US seizes Flax Typhoon tools, adds five flaws to CISA KEV
DOJ and FBI seized Flax Typhoon tools Microscan and FishHub tied to Integrity Technology Group, and CISA added five exploited flaws to its KEV catalog with an October 11 federal deadline.
The US government moved against the China-linked Flax Typhoon group on two fronts this week. The Justice Department and FBI seized two of its tools, and CISA added five actively exploited flaws to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of October 11, 2026.
The tool seizures
DOJ and the FBI seized Microscan, a vulnerability scanner, and FishHub, a spearphishing tool, through court-authorized domain seizures in the Western District of Pennsylvania, announced October 8. CyberScoop reports both are attributed to Integrity Technology Group, a China-based company the US sanctioned last year and targeted in a 2024 botnet takedown. Microscan reportedly ran on a Mirai-variant IoT botnet; named targets include a South Carolina power company, airports in Japan and Poland, and universities and critical-infrastructure firms in Taiwan.
The seizures accompanied a joint FBI/CISA/NSA advisory (AA26-281A) and a multi-nation advisory co-signed by Australia, Canada, Japan, New Zealand, Spain, the UK, and the US. FBI Cyber Division head Brett Leatherman said "Integrity Technology Group, a China-based company with ties to the Chinese government, is one of those enterprises." CISA's acting cybersecurity chief Chris Butera added that "Chinese government-affiliated actors continue to position themselves within critical infrastructure networks."
The five KEV additions
CISA's catalog additions, following reported abuse by Flax Typhoon, are all older flaws in internet-facing software, per The Hacker News:
- CVE-2015-3306 (CVSS 10.0) — ProFTPD, improper access control.
- CVE-2021-3199 (CVSS 9.8) — ONLYOFFICE Docs, path traversal.
- CVE-2016-3081 (CVSS 8.1) — Apache Struts, command injection.
- CVE-2015-5477 (CVSS 7.5) — ISC BIND, reachable assertion / denial of service.
- CVE-2023-22894 (CVSS 7.2) — Strapi, cleartext storage of sensitive information.
Federal agencies must patch or discontinue use of the affected products by October 11. The CISA KEV catalog is the authoritative listing.
What to do today
- Treat the KEV list as a hunt scope, not just a patch queue. All five flaws are years old; if any of these services is internet-facing and unpatched, assume it has been scanned.
- Block and hunt the seized infrastructure using the indicators in advisory AA26-281A, and review IoT/edge devices for Mirai-variant botnet activity feeding Microscan.
- Prioritize ProFTPD (CVE-2015-3306) and ONLYOFFICE (CVE-2021-3199) — the two highest-scored and the likeliest to sit exposed on forgotten hosts.
Context
The pattern is now familiar from Volt and Salt Typhoon: China-linked actors prepositioning in critical infrastructure using long-patched flaws on edge and appliance software rather than zero-days. It rhymes with the MI5 and partner warning on Chinese MSS espionage earlier this month. The attribution to Integrity Technology Group is firmer than most Typhoon reporting — it rests on existing US sanctions, not vendor framing alone — but the operational takeaway is the dull one: a 2015 ProFTPD flaw scoring a perfect 10 is still a live door, and nation-state crews walk through the cheapest one available.