hacker-news · Crawled Oct 9, 2026
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
1 Actors 7 CVEs
Read original article ↗
AI Summary
The China-linked threat actor Flax Typhoon has exploited five vulnerabilities in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to gain initial access to organizations and exfiltrate sensitive data. These vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and federal agencies are mandated to patch or discontinue use by October 11, 2026. The attacks involve scanning tools, cross-site scripting, password spraying on Microsoft Exchange servers, persistence via VPN software, and data exfiltration using scripts.
AI-extracted · verify before operational use
Extracted Entities 8 found
MITRE ATT&CK TTPs 8 techniques
T1003 OS Credential Dumping · Credential Access T1021 Remote Services · Lateral Movement T1059 Command and Scripting Interpreter · Execution T1071 Application Layer Protocol · Command And Control T1078 Valid Accounts · Defense Evasion T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1558 Steal or Forge Kerberos Tickets · Credential Access