Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies

Summary

CISA has added five vulnerabilities exploited by the China-linked Flax Typhoon threat actor to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are given an October 11 deadline to patch these flaws. One of the listed vulnerabilities is CVE-2015-3306 in ProFTPD, which has a critical CVSS score of 10.0.

IFF Assessment

FOE

The article highlights active exploitation of vulnerabilities by a threat actor, posing a direct risk to federal agencies and increasing the likelihood of successful attacks.

Severity

10.0 Critical

CISA KEV: Listed as actively exploited. Federal patch due: October 11, 2026. Known ransomware use: Unknown.

Defender Context

This article is highly relevant for defenders as it details active exploitation by a known threat actor, signaling immediate risks to systems using the identified vulnerabilities. Agencies must prioritize patching these flaws to mitigate potential breaches and further exploitation by Flax Typhoon.

Read Full Story →