Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306…
Sources
- T2Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal AgenciesThe Hacker News
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| kev added | 50 |
| kev short fuse — 3 days to remediate | 15 |
| ssvc active | 35 |
| epss high | 20 |
| public poc — 18 repositories | 20 |