CISA added CVE-2015-5477 (ISC BIND) to its Known Exploited Vulnerabilities catalog on October 8, 2026, which means there is reliable evidence of exploitation in the wild. ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
Why it matters
CISA lists this as exploited in the wild. Unpatched BIND systems are exposed to active attacks now.
Advisory at a Glance
Title
Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data
Original Publication
October 8, 2026
Executive Summary
Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal…
Why it matters
CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.
Act now
Treat this as an emergency.
CISA Cybersecurity AdvisoriesHomeSMBEnterprise+2
Recent intelligence
The latest developments from the last 30 days, newest first.