Advisory AA26-281A of 8 October describes how the company supplies tools and infrastructure to threat actors whose techniques CISA calls consistent with Flax Typhoon. The same day KEV received five holes from its list, the newest numbered from 2023.
- 8 October 2026: CISA, FBI, NSA and partners from six countries warn that China-based Integrity Technology Group, with ties to the Chinese government, supplies tools, infrastructure and intrusions for threat actors.
- The actors' techniques are consistent with the publicly known Flax Typhoon, Ethereal Panda and Red Juliett (CISA), but the advisory does not equate them. They target edge devices that organizations do not monitor closely.
- The same day KEV received five holes from the advisory's list, all with an 11 October 2026 deadline under directive BOD 26-04. The deadline is for US federal civilian agencies; for everyone else it is a signal.
The newest of the five holes is numbered from 2023. The oldest, from 2015. The actors in the advisory get in through old holes and go after devices that organizations do not monitor closely.
Who does the advisory describe? A company, not a group. According to CISA and the FBI, Integrity Tech acquires or develops tools, hosts infrastructure and breaches networks for others. The link to Flax Typhoon is in consistent techniques, and the advisory itself notes that these actors may also act outside Integrity Tech. So do not put an equals sign between the two names.
The most concrete part of the advisory is how they get in and how they stay. Exchange mail, which the actors guess at with password spraying. SoftEther, a real VPN program whose installers they name conhost.exe or dllhost.exe so it looks familiar. Endpoint protection is less likely to flag it, because the program is legitimate.
The deadline is 11 October, a Sunday, three days after the announcement. It applies to US federal civilian agencies under directive BOD 26-04; for everyone else it is a signal, not an obligation.
If you run BIND, ProFTPD, Struts, ONLYOFFICE Docs or Strapi, check the versions today and look for traces of a breach that has already happened: the advisory asks for both. For Strapi, CISA adds in the catalog that the product may be unsupported and advises you to stop using it or move to a supported version. If you have none of the five, the advisory starts with the simplest thing: turn off the services and ports you do not use.