." sequence into an image upload parameter.
CVE-2023-22894, scored 7.2, involves cleartext storage of sensitive information in Strapi. Anyone with access to the admin panel could use a query filter to uncover sensitive user details.
CVE-2016-3081 affects Apache Struts and carries a score of 8.1. It is a command injection vulnerability that allows remote code execution via the method:prefix technique when Dynamic Method Invocation is enabled.
CVE-2015-5477, rated 7.5, is a reachable assertion flaw in ISC BIND that permits denial-of-service attacks through TKEY queries.
The KEV update landed alongside a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States. The seven governments warned that Flax Typhoon's operations have been enabled by Integrity Technology Group, a Beijing-based cybersecurity company that allegedly developed the intrusion tooling used in these campaigns.
According to the advisory, the attackers have targeted eight vulnerabilities in total to gain initial access to victim organizations and steal sensitive data. The three additional flaws already had a place in the KEV catalog: CVE-2014-6278, the GNU Bash command injection vulnerability known as Shellshock, added in October 2025; CVE-2019-11510, an arbitrary file read bug in Ivanti Pulse Connect Secure, added in November 2021; and CVE-2021-22205, a remote code execution flaw in GitLab Community and Enterprise Edition, also added in November 2021.
"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," said Chris Butera, acting executive assistant director for cybersecurity at CISA.
The advisory describes a multi-stage intrusion pattern. The group uses scanning tools to identify vulnerable systems, launches cross-site scripting attacks, and conducts password spraying against Microsoft Exchange servers. After gaining a foothold, the actors establish persistence through VPN software and then exfiltrate emails and credentials using custom scripts.
The CISA action follows an FBI announcement that it had seized seven web domains linked to hacking tools allegedly operated by Integrity Technology Group. Court documents unsealed Thursday allege the company has contracts with the Chinese government and developed the tooling used by Flax Typhoon.
One of the seized domains, c0cc[.]cc, was used to access Microscan, a vulnerability scanner allegedly built by Integrity Tech. Court documents state that Flax Typhoon actors conducted successful intrusions against multiple victims whose networks had first been scanned with Microscan.
Those victims include a university in Hsinchu, Taiwan, compromised in March 2023, and a second university in Puli Township, Taiwan, breached in August 2022. The documents also allege that on April 26, 2022, and December 29, 2022, the group used Microscan to probe networks belonging to a South Carolina power company, a multinational non-governmental organization, Japanese and Polish airports, and at least two Taiwanese critical infrastructure firms in the natural gas and power sectors.
Five other seized domains -- 98aicai[.]com, 98aicode[.]com, outlook3650[.]com, youtubecard[.]com, and linkedinns[.]net -- delivered a post-compromise tool called FishHub. The malware was active as recently as March and infected approximately 20 Taiwanese universities.
"Based on my training and experience I believe the tool was named FishHub because it facilitated phishing activity," FBI special agent Adam James said in a seizure warrant affidavit.
After FishHub downloaded an initial file onto a victim's computer, that file retrieved additional malicious programs from the five domains. The malware then created a file listing, searched for specific documents, compressed them, and exfiltrated the selected data to an attacker-controlled server, giving Flax Typhoon persistent remote access to compromised networks.
A long-running campaign
From 2021 until its disruption, Flax Typhoon allegedly operated a Mirai-based botnet that infected internet-connected devices with malware, scanned networks for vulnerabilities, and launched follow-on attacks while masking the true IP addresses and physical locations of Chinese government hackers.
In September 2024, the FBI said Integrity Tech and Flax Typhoon dismantled their 260,000-device botnet after coordinated action by U.S. and international partners. But the reprieve did not last. In February, operational technology security firm Dragos reported that China's state- spies were continuing their attempts to compromise American critical infrastructure, including a group whose activity overlaps with Flax Typhoon. That group focuses on long-term access to OT engineering workstations and the exfiltration of operational files, targeting manufacturing, defense, automotive, electric power, oil and gas, and government organizations across the U.S., Europe, and Asia-Pacific.
In April, a 10-country advisory warned that virtually every Chinese "Typhoon" group is using botnets "strategically, and at scale." Some of those covert networks are built and maintained by Chinese infosec companies including Integrity Tech, which also controlled the Raptor Train network.
In late August, the FBI announced it had disrupted a different botnet and seized domains associated with two platforms allegedly used by Chinese government-backed operatives to target NASA, the U.S. Senate, the Department of Energy, and other agencies. The Department of Justice later clarified that not all the named organizations had been compromised.
The latest KEV additions underscore the persistence of the threat. Federal agencies now face a strict deadline to close the five newly flagged vulnerabilities, while the broader advisory serves as a warning to private-sector operators of critical infrastructure that the same tooling is being deployed against them.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
