Home / Oct 10, 2026 / Story
0
#2 The Hacker News general October 09, 2026 at 12:21 UTC

Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

By [email protected] (The Hacker News)

AI Summary

CISA added five vulnerabilities to its KEV catalog — including CVE-2015-3306 (CVSS 10.0, ProFTPD improper access control) — all actively exploited by China-linked Flax Typhoon, with a federal agency remediation deadline of October 11, 2026. The additions tie directly to the same Integrity Tech / Flax Typhoon campaign disrupted by the FBI and DOJ this week. Federal agencies and critical infrastructure operators must prioritize these five flaws immediately given the tight deadline.

Relevance score: 86.0/100

# More from October 10