This month: 9 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2015-3306
ProFTPD · ProFTPD
ProFTPD Improper Access Control Vulnerability
■Detected Oct 8 · 3-day patch deadline
CVE-2015-5477
ISC · BIND
ISC BIND Data Processing Errors Vulnerability
■Detected Oct 8 · 3-day patch deadline
CVE-2016-3081
Apache · Struts
Apache Struts Command Injection Vulnerability
■Detected Oct 8 · 3-day patch deadline

KEV Intelligence Brief: Special Edition — AA26-281A

Audience: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders
Advisory Classification: TLP:CLEAR
Reporting Date: October 8, 2026

CISA's October 8 advisory, AA26-281A, identifies eight vulnerabilities exploited by Chinese government-linked threat actors, including five older CVEs highlighted in this KEV update. Two date to 2015, and the newest to 2023. The advisory documents years of intrusion activity enabled by Integrity Technology Group, a China-based contractor whose associated activity overlaps with Flax Typhoon, Ethereal Panda, and Red Juliett.

The lesson is not simply that old vulnerabilities remain dangerous. It is that a well-resourced, state-linked operation combined years-old exploits with automated scanning, credential attacks, legitimate remote-access software, and specialized email-theft tools to compromise organizations worldwide.

Who Is Behind It: Integrity Tech, Again

Integrity Technology Group is not a new name. In September 2024, the FBI disrupted the Raptor Train botnet, consisting of more than 200,000 compromised consumer devices worldwide, which the Justice Department linked to Integrity Tech. The U.S. Treasury sanctioned the company in January 2025, followed by additional international measures.

On October 8, the Justice Department and FBI announced the seizure of seven domains associated with two platforms: MicroScan, a Python-based vulnerability scanner containing more than 1,300 testing scripts and used since at least 2017, and FishHub, a platform associated with spear-phishing, malware delivery, and post-compromise data theft.

According to the Justice Department, MicroScan supported reconnaissance against critical infrastructure and other organizations. FishHub facilitated intrusions and malware deployment, with confirmed victims including approximately 20 Taiwanese universities.

The joint advisory identifies targeted U.S. sectors including Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology, alongside law enforcement, educational, and religious organizations.

One particularly concerning finding involves stolen email. Investigators identified a custom web application that allowed third parties to browse exfiltrated mailbox content. This suggests that compromised communications could be accessible beyond the operators responsible for the initial intrusion.

Operational note: Domain seizures disrupt specific infrastructure, not necessarily the personnel, capabilities, or remaining access of the threat actors. Organizations should continue investigating potential compromise rather than interpreting the takedown as the end of the threat.

Old Bugs, New Listings: Five KEV Additions

The five vulnerabilities highlighted in this update span FTP services, DNS infrastructure, Java applications, document collaboration platforms, and headless content management systems.

The advisory documents successful exploitation associated with the actors' tooling, but that does not establish that every listed vulnerability was used in every intrusion.

CVE-2015-3306 (ProFTPD 1.3.5) exploits the mod_copy module through SITE CPFR and SITE CPTO commands, allowing unauthorized file copying under vulnerable configurations. The issue was addressed in version 1.3.5a. Administrators should identify exposed FTP services, remove unnecessary internet access, and retire unsupported deployments.

CVE-2015-5477 (ISC BIND 9) allows a specially crafted TKEY query to crash a vulnerable DNS server. Fixes were released in versions 9.9.7-P2 and 9.10.2-P3. Although this is a denial-of-service vulnerability rather than remote code execution, disruption of critical DNS infrastructure can affect numerous dependent services. Embedded and appliance-bundled BIND installations deserve particular attention.

CVE-2016-3081 (Apache Struts 2) involves remote code execution associated with Dynamic Method Invocation and affected Struts configurations. Apache released fixes across supported branches, including versions 2.3.20.3, 2.3.24.3, and 2.3.28.1. Disabling Dynamic Method Invocation may provide mitigation for applicable configurations, but surviving Struts 2.3 installations should be treated as modernization and replacement priorities.

CVE-2021-3199 (ONLYOFFICE Document Server) is a path traversal vulnerability affecting older releases, including versions 5.1.5 through 5.6.2, with potential remote code execution consequences under affected configurations. The issue was addressed in version 5.6.3. Teams should inventory self-hosted document collaboration services, including deployments maintained outside centralized platform management.

CVE-2023-22894 (Strapi) involves improper filtering of user information that can expose sensitive data, including password-reset-related information, to users with administrative-panel access under affected configurations. Vendor reporting identifies affected releases across the 3.x and 4.x branches, with version 4.8.0 addressing the issue in the 4.x line. Administrators should consult Strapi's advisory for exact affected versions and remediation requirements.

For teams using Strapi behind modern web applications, the lesson is straightforward: a headless CMS remains a security-sensitive backend even when the public website is statically rendered.

Three previously listed vulnerabilities also appear in the advisory: Shellshock (CVE-2014-6278), Pulse Connect Secure (CVE-2019-11510), and GitLab (CVE-2021-22205). Their inclusion reinforces the continued exploitation of longstanding weaknesses.

Operational guidance: Inventory exposure to all eight CVEs, paying particular attention to vendor-bundled software, legacy appliances, forgotten development systems, and applications outside standard vulnerability scanning coverage.

Apply supported fixes where available. For unsupported products, reduce exposure through isolation, access restrictions, or replacement. Where compromise is suspected, preserve relevant evidence and follow incident-response procedures before making disruptive changes.

The Real Target Is Email: Detection Priorities

Although vulnerability exploitation provides initial access, the advisory documents an extensive collection capability focused on credentials, mailboxes, and sensitive organizational information.

Password spraying against Exchange and Microsoft 365. The actors used EBurst, an open-source tool supporting password spraying and guessing across Exchange interfaces including OWA, EWS, ActiveSync, Autodiscover, MAPI, and PowerShell. Defenders should verify authentication controls across all enabled interfaces, disable unnecessary legacy authentication, and monitor for distributed password-spraying attempts.

XSS-delivered credential harvesting. Investigators recovered a cross-site scripting payload capable of replacing vulnerable webpage content with credential-entry fields. The payload also delivered a password-protected archive containing live700_v1.exe. Analysis showed the executable launching a process named DiagTrack.exe, imitating legitimate Windows software, and communicating with dns.studiocloud[.]xyz. Defenders should investigate unexpected instances of this process, particularly those executing from unusual paths.

Persistence through legitimate VPN software. The actors installed SoftEther VPN clients on compromised systems, sometimes disguising installers as conhost.exe or dllhost.exe. The clients were configured to reconnect automatically after restart. Investigate unauthorized SoftEther installations, unexpected outbound VPN sessions, and suspicious executable locations.

Credential theft through DCSync. A tool named DC.exe used Active Directory replication functionality to retrieve account information, credentials, group memberships, and trust relationships. Monitor replication requests from unexpected systems and investigate any unauthorized account granted directory replication privileges.

Mail collection through legitimate APIs. A PHP script named Curlc4.txt collected mailbox content using Exchange Web Services. Another tool, office-cli, automated Microsoft 365 email access using application credentials and configuration files containing client and tenant identifiers.

Security teams should review application registrations, mail-read permissions, service principal activity, and unusual EWS access patterns. Applications with broad mailbox permissions and no identifiable business owner warrant investigation.

Operational guidance: The advisory emphasizes identifying the full scope of an intrusion before eviction. Organizations should isolate affected systems where necessary, preserve forensic evidence, investigate persistence and credential compromise, and coordinate remediation to avoid leaving undetected access behind.

The advisory also provides extensive indicators of compromise, including infrastructure observed over multiple years. Validate indicators against current context before implementing broad blocking rules; historical association does not establish that every address remains malicious today.

Summary: Vulnerability and Remediation Priorities

| CVE | Vendor / Product | Remediation reference | KEV context | |---|---|---|---| | CVE-2015-3306 | ProFTPD | 1.3.5a | October 8 update | | CVE-2015-5477 | ISC BIND | 9.9.7-P2 / 9.10.2-P3 | October 8 update | | CVE-2016-3081 | Apache Struts | Fixed 2.3.x releases | October 8 update | | CVE-2021-3199 | ONLYOFFICE Document Server | 5.6.3 | October 8 update | | CVE-2023-22894 | Strapi | 4.8.0 for affected 4.x releases | October 8 update | | CVE-2014-6278 | GNU Bash | Vendor-supported security updates | Previously listed | | CVE-2019-11510 | Pulse Connect Secure | Vendor-supported fixed releases | Previously listed | | CVE-2021-22205 | GitLab | 13.8.8 / 13.9.6 / 13.10.3 | Previously listed |

Deadline note: Confirm the exact required-action dates for the five new entries against the live KEV catalog before publication. Earlier KEV entries retain their established compliance history; their inclusion in this advisory does not automatically reset remediation deadlines.

BOD 26-04 establishes vulnerability remediation requirements for Federal Civilian Executive Branch agencies. Federal contractors should assess applicable contractual, agency-specific, and authorization requirements rather than assuming direct applicability of the directive.

Bottom line: Integrity Tech's operations demonstrate how old vulnerabilities, credential abuse, legitimate administrative tools, and automated reconnaissance can support long-running intelligence collection. The immediate priority is not merely checking patch status. It is determining whether exposed systems have already been used to establish persistence or steal sensitive information.

Sources: CISA Advisory AA26-281A · Joint Advisory PDF (FBI IC3) · CISA KEV Catalog · DOJ: Integrity Tech Tool Seizures · CISA Eviction Strategies Tool · Apache Struts S2-032 · Strapi Security Disclosure

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — October 9, 2026

FBI Disrupts Chinese State-Sponsored Infrastructure Targeting Critical Systems

The FBI seized seven internet domains operated by Chinese state-linked threat actor Flax Typhoon, disrupting two hacking tools—MicroScan and FishHub—used to breach U.S. critical infrastructure, power sector entities, and academic institutions. The domains were operated by China's Integrity Tech Group and used to conduct scanning operations and credential harvesting campaigns. Australian cyber authorities issued a coordinated advisory noting that Chinese government-linked actors are increasingly combining automated tooling with hands-on keyboard techniques to exfiltrate sensitive data from compromised networks. The disruption represents the latest U.S. government action targeting persistent Chinese infrastructure operations against high-value domestic targets.

Active Exploitation of AhsayCBS Backup Software and Ransomware Operations

Threat actors are actively chaining two unpatched vulnerabilities in AhsayCBS backup software to achieve unauthenticated remote code execution and deploy webshells, with at least five organizations confirmed compromised. Separately, Japan's IDCF Cloud suffered a ransomware attack on October 7 that caused a major outage at a data center cluster serving government clients in eastern Japan. A CloudSEK investigation identified a ransomware campaign affecting more than 24 organizations across six countries in which the operator used AI coding assistants for direct attack execution and data exfiltration. Additionally, a former MonsterCloud employee was charged with defrauding ransomware victims by obtaining decryption keys from threat actors then charging clients an $11 million markup for fake remediation services.

Discord Security Bot Breach Exposes 28 Million Accounts

The Discord security bot Double Counter disclosed that attackers compromised its cloud infrastructure for six hours, exposing data for 28 million Discord accounts and copying 12 GB of database records. The breach demonstrates the downstream impact when security tooling providers themselves become attack vectors. Separately, Japanese semiconductor testing firm Advantest confirmed that personal information was stolen during a February 2026 ransomware attack, adding to recent disclosures from legacy breach incidents.

Sources: Bleeping Computer · Yahoo Finance · Cyber.gov.au · SecurityWeek · Bleeping Computer · CyberSecurity News · SecurityWeek · Cybernews

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://cyberscoop.comOct 8

DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub

The Justice Department and FBI seized Flax Typhoon-linked hacking tools Microscan and FishHub operated by Integrity Technology Group, accompanied by a...

https://www.justice.govOct 8

Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

Justice Department and FBI announced court-authorized seizures of Microscan and FishHub tools used by Flax Typhoon actors associated with Integrity Te...

https://theregister.comOct 8

US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

The FBI and Justice Department seized Flax Typhoon hacking tools while FBI, CISA, NSA and international partners warned of Chinese government-linked a...

https://www.ic3.govOct 8

Chinese Government-Linked Cyber Threat Actors Combine Automated and Hands-On Hacking Tools

FBI, CISA, NSA, and NCSC-UK issue joint advisory on Chinese government-linked cyber threat actors combining automated scanning tools and hands-on expl...

https://www.theregister.comOct 9

US disrupts Chinese hacking tools as 7 govts warn of PRC spies stealing sensitive data worldwide

The FBI announced that it has seized seven web domains linked to hacking tools allegedly operated by a Chinese security firm called Integrity ...

https://www.securityweek.comOct 8

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian's self-hosted Data Center products, with attacks beginning ...

https://www.securityweek.comOct 8

Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ Countries

Bitdefender uncovered Midnight Mimosa, a firmware-level Android malware campaign shipping preinstalled on budget smartphones worldwide affecting 150+ ...

https://www.bloomberg.comOct 5

US Nabs Suspected China Spy for Surveilling Taiwan Leader's Son

The FBI arrested a woman suspected of spying for China by surveilling the Taiwanese president's son and his family at Los Angeles International Airpor...


Updated daily