Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Federal Agencies Urged to Patch Flaws Exploited by Flax Typhoon

Federal Agencies Urged to Patch Flaws Exploited by Flax Typhoon

Posted on October 9, 2026 By CWS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has heightened its security alerts by adding five newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. This announcement, made on Thursday, follows confirmed reports of exploitation by Flax Typhoon, a threat group with links to China.

Identifying the Targeted Vulnerabilities

The identified vulnerabilities span various software systems and are rated with significant severity scores, emphasizing the urgency for mitigation. Among them, CVE-2015-3306 in ProFTPD scores a full 10.0 on the CVSS scale, highlighting its critical nature as it could permit unauthorized file access. Another, CVE-2021-3199 in ONLYOFFICE Docs, holds a 9.8 score, presenting a serious risk of remote code execution.

Additional vulnerabilities include CVE-2023-22894 in Strapi, which risks exposing sensitive information, and CVE-2016-3081 in Apache Struts, susceptible to command injection. Lastly, CVE-2015-5477 in ISC BIND could enable denial-of-service attacks.

International Cybersecurity Advisory

The acknowledgment of these vulnerabilities is part of a broader advisory released in collaboration with cybersecurity agencies from Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. This advisory warns that the Integrity Technology Group, a China-based cybersecurity entity, is leveraging these and other vulnerabilities for unauthorized access and data exfiltration.

These threats manifest through various tactics, including cross-site scripting and password spraying on Microsoft Exchange servers, aiming for persistence via VPN applications while extracting sensitive emails and credentials.

Broader Implications and Mandated Actions

Three additional vulnerabilities previously cataloged include CVE-2014-6278 (Shellshock), CVE-2019-11510, and CVE-2021-22205, underscoring the persistent threat landscape. CISA’s Acting Executive Assistant Director for Cybersecurity, Chris Butera, stressed the strategic infiltration of these actors into vital infrastructure, potentially disrupting future operations.

Given the active threat, federal agencies have been directed to implement the necessary patches by October 11, 2026, or cease using the affected systems to prevent further exploitation.

The urgency and international cooperation reflect the critical need for robust cybersecurity measures, particularly in safeguarding national infrastructure against sophisticated cyber threats.

The Hacker News Tags:China-linked threat, CISA, cyber espionage, cyber threats, Cybersecurity, federal agencies, Flax Typhoon, patch management, security flaws, Vulnerabilities

Post navigation

Previous Post: New Exploit in Telegram Desktop Allows Account Takeover
Next Post: Google Domains Expose Vulnerability in Recent ccTLD Hijacks

Related Posts

Ubuntu Security Flaw CVE-2026-3888 Enables Root Access Ubuntu Security Flaw CVE-2026-3888 Enables Root Access The Hacker News
TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs The Hacker News
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection The Hacker News
UAC-0050 Expands to European Finance with RMS Malware UAC-0050 Expands to European Finance with RMS Malware The Hacker News
DarkSword iOS Kit Exploits Multiple Flaws for Device Control DarkSword iOS Kit Exploits Multiple Flaws for Device Control The Hacker News
PaperCut Vulnerabilities Enable Credential Theft in Education PaperCut Vulnerabilities Enable Credential Theft in Education The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Terraform Workflows to Spread Malware
  • Anthropic Accelerates AI Bug Reports for Open Source Security
  • Citrix Addresses Critical NetScaler Vulnerability
  • Top Container Image Scanning Tools of 2026
  • Google Domains Expose Vulnerability in Recent ccTLD Hijacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Terraform Workflows to Spread Malware
  • Anthropic Accelerates AI Bug Reports for Open Source Security
  • Citrix Addresses Critical NetScaler Vulnerability
  • Top Container Image Scanning Tools of 2026
  • Google Domains Expose Vulnerability in Recent ccTLD Hijacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark