The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog following confirmed abuse by a China-linked threat actor known as Flax Typhoon.

The update arrives concurrently with a sweeping joint cybersecurity advisory issued by an international coalition including Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States. The advisory warns global organizations about active cyber espionage campaigns enabled by a China-based cybersecurity company identified as Integrity Technology Group.

According to the joint advisory, these operations target a total of eight security vulnerabilities—including the five newly added to the CISA catalog—to gain initial access to targeted networks and siphon sensitive data. Threat actors have been observed exploiting these critical flaws using automated scanning tools, cross-site scripting attacks, and password spraying directed at Microsoft Exchange servers. Once inside target environments, the operators establish long-term persistence through compromised virtual private network (VPN) software and exfiltrate internal communications, emails, and user credentials utilizing custom scripting.

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

The newly cataloged flaws join three other related vulnerabilities that were already tracked within the KEV database due to prior exploitation patterns. The discovery and disruption of these tactics also parallel recent federal enforcement actions, including an operation by the FBI to seize seven domains used by Flax Typhoon to manage their infrastructure.

U.S. officials emphasize that the campaign highlights a broader, persistent strategy by state-sponsored actors to embed themselves deeply within critical infrastructure networks. These intrusions frequently extend to operational technology (OT) systems, raising concerns that hostile actors are positioning themselves to potentially disrupt vital public and private functions at a future time of their choosing.

"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology systems, with the aim of disrupting critical functions at a future time of their choosing," said Acting Executive Assistant Director for Cybersecurity Chris Butera.

In response to the active exploitation of these eight vulnerabilities, federal agencies and participating organizations have been directed to apply necessary security patches or completely discontinue the use of affected software. U.S. federal civilian agencies face a strict remediation deadline of October 11, 2026, to secure their systems against the identified vectors. Cybersecurity authorities worldwide continue to urge both public and private sector organizations to review the joint advisory, audit their networks for indicators of compromise, and harden their perimeter defenses against ongoing state-backed cyber espionage operations.

Leave a Reply

Your email address will not be published. Required fields are marked *