CISA, the FBI, the NSA and partners in the UK, Australia, Canada, Japan, New Zealand and Spain published joint advisory AA26-281A on 8 October, warning that Integrity Technology Group (Integrity Tech), a China-based cybersecurity company with links to the Chinese government, enables threat actors targeting critical infrastructure worldwide through large-scale botnets, hosted VPN infrastructure, living-off-the-land techniques and repositories of exploitation tools. The authoring organisations assess the activity is consistent with the clusters publicly tracked as Flax Typhoon, Ethereal Panda and Red Juliett, and say the actors target edge devices organisations monitor less closely in order to hold long-term, stealthy access; victims span government services, critical manufacturing, healthcare and IT, plus US law enforcement, education and religious organisations, with targets also across Southeast Asia, Africa and North America. The advisory lists eight exploited CVEs — including CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2021-3199 (ONLYOFFICE) and CVE-2023-22894 (Strapi) — that also appear in CISA's KEV additions of the same day. In parallel, the Justice Department seized the domains and infrastructure behind Microscan, a vulnerability-scanning tool used since 2017, and FishHub, a phishing-and-payload tool, and published a 58-page IC3 advisory; documented Microscan victims include a South Carolina power company and Japanese and Polish airports, and FishHub remote access was used against about 20 Taiwanese universities.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-10-09 |
| Source | CISA advisory AA26-281A |
| Reliability | Tier 1 |
| CVEs | CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199, CVE-2023-22894 |