we_are_coded.by CODE · The world, decoded
БГ
CISA

CISA, FBI and NSA warn about China-based Integrity Tech, and five old holes from the advisory entered the KEV catalog with an 11 October deadline

CISA · event date: 8 October 2026Security

Advisory AA26-281A of 8 October describes how the company supplies tools and infrastructure to threat actors whose techniques CISA calls consistent with Flax Typhoon. The same day KEV received five holes from its list, the newest numbered from 2023.

In short
  • 8 October 2026: CISA, FBI, NSA and partners from six countries warn that China-based Integrity Technology Group, with ties to the Chinese government, supplies tools, infrastructure and intrusions for threat actors.
  • The actors' techniques are consistent with the publicly known Flax Typhoon, Ethereal Panda and Red Juliett (CISA), but the advisory does not equate them. They target edge devices that organizations do not monitor closely.
  • The same day KEV received five holes from the advisory's list, all with an 11 October 2026 deadline under directive BOD 26-04. The deadline is for US federal civilian agencies; for everyone else it is a signal.
Checked on9 October 2026Responsible editorCvetelin IvanovHow we workMethod · Corrections

The newest of the five holes is numbered from 2023. The oldest, from 2015. The actors in the advisory get in through old holes and go after devices that organizations do not monitor closely.

The facts: on 8 October 2026 CISA, FBI and NSA, together with the UK's NCSC, Australia's ACSC, Canada's Cyber Centre, Japan's NPA and NCO, New Zealand's NCSC and Spain's CNI, published advisory AA26-281A about Integrity Technology Group, a China-based cybersecurity company with ties to the Chinese government. Per the advisory, the company supplies tools, infrastructure (botnets and VPN) and intrusions to threat actors whose techniques CISA calls consistent with the publicly known Flax Typhoon, Ethereal Panda and Red Juliett; the advisory also notes that these actors may perform activity not associated with Integrity Tech. The targets are edge devices that organizations do not monitor closely. In the US the targets are in government, critical manufacturing, healthcare and information technology, as well as law enforcement, education and religious organizations, plus organizations across Southeast Asia, Africa and North America. The techniques are scanning, XSS, password spraying against Microsoft Exchange, SoftEther VPN for persistent access and exfiltration of email. The advisory lists eight vulnerabilities, and the same day CISA added five of them to its Known Exploited Vulnerabilities (KEV) catalog: ISC BIND (CVE-2015-5477, denial of service), ProFTPD, Apache Struts (CVE-2016-3081, command execution), ONLYOFFICE Docs and Strapi (CVE-2023-22894; CISA notes the product may be end-of-life). The deadline for all five is 11 October 2026 under directive BOD 26-04; for four of them (all but BIND) the catalog, under the same directive, also requires a forensic triage to check whether the system is already compromised. CISA marks their use in ransomware campaigns as unknown.

Who does the advisory describe? A company, not a group. According to CISA and the FBI, Integrity Tech acquires or develops tools, hosts infrastructure and breaches networks for others. The link to Flax Typhoon is in consistent techniques, and the advisory itself notes that these actors may also act outside Integrity Tech. So do not put an equals sign between the two names.

The most concrete part of the advisory is how they get in and how they stay. Exchange mail, which the actors guess at with password spraying. SoftEther, a real VPN program whose installers they name conhost.exe or dllhost.exe so it looks familiar. Endpoint protection is less likely to flag it, because the program is legitimate.

A hole is old only for the one who has patched it.

The deadline is 11 October, a Sunday, three days after the announcement. It applies to US federal civilian agencies under directive BOD 26-04; for everyone else it is a signal, not an obligation.

If you run BIND, ProFTPD, Struts, ONLYOFFICE Docs or Strapi, check the versions today and look for traces of a breach that has already happened: the advisory asks for both. For Strapi, CISA adds in the catalog that the product may be unsupported and advises you to stop using it or move to a supported version. If you have none of the five, the advisory starts with the simplest thing: turn off the services and ports you do not use.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - press release on Integrity Technology Group, 08.10.2026→CISA - advisory AA26-281A, 08.10.2026→CISA KEV (CVE-2015-5477, CVE-2016-3081, CVE-2023-22894), 08.10.2026→CISA - BOD 26-04: Prioritizing Security Updates Based on Risk, 10.06.2026
Original: https://wearecoded.com/en/articles/cisa-integrity-tech-pet-stari-dupki-v-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news