Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The Hacker News by The Hacker News
October 9, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananOct 09, 2026Vulnerability / Cyber Espionage

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon.

The vulnerabilities in question are listed below –

  • CVE-2015-3306 (CVSS score: 10.0) – An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
  • CVE-2021-3199 (CVSS score: 9.8) – A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a “/..” sequence in an image upload parameter and could allow for remote code execution.
  • CVE-2023-22894 (CVSS score: 7.2) – A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.
  • CVE-2016-3081 (CVSS score: 8.1) – A command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
  • CVE-2015-5477 (CVSS score: 7.5) – A reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries.

The addition of the five vulnerabilities coincides with a joint advisory released by Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. warning of attacks enabled by a China-based cybersecurity company known as Integrity Technology Group.

These operations have been found to target eight security vulnerabilities, including the five listed above, to obtain initial access to organizations and siphon sensitive data. The activity involves exploiting flaws using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts.

It’s worth noting that the remaining three vulnerabilities already have a place in the KEV catalog –

  • CVE-2014-6278 – GNU Bash operating system command injection vulnerability (aka Shellshock) (Added in October 2025)
  • CVE-2019-11510 – Ivanti Pulse Connect Secure arbitrary file read vulnerability (Added in November 2021)
  • CVE-2021-22205 – GitLab Community and Enterprise Edition remote code execution vulnerability (Added in November 2021)

“Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” said Acting Executive Assistant Director for Cybersecurity Chris Butera.

In light of active exploitation, federal agencies are required to apply the necessary patches or discontinue their use by October 11, 2026.



Source link

The Hacker News

The Hacker News

Next Post

Stocks making the biggest moves premarket: Delta Air Lines, SpaceX, T-Mobile, Humana & more

Recommended.

F1’s Red Bull charges 1Password to protect its 2025 season | Computer Weekly

F1’s Red Bull charges 1Password to protect its 2025 season | Computer Weekly

February 11, 2025
Bridging the Remediation Gap: Introducing Pentera Resolve

Bridging the Remediation Gap: Introducing Pentera Resolve

October 22, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio