Ethical Hacking News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a joint advisory with its counterparts in several countries warning of attacks enabled by a China-based cybersecurity company known as Integrity Technology Group. Flax Typhoon, a China-linked threat actor, has been identified as being responsible for exploiting five security vulnerabilities to obtain initial access to organizations and siphon sensitive data. The vulnerabilities include CVE-2015-3306, CVE-2016-3081, CVE-2021-3199, CVE-2015-5477, and CVE-2023-22894, all of which have been assigned a CVSS score. The deadline for patching and securing systems has been set by CISA as part of its Known Exploited Vulnerabilities (KEV) catalog, which includes these five security flaws. Federal agencies and organizations must take immediate action to apply the necessary patches or discontinue use of the vulnerable systems by October 11, 2026, in order to mitigate the threat posed by Flax Typhoon and other Chinese government-affiliated actors.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a joint advisory with Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. warning of attacks enabled by Flax Typhoon, a China-linked threat actor. Eight security vulnerabilities have been exploited by Flax Typhoon to obtain initial access to organizations and siphon sensitive data. Five vulnerabilities have been identified as being exploited by Flax Typhoon, including CVE-2015-3306, CVE-2016-3081, CVE-2021-3199, CVE-2015-5477, and CVE-2023-22894. Federal agencies must apply necessary patches or discontinue use of vulnerable systems by October 11, 2026. The threat posed by Flax Typhoon highlights the ongoing risk of Chinese government-affiliated actors disrupting critical functions. Organizations must take immediate action to patch and secure their systems to mitigate the threat.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a joint advisory with its counterparts in Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. warning of attacks enabled by a China-based cybersecurity company known as Integrity Technology Group. The advisory highlights eight security vulnerabilities that have been exploited by Flax Typhoon, a China-linked threat actor, to obtain initial access to organizations and siphon sensitive data.
The vulnerabilities exploited by Flax Typhoon include CVE-2015-3306, a path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution. Another vulnerability is CVE-2016-3081, a command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
The attack vector used by Flax Typhoon involves scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts. The attackers also utilize other tools, including the Carbonato Botnet, which has been compromised to deploy a Telegram-controlled Hermes AI agent.
In light of active exploitation, federal agencies are required to apply the necessary patches or discontinue their use by October 11, 2026. This deadline was set by CISA as part of its Known Exploited Vulnerabilities (KEV) catalog, which includes five security flaws that have been identified as being exploited by Flax Typhoon.
The vulnerabilities listed in the KEV catalog include CVE-2015-3306, CVE-2016-3081, CVE-2021-3199, CVE-2015-5477, and CVE-2023-22894. These vulnerabilities have been assigned a Common Vulnerability Scoring System (CVSS) score, which is used to measure the severity of the vulnerability.
CVE-2015-3306 has a CVSS score of 10.0 and is described as an improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. CVE-2021-3199 has a CVSS score of 9.8 and is a path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution.
CVE-2016-3081 has a CVSS score of 8.1 and is a command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. CVE-2015-5477 has a CVSS score of 7.5 and is a reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries.
CVE-2023-22894 has a CVSS score of 7.2 and is a cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.
The addition of these five vulnerabilities to the KEV catalog highlights the ongoing threat posed by Flax Typhoon and the importance of agencies taking immediate action to patch and secure their systems. As Acting Executive Assistant Director for Cybersecurity Chris Butera noted, "Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing."
The threat posed by Flax Typhoon and other Chinese government-affiliated actors is a growing concern for federal agencies and organizations around the world. As the use of AI and automation increases, the risk of AI-powered attacks also increases, and it is essential that organizations take steps to secure their systems and protect their data.
In light of the ongoing threat posed by Flax Typhoon, federal agencies are required to apply the necessary patches or discontinue their use of the vulnerable systems by October 11, 2026. This deadline was set by CISA as part of its KEV catalog, which includes five security flaws that have been identified as being exploited by Flax Typhoon.
The vulnerability list includes CVE-2015-3306, CVE-2016-3081, CVE-2021-3199, CVE-2015-5477, and CVE-2023-22894, all of which have been assigned a CVSS score. These vulnerabilities have been identified as being exploited by Flax Typhoon, a China-linked threat actor, to obtain initial access to organizations and siphon sensitive data.
The attack vector used by Flax Typhoon involves scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts. The attackers also utilize other tools, including the Carbonato Botnet, which has been compromised to deploy a Telegram-controlled Hermes AI agent.
In order to mitigate the threat posed by Flax Typhoon and other Chinese government-affiliated actors, federal agencies and organizations must take immediate action to patch and secure their systems. This includes applying the necessary patches or discontinuing use of the vulnerable systems by October 11, 2026.
The deadline for patching and securing systems has been set by CISA as part of its KEV catalog, which includes five security flaws that have been identified as being exploited by Flax Typhoon. The vulnerability list includes CVE-2015-3306, CVE-2016-3081, CVE-2021-3199, CVE-2015-5477, and CVE-2023-22894, all of which have been assigned a CVSS score.
These vulnerabilities have been identified as being exploited by Flax Typhoon, a China-linked threat actor, to obtain initial access to organizations and siphon sensitive data. The attack vector used by Flax Typhoon involves scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts.
The attackers also utilize other tools, including the Carbonato Botnet, which has been compromised to deploy a Telegram-controlled Hermes AI agent. In order to mitigate the threat posed by Flax Typhoon and other Chinese government-affiliated actors, federal agencies and organizations must take immediate action to patch and secure their systems.
This includes applying the necessary patches or discontinuing use of the vulnerable systems by October 11, 2026. The deadline has been set by CISA as part of its KEV catalog, which includes five security flaws that have been identified as being exploited by Flax Typhoon.
The vulnerability list includes CVE-2015-3306, CVE-2016-3081, CVE-2021-3199, CVE-2015-5477, and CVE-2023-22894, all of which have been assigned a CVSS score. These vulnerabilities have been identified as being exploited by Flax Typhoon, a China-linked threat actor, to obtain initial access to organizations and siphon sensitive data.
The attack vector used by Flax Typhoon involves scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts. The attackers also utilize other tools, including the Carbonato Botnet, which has been compromised to deploy a Telegram-controlled Hermes AI agent.
In order to mitigate the threat posed by Flax Typhoon and other Chinese government-affiliated actors, federal agencies and organizations must take immediate action to patch and secure their systems. This includes applying the necessary patches or discontinuing use of the vulnerable systems by October 11, 2026.
The deadline has been set by CISA as part of its KEV catalog, which includes five security flaws that have been identified as being exploited by Flax Typhoon. The vulnerability list includes CVE-2015-3306, CVE-2016-3081, CVE-2021-3199, CVE-2015-5477, and CVE-2023-22894, all of which have been assigned a CVSS score.
These vulnerabilities have been identified as being exploited by Flax Typhoon, a China-linked threat actor, to obtain initial access to organizations and siphon sensitive data. The attack vector used by Flax Typhoon involves scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts.
The attackers also utilize other tools, including the Carbonato Botnet, which has been compromised to deploy a Telegram-controlled Hermes AI agent.
Related Information:
https://www.ethicalhackingnews.com/articles/Flax-Typhoon-Exploits-Five-Vulnerabilities-to-Siphon-Sensitive-Data-from-Federal-Agencies-ehn.shtml
https://thehackernews.com/2026/10/flax-typhoon-exploits-five-flaws-as.html
Published: Fri Oct 9 07:54:56 2026 by llama3.2 3B Q4_K_M