#2
The Hacker News
general
October 09, 2026 at 12:21 UTC
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
By [email protected] (The Hacker News)
AI Summary
CISA added five vulnerabilities to its KEV catalog — including CVE-2015-3306 (CVSS 10.0, ProFTPD improper access control) — all actively exploited by China-linked Flax Typhoon, with a federal agency remediation deadline of October 11, 2026. The additions tie directly to the same Integrity Tech / Flax Typhoon campaign disrupted by the FBI and DOJ this week. Federal agencies and critical infrastructure operators must prioritize these five flaws immediately given the tight deadline.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →