Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Insurance model is no substitute for the NHS | Healthcare industry

    October 10, 2026

    Taiwan president says defence spending boost aims to ‘deter war’ | Conflict News

    October 10, 2026

    ‘Would I sit down with Tommy Robinson? It’s not a definite no’: lessons from people who fought the far right in the 70s, 80s and beyond | Far right

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Insurance model is no substitute for the NHS | Healthcare industry
    • Taiwan president says defence spending boost aims to ‘deter war’ | Conflict News
    • ‘Would I sit down with Tommy Robinson? It’s not a definite no’: lessons from people who fought the far right in the 70s, 80s and beyond | Far right
    • Elon Musk intensifies attack on Ambani over Starlink India launch delay
    • AI Scramble Drives Cybersecurity M&A Boom
    • Bitcoin Life Insurer Meanwhile Raises $37.5M
    • Nearly 30,000 people tested quit-smoking methods. One stood out
    • Northern California Community Wants Stronger Oversight of Dangerous Refineries Nearby
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 10, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananOct 09, 2026Vulnerability / Cyber Espionage

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon.

    The vulnerabilities in question are listed below –

    • CVE-2015-3306 (CVSS score: 10.0) – An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
    • CVE-2021-3199 (CVSS score: 9.8) – A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a “/..” sequence in an image upload parameter and could allow for remote code execution.
    • CVE-2023-22894 (CVSS score: 7.2) – A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.
    • CVE-2016-3081 (CVSS score: 8.1) – A command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.
    • CVE-2015-5477 (CVSS score: 7.5) – A reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries.

    The addition of the five vulnerabilities coincides with a joint advisory released by Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S. warning of attacks enabled by a China-based cybersecurity company known as Integrity Technology Group.

    Cybersecurity

    These operations have been found to target eight security vulnerabilities, including the five listed above, to obtain initial access to organizations and siphon sensitive data. The activity involves exploiting flaws using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while setting up persistence through VPN software and exfiltrating emails and credentials using scripts.

    It’s worth noting that the remaining three vulnerabilities already have a place in the KEV catalog –

    • CVE-2014-6278 – GNU Bash operating system command injection vulnerability (aka Shellshock) (Added in October 2025)
    • CVE-2019-11510 – Ivanti Pulse Connect Secure arbitrary file read vulnerability (Added in November 2021)
    • CVE-2021-22205 – GitLab Community and Enterprise Edition remote code execution vulnerability (Added in November 2021)

    “Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” said Acting Executive Assistant Director for Cybersecurity Chris Butera.

    In light of active exploitation, federal agencies are required to apply the necessary patches or discontinue their use by October 11, 2026.

    agencies CISA deadline exploits Federal flaws Flax October Sets Typhoon
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI Scramble Drives Cybersecurity M&A Boom

    Paraguay meets UN deadline for improving governance in Chaco Biosphere Reserve

    Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

    Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects

    Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

    Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Insurance model is no substitute for the NHS | Healthcare industry

    October 10, 2026

    Taiwan president says defence spending boost aims to ‘deter war’ | Conflict News

    October 10, 2026

    ‘Would I sit down with Tommy Robinson? It’s not a definite no’: lessons from people who fought the far right in the 70s, 80s and beyond | Far right

    October 10, 2026

    Elon Musk intensifies attack on Ambani over Starlink India launch delay

    October 10, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Insurance model is no substitute for the NHS | Healthcare industry

    October 10, 2026

    Taiwan president says defence spending boost aims to ‘deter war’ | Conflict News

    October 10, 2026

    ‘Would I sit down with Tommy Robinson? It’s not a definite no’: lessons from people who fought the far right in the 70s, 80s and beyond | Far right

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.