Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
CISA Adds Five Flaws Exploited by Flax Typhoon to Must-Patch List, Sets Oct. 11 Deadline for Federal Agencies

Since the Justice Department and FBI announced the seizure of seven domains tied to China-linked hacking tools on Oct. 8, the practical work has shifted to patching. CISA added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, Oct. 8, after they were abused by the actor known as Flax Typhoon.
Federal agencies must apply patches or stop using the affected products by Oct. 11, 2026. That is three days after the listing and two days from today, Oct. 9.
What went on the list
One of the five is CVE-2015-3306, an improper access control flaw in ProFTPD with a CVSS score of 10.0, the maximum. The identifier dates the bug to 2015.
The five additions are part of a larger set. The joint advisory says the activity targeted eight vulnerabilities in total. The other three were already in the KEV catalog.
The attackers used those flaws for initial access to victim organizations and for siphoning data. The advisory describes the methods: scanning tools, cross-site scripting attacks, and password spraying against Microsoft Exchange servers. For persistence, the actors used VPN software. They pulled out emails and credentials with scripts.
The advisory behind the deadline
The KEV update came alongside a joint advisory from the U.S., Australia, Canada, Japan, New Zealand, Spain and the U.K. CISA, the FBI and the NSA led the U.S. side.
The advisory says Integrity Technology Group, a China-based cybersecurity company with ties to the Chinese government, enables the threat actors. It says their tactics match activity publicly tracked as Flax Typhoon, Ethereal Panda and Red Juliett.
According to the advisory, the actors target edge devices that organizations do not closely monitor, in order to keep long-term, stealthy access. CISA said the findings come from real-world investigations and observed activity in North America, Southeast Asia and Africa.
The advisory lists healthcare, manufacturing, government and IT organizations among the targets. It recommends prompt patching, multifactor authentication and shutting off unused services.
The warning from CISA
"Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," said Chris Butera, CISA's acting executive assistant director for cybersecurity.
That is a statement about positioning, not about an attack that has already happened. Butera urged organizations to read the advisory and implement its mitigations.
The FBI framed the company as a supplier to the Chinese state. "The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity," said Brett Leatherman, assistant director of the FBI's Cyber Division. "By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure."
What the seizures do and do not fix
The seized domains supported two tools. Microscan is a vulnerability scanner and FishHub is a spearphishing tool. According to the Justice Department's court filings, Microscan was used between April and December 2022 to scan a South Carolina power company, a multinational non-governmental organization, airports in Japan and Poland, and Taiwanese natural gas and power companies.
The filings say two Taiwanese universities were scanned and then broken into. The Justice Department says about 20 Taiwanese universities are confirmed FishHub victims. FBI special agent Adam James said in a seizure warrant affidavit that the tool was named FishHub because it facilitated phishing.
Scanning a network is not the same as breaching it, and the court records do not claim every scanned target was compromised. Taking a domain also does not remove malware from computers that are already infected. That is why the patch deadline matters. The vulnerabilities are the entry points, and they stay open until someone closes them.
This is not Washington's first move against the company. The U.S. sanctioned Integrity Technology Group last year. In 2024 it made the company the focus of a takedown operation against a large botnet. The newest filings describe a Mirai-variant botnet of internet-of-things devices that helped carry out Microscan's scans.
The seizures were court-authorized in the Western District of Pennsylvania. No charges against Integrity Technology Group or named individuals were described in the announcements.
What comes next
The next fixed date is Oct. 11, when federal agencies must have the five flaws patched or the affected products out of service. The agencies have not said how many federal systems run the vulnerable software, or whether any has already been compromised.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.