Threat Intelligence

Flax Typhoon Hackers Target Exchange Servers as Seven Countries Issue Joint Warning

The Hacker News · 9 Oct 2026
Key Takeaway Check whether your Exchange servers and VPN software are fully patched, review the KEV catalog for flaws affecting your systems, and use strong, unique passwords with multi-factor authentication to blunt password spraying.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they were abused by a China-linked threat actor known as Flax Typhoon. The move coincides with a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the U.K. and the U.S. The advisory warns of attacks enabled by a China-based cybersecurity company called Integrity Technology Group.

According to the source, the operations targeted eight vulnerabilities in total, including the five newly listed. The other three were already in the KEV catalog. Attackers used these flaws to gain initial access to organisations and take sensitive data. The activity involved scanning tools, cross-site scripting attacks and password spraying against Microsoft Exchange servers. The attackers then set up persistence through VPN software and used scripts to exfiltrate emails and credentials.

CISA's Chris Butera said Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology systems, with the aim of disrupting critical functions at a future time of their choosing. U.S. federal agencies must apply the necessary patches or stop using the affected products by October 11, 2026. With Australia among the advisory's authors, local businesses running Exchange servers or VPN software have good reason to pay attention.

Flax Typhoon CISA KEV Microsoft Exchange Patch Management

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.