Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Advisory at a Glance Title Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data Original Publication October 8, 2026 Executive Summary Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…
Excerpt from the primary source: CISA Cybersecurity Advisories
Who is affected
Home users · Small businesses · Enterprises · Security professionals · Critical infrastructure
Affected technology: BIND, Community and Enterprise Editions, Docs, Exchange Server, GNU Bash, ProFTPD, Pulse Connect Secure, Strapi, Struts
Why it matters
CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.
Automated: stated only from CISA listings and the exploitation evidence in the sources below.
What you should do · Act now
Treat this as an emergency. Identify every system running Exchange Server, Struts, Pulse Connect Secure, Community and Enterprise Editions, GNU Bash, BIND, Strapi, Docs and ProFTPD, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.
CISA's required action for CVE-2014-6278: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. " US federal civilian agencies must comply by October 23, 2025.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Related
ISC BIND Data Processing Errors Vulnerability (CVE-2015-5477) is being actively exploited, CISA warns
CISA added CVE-2015-5477 (ISC BIND) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
CISA lists this as exploited in the wild. Unpatched BIND systems are exposed to active attacks now.
Apply the vendor's security update for BIND.
Strapi Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-22894) is being actively exploited, CISA warns
CISA added CVE-2023-22894 (Strapi Strapi) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL)…
CISA lists this as exploited in the wild. Unpatched Strapi systems are exposed to active attacks now.
Apply the vendor's security update for Strapi.
ONLYOFFICE Docs Server Path Traversal Vulnerability (CVE-2021-3199) is being actively exploited, CISA warns
CISA added CVE-2021-3199 (ONLYOFFICE Docs) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.
CISA lists this as exploited in the wild. Unpatched Docs systems are exposed to active attacks now.
Treat this as an emergency.
ProFTPD Improper Access Control Vulnerability (CVE-2015-3306) is being actively exploited, CISA warns
CISA added CVE-2015-3306 (ProFTPD ProFTPD) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
CISA lists this as exploited in the wild. Unpatched ProFTPD systems are exposed to active attacks now.
Treat this as an emergency.
