Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…

Excerpt from the primary source: CISA Cybersecurity Advisories

Who is affected

Home users · Small businesses · Enterprises · Security professionals · Critical infrastructure

Affected technology: BIND, Community and Enterprise Editions, Docs, Exchange Server, GNU Bash, ProFTPD, Pulse Connect Secure, Strapi, Struts

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Act now

Treat this as an emergency. Identify every system running Exchange Server, Struts, Pulse Connect Secure, Community and Enterprise Editions, GNU Bash, BIND, Strapi, Docs and ProFTPD, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.

CISA's required action for CVE-2014-6278: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. " US federal civilian agencies must comply by October 23, 2025.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

ISC BIND Data Processing Errors Vulnerability (CVE-2015-5477) is being actively exploited, CISA warns

CISA added CVE-2015-5477 (ISC BIND) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

Why it matters

CISA lists this as exploited in the wild. Unpatched BIND systems are exposed to active attacks now.

Patch

Apply the vendor's security update for BIND.

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

Strapi Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-22894) is being actively exploited, CISA warns

CISA added CVE-2023-22894 (Strapi Strapi) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL)…

Why it matters

CISA lists this as exploited in the wild. Unpatched Strapi systems are exposed to active attacks now.

Patch

Apply the vendor's security update for Strapi.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

ONLYOFFICE Docs Server Path Traversal Vulnerability (CVE-2021-3199) is being actively exploited, CISA warns

CISA added CVE-2021-3199 (ONLYOFFICE Docs) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

Why it matters

CISA lists this as exploited in the wild. Unpatched Docs systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns

CISA added CVE-2015-3306 (ProFTPD ProFTPD) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Why it matters

CISA lists this as exploited in the wild. Unpatched ProFTPD systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data | CybersecurityNews.us