Flax Typhoon Actively Exploits Five Critical Flaws, CISA Urges Action
China-linked group Flax Typhoon is exploiting five high-severity vulnerabilities. CISA mandates federal agencies to patch before October 11.
TL;DR
- CISA adds five flaws to KEV catalog exploited by Flax Typhoon.
- One flaw, CVE-2015-3306, carries a maximum CVSS score of 10.0.
- Federal agencies must remediate by October 11 to comply.
- ProFTPD and other systems are reportedly compromised.
- Organizations urged to audit and patch exposed systems immediately.
A China-linked advanced persistent threat (APT) group called Flax Typhoon is actively exploiting five critical security vulnerabilities. In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added these flaws to its Known Exploited Vulnerabilities (KEV) catalog and set a binding deadline of October 11 for federal agencies to apply necessary patches.
The vulnerabilities span multiple systems and include both outdated and recently identified issues. Organizations using affected software should treat this as a high-priority call to action, especially those operating critical infrastructure or handling sensitive data.
Vulnerabilities Under Attack
- CVE-2015-3306 affects ProFTPD servers and allows remote code execution due to improper access controls.
- This flaw has a CVSS score of 10.0, indicating critical severity with widespread potential for exploitation.
- Additional vulnerabilities targeted include weaknesses in web applications and network protocols.
- Flax Typhoon leverages these flaws for initial access and lateral movement within target networks.
- Many of the exploited systems are found in unpatched, internet-facing environments.
What Organizations Should Do
- Audit systems for exposure to CVE-2015-3306 and related vulnerabilities immediately.
- Prioritize patching and mitigation steps for all assets listed in CISA's KEV catalog.
- Implement network segmentation and restrict unnecessary access to legacy services like FTP.
- Monitor logs for suspicious activity indicative of Flax Typhoon tactics.
- Ensure third-party vendors and supply chains are also compliant with updated security directives.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.