The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their active abuse by a China-linked threat actor known as Flax Typhoon.
The emergency update to the KEV catalog underscores a broader, coordinated international effort to counter sophisticated cyber espionage operations directed at critical infrastructure and enterprise networks. The addition of the five vulnerabilities coincides with a sweeping joint advisory released by an international coalition of cybersecurity authorities from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States. This multinational warning explicitly highlights ongoing cyberattacks enabled by a China-based cybersecurity enterprise known as Integrity Technology Group.
According to intelligence gathered by the participating global agencies, these threat operations have been found to target a total of eight distinct security vulnerabilities—including the five newly added to the CISA catalog—to obtain initial access to targeted organizations and systematically siphon sensitive data. The adversary’s methodology involves a mix of automated scanning tools, cross-site scripting attacks, and password spraying directed at Microsoft Exchange servers. Once inside a network, the threat actors establish long-term persistence by leveraging vulnerable virtual private network (VPN) software, subsequently deploying custom scripts to exfiltrate confidential emails, internal documentation, and administrative credentials.

The coordinated warnings and catalog updates arrive on the heels of significant law enforcement actions. Notably, the remaining three vulnerabilities utilized in the Flax Typhoon campaign already hold a prominent place in the KEV catalog, reflecting their prior widespread exploitation in the wild. Federal authorities and intelligence agencies have increasingly targeted the operational infrastructure of these state-sponsored groups, recently resulting in actions such as the FBI seizing multiple domains associated with the disruption of Flax Typhoon’s command and control networks.
Government cybersecurity officials have issued stern warnings regarding the strategic positioning of foreign threat groups within domestic and international networks. "Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing," stated Acting Executive Assistant Director for Cybersecurity Chris Butera.
The involvement of a front-facing cybersecurity company like Integrity Technology Group highlights an evolving trend where state-backed threat actors utilize commercial enterprises as a veneer for espionage and operational staging. By blending malicious activities with the normal operational noise of security research and corporate services, these actors attempt to mask their intrusion vectors and complicate attribution efforts by international defenders. The joint advisory details how these networks are systematically leveraged to map critical assets, steal intellectual property, and maintain clandestine footholds across sectors ranging from telecommunications and defense to government and critical manufacturing.
In light of active exploitation and the severe risks posed to national security and operational resilience, federal civilian executive branch agencies are bound by strict binding operational directives. Under these rules, agencies are required to apply the necessary patches or discontinue the use of the vulnerable software products by October 11, 2026. Private sector organizations, critical infrastructure operators, and global enterprises are also strongly urged to review the updated CISA catalog and implement the recommended mitigations immediately to prevent potential compromise.
