Ethical Hacking News
U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog, highlighting the growing threat of cyberattacks on U.S. networks. The coordinated action aims to disrupt infrastructure allegedly used to support China-linked cyber operations. Learn more about the vulnerabilities and the impact on global networks.
U.S. CISA adds 5 new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws.The 5 vulnerabilities pose significant risks to organizations and individuals who fail to address them promptly.CVE-2015-3306 is an access control flaw in ProFTPD that allows remote attackers to read or modify arbitrary files.CVE-2021-3199 is a path traversal flaw in ONLYOFFICE Docs that enables attackers to execute code remotely when JSON Web Token (JWT) is enabled.CVE-2023-22894 is a vulnerability in Strapi that exposes sensitive information stored in cleartext, allowing attackers with admin panel access to retrieve confidential user details.CVE-2016-3081 is a command injection flaw in Apache Struts that could allow remote attackers to run arbitrary code.CVE-2015-5477 is a reachable assertion vulnerability in ISC BIND that could be triggered by remote TKEY queries, potentially causing a denial-of-service condition.The vulnerabilities were added to a broader list of flaws linked to China-linked actors associated with Integrity Technology Group.The update coincides with a joint advisory issued by 7 countries, highlighting the growing threat of cyberattacks on global networks.The campaign used scanning tools, cross-site scripting (XSS), and password-spraying attacks to gain initial access to targeted networks and steal sensitive information.The U.S. Department of Justice and FBI seized two tools allegedly operated by Integrity Tech, Microscan and FishHub.The joint advisory aims to disrupt infrastructure allegedly used to support China-linked cyber operations.CISA orders federal agencies to fix the flaws by October 11, 2026, and recommends that private organizations review the Catalog and address the vulnerabilities.
U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog.
The cybersecurity landscape is a constantly evolving landscape, with new vulnerabilities and threats emerging on a daily basis. In order to stay ahead of the curve, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has been working tirelessly to identify and address the most pressing vulnerabilities in the nation's critical infrastructure. In a recent move, CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the growing threat of cyberattacks on U.S. networks.
The five vulnerabilities in question are CVE-2015-3306, CVE-2021-3199, CVE-2023-22894, CVE-2016-3081, and CVE-2015-5477. These vulnerabilities, which were identified by various security researchers and experts, pose significant risks to organizations and individuals who fail to address them promptly.
CVE-2015-3306 is an access control flaw in ProFTPD, which could allow remote attackers to read or modify arbitrary files by abusing the SITE CPFR and SITE CPTO commands. CVE-2021-3199 is a path traversal flaw in ONLYOFFICE Docs, which could enable attackers to execute code remotely when JSON Web Token (JWT) is enabled. CVE-2023-22894 is a vulnerability in Strapi that exposes sensitive information stored in cleartext, allowing attackers with admin panel access to retrieve confidential user details. CVE-2016-3081 is a command injection flaw in Apache Struts, which could allow remote attackers to run arbitrary code through method prefixes when Dynamic Method Invocation is enabled. Finally, CVE-2015-5477 is a reachable assertion vulnerability in ISC BIND, which could be triggered by remote TKEY queries, potentially causing a denial-of-service condition.
These vulnerabilities have been added to a broader list of flaws linked to cyber operations attributed to China-linked actors associated with Integrity Technology Group, a China-based cybersecurity company. The update coincides with a joint advisory issued by Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States, highlighting the growing threat of cyberattacks on global networks.
The activity reportedly involved the exploitation of eight vulnerabilities, including the five listed above, to gain initial access to targeted networks and steal sensitive information. The attackers used scanning tools, cross-site scripting (XSS), and password-spraying attacks against Microsoft Exchange servers. They also relied on VPN software to maintain access and scripts to extract emails and credentials.
The campaign is part of a broader set of activities linked to Integrity Tech. The U.S. Department of Justice and FBI seized two tools, Microscan and FishHub, allegedly operated by the Chinese company. Microscan was used to scan networks for vulnerable systems, while FishHub relied on spear-phishing emails to deliver malware, enable remote access, and steal files. The tools were reportedly used against critical infrastructure and other organizations in multiple countries.
The joint advisory highlights the risks posed by tools that combine large-scale vulnerability scanning with hands-on exploitation. The coordinated action by seven countries and the U.S. seizure of Microscan and FishHub aim to disrupt infrastructure allegedly used to support China-linked cyber operations.
CISA orders federal agencies to fix the flaws by October 11, 2026. Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure. The update serves as a reminder that the cybersecurity landscape is constantly evolving, and organizations must remain vigilant in addressing emerging threats.
In conclusion, the addition of these five vulnerabilities to CISA's KEV catalog highlights the growing threat of cyberattacks on U.S. networks. The coordinated action by seven countries and the U.S. seizure of Microscan and FishHub aim to disrupt infrastructure allegedly used to support China-linked cyber operations. It is essential for organizations to review the Catalog and address the vulnerabilities in their infrastructure to stay ahead of the curve in the ever-evolving cybersecurity landscape.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Shadowy-World-of-Exploited-Vulnerabilities-CISAs-Latest-Additions-ehn.shtml
https://securityaffairs.com/200734/security/u-s-cisa-adds-proftpd-onlyoffice-docs-strapi-apache-struts-and-isc-bind-flaws-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2015-3306
https://www.cvedetails.com/cve/CVE-2015-3306/
https://nvd.nist.gov/vuln/detail/CVE-2021-3199
https://www.cvedetails.com/cve/CVE-2021-3199/
https://nvd.nist.gov/vuln/detail/CVE-2023-22894
https://www.cvedetails.com/cve/CVE-2023-22894/
https://nvd.nist.gov/vuln/detail/CVE-2016-3081
https://www.cvedetails.com/cve/CVE-2016-3081/
https://nvd.nist.gov/vuln/detail/CVE-2015-5477
https://www.cvedetails.com/cve/CVE-2015-5477/
Published: Sun Oct 11 05:33:11 2026 by llama3.2 3B Q4_K_M