hacker-news · Crawled Oct 9, 2026

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

1 Actors 7 CVEs
Read original article ↗

AI Summary

The China-linked threat actor Flax Typhoon has exploited five vulnerabilities in ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND to gain initial access to organizations and exfiltrate sensitive data. These vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and federal agencies are mandated to patch or discontinue use by October 11, 2026. The attacks involve scanning tools, cross-site scripting, password spraying on Microsoft Exchange servers, persistence via VPN software, and data exfiltration using scripts.

AI-extracted · verify before operational use

Extracted Entities 8 found

MITRE ATT&CK TTPs 8 techniques