Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
AI-summarised brief · reviewed before publication
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after a China‑linked threat actor, Flax Typhoon, abused them. The update aligns with a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the U.K., and the U.S., warning of attacks by Integrity Technology Group that target eight flaws, including the five added. Exploits involve scanning, cross‑site scripting, password spraying on Microsoft Exchange, VPN persistence, and data exfiltration. Federal agencies must patch or retire affected systems by October 11, 2026.
💡 Why It Matters
- · The deadline forces federal agencies to address a surge in AI‑driven, cross‑platform attacks that threaten critical infrastructure and sensitive data.