NoticiasNews

Flax Typhoon: CISA suma cinco fallas explotadas a su catálogo KEV y el FBI incauta siete dominiosFlax Typhoon: CISA Adds Five Exploited Flaws to KEV and the FBI Seizes Seven Domains

2026-10-09

El 9 de octubre de 2026 se conocieron dos movimientos coordinados contra el grupo Flax Typhoon, vinculado a China. Por un lado, CISA agregó cinco vulnerabilidades a su catálogo de Vulnerabilidades Explotadas Conocidas (KEV), con fecha límite del 11 de octubre para las agencias federales de EE. UU. Por otro, el FBI y el Departamento de Justicia incautaron siete dominios y desarticularon herramientas empleadas para escanear y, en algunos casos, infiltrar infraestructura crítica.

Las fallas incluidas

Entre las vulnerabilidades figuran fallas antiguas que siguen vivas en muchos entornos:

  • CVE-2015-3306 (CVSS 10.0): control de acceso indebido en ProFTPD que permite leer y escribir archivos arbitrarios de forma remota.
  • CVE-2021-3199 (CVSS 9.8): salto de ruta en ONLYOFFICE Docs cuando se usa JWT, que puede derivar en ejecución remota de código.
  • CVE-2023-22894 (CVSS 7.2): almacenamiento en texto claro de información sensible en Strapi, expuesta a quien acceda al panel de administración.
  • CVE-2016-3081 (CVSS 8.1), junto con una quinta falla incluida en el boletín.

El golpe judicial

Según The Hacker News, los dominios incautados incluyen nombres que imitan servicios conocidos, como outlook3650[.]com, youtubecard[.]com y linkedinns[.]net. El grupo se ha relacionado con Integrity Technology Group, una empresa de Beijing, y con la botnet Raptor Train, desmantelada en septiembre de 2024.

Qué deben hacer las empresas

La lección es que los atacantes no necesitan fallas nuevas: aprovechan software sin parchar de hace años. Conviene inventariar servicios expuestos (FTP, suites ofimáticas, CMS), aplicar parches y revisar accesos administrativos. Fuente: The Hacker News y cobertura de la incautación.

En TEKFENIX ayudamos a las empresas a ordenar este tipo de riesgo. Con Servigo365 centralizas incidentes y solicitudes de parcheo con trazabilidad, y con CumplimientoControl dejas evidencia auditable de la gestión de vulnerabilidades ante reguladores y auditores.

On October 9, 2026, two coordinated moves against China-linked Flax Typhoon came to light. CISA added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, with an October 11 deadline for U.S. federal agencies. Meanwhile, the FBI and the Department of Justice seized seven domains and disrupted tools used to scan and, in some cases, infiltrate critical infrastructure.

The flaws added

The list includes old bugs that remain alive in many environments:

  • CVE-2015-3306 (CVSS 10.0): improper access control in ProFTPD allowing remote read/write of arbitrary files.
  • CVE-2021-3199 (CVSS 9.8): path traversal in ONLYOFFICE Docs when JWT is used, potentially leading to remote code execution.
  • CVE-2023-22894 (CVSS 7.2): cleartext storage of sensitive information in Strapi, exposed to anyone with admin panel access.
  • CVE-2016-3081 (CVSS 8.1), plus a fifth flaw included in the alert.

The law enforcement action

According to The Hacker News, the seized domains include names mimicking well-known services, such as outlook3650[.]com, youtubecard[.]com and linkedinns[.]net. The group has been linked to Integrity Technology Group, a Beijing company, and to the Raptor Train botnet, taken down in September 2024.

What businesses should do

Attackers do not need new bugs: they exploit unpatched software that is years old. Inventory exposed services (FTP, office suites, CMS platforms), apply patches and review administrative access. Sources: The Hacker News and coverage of the seizure.

At TEKFENIX we help companies manage this kind of risk. With Servigo365 you centralize incidents and patch requests with traceability, and with CumplimientoControl you keep auditable evidence of vulnerability management for regulators and auditors.

← Volver al blog← Back to blog