
Ten agencies tie a Chinese firm to eight old software flaws
CISA, the FBI and the NSA name Integrity Technology Group in an email-theft campaign that used flaws dating to 2014. Five join CISA's exploited list.
On Oct. 8, 2026, the U.S. cybersecurity agency CISA published advisory AA26-281A together with the FBI, the NSA and agencies from the United Kingdom, Australia, Canada, Japan, New Zealand and Spain. The document attributes to Integrity Technology Group, a Chinese company with ties to its government, a campaign that mixes automated scanning with hands-on access to steal sensitive information, including email.
The activity overlaps with the names Flax Typhoon, Ethereal Panda and Red Juliett. According to the document, those actors could also act apart from the company. It is an attribution by the agencies: the sources consulted show no public response from Integrity Technology Group.
The advisory says the activity goes back to at least mid-January 2021, with isolated indicators from 2016. Targets include U.S. critical infrastructure in sectors such as government, manufacturing, health and information technology, plus law enforcement, education and religious organizations. It cites victims of email theft in Southeast Asia. It also mentions affected organizations in Africa and does not name North American countries.
The eight vulnerabilities
Eight vulnerabilities, each identified by a CVE code, are listed as successfully exploited. The five marked with an asterisk were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, the list the agency uses to require patching by U.S. federal agencies.
| Product | CVE | Type | Affected versions |
|---|---|---|---|
| GNU Bash | CVE-2014-6278 | Remote code execution | up to 4.3 (bash43-026) |
| ProFTPD | CVE-2015-3306* | Unauthorized read | 1.3.5 |
| ISC BIND 9 | CVE-2015-5477* | Denial of service | before 9.9.7-P2; 9.10.x before 9.10.2-P3 |
| Apache Struts | CVE-2016-3081* | Remote code execution | 2.3.19 to 2.3.28 |
| Pulse Connect Secure | CVE-2019-11510 | Unauthorized read | 8.2 before 8.2R12.1; 8.3 before 8.3R7.1; 9.0 before 9.0R3.4 |
| GitLab | CVE-2021-22205 | Remote code execution | all since 11.9 |
| ONLYOFFICE DocumentServer | CVE-2021-3199* | Unauthorized write | 5.1.5 to 5.6.2 |
| Strapi | CVE-2023-22894* | Information disclosure | up to 4.5.5 |
All date from 2014 to 2023, so the advisory presents them as open doors in systems that were never updated, not as new flaws. It also does not list the fixed versions of each one: it recommends applying patches, and each vendor publishes its own.
Among the mitigations, CISA lists multifactor authentication on web email and VPN, turning off unused services, segmenting networks and watching for unexpected Active Directory replication and abnormal data uploads.
The sources consulted do not mention victims in Mexico. Still pending are the reading of other signatories, such as Britain's NCSC or Australia's agency, and a response from the company named.



