News with an accent.

A technician in a blue shirt checks a server and a network switch mounted in a rack.
Un técnico revisa un servidor de red.Bill Branson / NIH (dominio público)
Privacy

Ten agencies tie a Chinese firm to eight old software flaws

CISA, the FBI and the NSA name Integrity Technology Group in an email-theft campaign that used flaws dating to 2014. Five join CISA's exploited list.

On Oct. 8, 2026, the U.S. cybersecurity agency CISA published advisory AA26-281A together with the FBI, the NSA and agencies from the United Kingdom, Australia, Canada, Japan, New Zealand and Spain. The document attributes to Integrity Technology Group, a Chinese company with ties to its government, a campaign that mixes automated scanning with hands-on access to steal sensitive information, including email.

The activity overlaps with the names Flax Typhoon, Ethereal Panda and Red Juliett. According to the document, those actors could also act apart from the company. It is an attribution by the agencies: the sources consulted show no public response from Integrity Technology Group.

The advisory says the activity goes back to at least mid-January 2021, with isolated indicators from 2016. Targets include U.S. critical infrastructure in sectors such as government, manufacturing, health and information technology, plus law enforcement, education and religious organizations. It cites victims of email theft in Southeast Asia. It also mentions affected organizations in Africa and does not name North American countries.

The eight vulnerabilities

Eight vulnerabilities, each identified by a CVE code, are listed as successfully exploited. The five marked with an asterisk were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, the list the agency uses to require patching by U.S. federal agencies.

Vulnerabilities that advisory AA26-281A lists as exploited
ProductCVETypeAffected versions
GNU BashCVE-2014-6278Remote code executionup to 4.3 (bash43-026)
ProFTPDCVE-2015-3306*Unauthorized read1.3.5
ISC BIND 9CVE-2015-5477*Denial of servicebefore 9.9.7-P2; 9.10.x before 9.10.2-P3
Apache StrutsCVE-2016-3081*Remote code execution2.3.19 to 2.3.28
Pulse Connect SecureCVE-2019-11510Unauthorized read8.2 before 8.2R12.1; 8.3 before 8.3R7.1; 9.0 before 9.0R3.4
GitLabCVE-2021-22205Remote code executionall since 11.9
ONLYOFFICE DocumentServerCVE-2021-3199*Unauthorized write5.1.5 to 5.6.2
StrapiCVE-2023-22894*Information disclosureup to 4.5.5
Source: CISA, advisory AA26-281A

All date from 2014 to 2023, so the advisory presents them as open doors in systems that were never updated, not as new flaws. It also does not list the fixed versions of each one: it recommends applying patches, and each vendor publishes its own.

Among the mitigations, CISA lists multifactor authentication on web email and VPN, turning off unused services, segmenting networks and watching for unexpected Active Directory replication and abnormal data uploads.

The sources consulted do not mention victims in Mexico. Still pending are the reading of other signatories, such as Britain's NCSC or Australia's agency, and a response from the company named.

Keep reading

El Mediático counts visits without cookies, with its own measurement and with Google Analytics, which receives basic data about your visit. Only if you accept does Google Analytics also store cookies and, where advertising is active, show personalized ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)