10/08/2026 2:30 PM EDT

Today, the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA) and international partners released a joint Cybersecurity Advisory Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data. The advisory details malicious cyber activity enabled by the Integrity Technology Group (Integrity Tech), a China-based company with ties to the Chinese government, targeting organizations around the globe—including the Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology U.S. critical infrastructure sectors, as well as law enforcement, education, and religious organizations.
These Integrity Tech-enabled threat actors employ a sophisticated combination of large-scale botnets, virtual private network (VPN) infrastructure, living off the land techniques, and repositories of computer network exploitation tools to infiltrate networks and exfiltrate sensitive data. Their tactics, techniques, and procedures (TTPs) are consistent with cyber activity known publicly as Flax Typhoon, Ethereal Panda and Red Juliett—among other names—and include exploiting vulnerabilities through automated scanning tools, cross-site scripting (XSS) attacks, and password spraying. This advisory shares detection and mitigation guidance to help network defenders across public and private sector organizations reduce the risk of compromise and provides a full list of successfully exploited Common Vulnerabilities and Exposures (CVEs). CISA has added the following five CVEs to the Known Exploited Vulnerabilities Catalog (KEV) based on this activity:
Key Actions to Protect Your Organization:
- Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols.
- Sanitize user input in web applications to prevent possible XSS payload injection.
- Implement identity, credential, and access management (ICAM) policies, and require multifactor authentication for services (to the extent possible).
Read the full advisory and leverage available resources, such as CISA’s Eviction Strategies Tool and Internet Exposure Reduction Guidance to develop tailor eviction strategies and secure internet-exposed devices. Visit CISA’s China Threat Overview and Advisories page for more information on Chinese government-linked threat activity.
Discover more from #News247WorldPress
Subscribe to get the latest posts sent to your email.

