AA26-281A: Ten-Nation Advisory Names a Chinese Contractor, and Five Decade-Old Bugs Enter KEV the Same Day

On 8 October 2026, CISA published AA26-281A, a joint cybersecurity advisory on Chinese government-linked intrusion activity enabled by a named commercial entity: Integrity Technology Group. The authoring list is unusually broad — ten countries' agencies: the FBI, CISA and NSA from the US, alongside NCSC-UK, Australia's ASD/ACSC, the Canadian Centre for Cyber Security, Japan's National Police Agency and National Cybersecurity Office, New Zealand's NCSC, and Spain's Centro Nacional de Inteligencia.

The advisory states that its technical content comes from evidence recovered during multiple FBI investigations into Integrity Tech, and that the enabled actors use TTPs consistent with activity publicly tracked as Flax Typhoon, Ethereal Panda, and Red Juliett — while cautioning that vendor naming is not a 1:1 match to the US government's own grouping. Targeting spans US government services and facilities, critical manufacturing, healthcare and public health, and IT, plus law enforcement, education and religious organisations, and victims across Southeast Asia, Africa and North America.

The detail most defenders will miss: five KEV additions, dated the same day

Appendix B lists eight CVEs that the actors successfully exploited, recovered from penetration-testing scripts. Five carry an asterisk marking them as newly added to CISA's Known Exploited Vulnerabilities catalog. We checked the KEV catalog directly to confirm the dates rather than relying on the asterisks:

  • CVE-2015-3306 — ProFTPD 1.3.5, improper access control (CWE-284), unauthorized read. KEV-added 8 October 2026.
  • CVE-2015-5477 — ISC BIND 9.x before 9.9.7-P2 / 9.10.2-P3, denial of service. KEV-added 8 October 2026.
  • CVE-2016-3081 — Apache Struts 2.3.19–2.3.28 ranges, command injection (CWE-77), RCE. KEV-added 8 October 2026.
  • CVE-2021-3199 — ONLYOFFICE DocumentServer 5.1.5–5.6.2, path traversal, unauthorized write. KEV-added 8 October 2026.
  • CVE-2023-22894 — Strapi up to 4.5.5, cleartext storage of sensitive information (CWE-312). KEV-added 8 October 2026.

The other three were already catalogued: CVE-2019-11510 (Pulse Connect Secure) and CVE-2021-22205 (GitLab) since 3 November 2021 — both flagged for known ransomware campaign use — and CVE-2014-6278 (GNU Bash) since 2 October 2025. The KEV catalog we read was version 2026.10.08, released 8 October 2026 at 20:09 UTC with 1,739 entries; these five were five of the nine additions made in October so far.

That is the operationally sharp fact in this advisory. A vulnerability disclosed in 2015 entered the federal must-patch catalog in October 2026 because an FBI investigation recovered proof it was still working. KEV inclusion triggers remediation deadlines for US federal civilian agencies and is widely used as a prioritisation input in the private sector, so five records that most risk-scoring pipelines had long since aged out of relevance just reappeared at the top of the queue. If your prioritisation is EPSS- or CVSS-weighted with a recency bias, a ProFTPD bug from 2015 is exactly the kind of finding it will have buried.

Scanning at industrial scale, with a product behind it

The reconnaissance section describes an open-source toolkit — BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, wpscan — focused on ports 21, 22, 53, 80, 443 and 1080, enumerating PHP and ASP pages. The advisory's own reading of that choice is worth quoting in substance: reliance on commodity GitHub tooling "suggests the threat actors tend to look for more vulnerable targets." This is breadth-first opportunism, not precision targeting.

Behind it sits MicroScan, described as a Python-based web application in use since as early as 2017 containing over 1,300 penetration-testing scripts, with an account dashboard displaying detected vulnerabilities. Targets named include OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins and Apache Struts. A multi-tenant scanning platform with a login and a findings dashboard is a product, and that framing is the advisory's point: Integrity Tech is characterised as a for-profit company that acquires or builds tooling, hosts infrastructure, and compromises networks — contract offence with a customer-facing UI.

Living off legitimate software: SoftEther as the persistence layer

The persistence tradecraft is the part defenders can act on immediately. Rather than deploying custom implants, the actors install SoftEther VPN clients on victim devices, configured to reconnect automatically at startup, with installers renamed conhost.exe or dllhost.exe to pass as normal Windows binaries (T1036.003). Delivery is PowerShell or LOTL binaries on Windows, curl or wget on Linux/Unix. The advisory is explicit about why this works: endpoint detection is less likely to flag SoftEther because it is legitimate VPN software.

Credential access follows the same logic. EBurst, an open-source Python tool, sprays and guesses passwords against Microsoft Exchange and Office 365 across ten interfaces — ECP, EWS, OAB, OWA, RPC, API, MAPI, PowerShell, Autodiscover and Microsoft-Server-ActiveSync. The advisory specifically instructs defenders to cover all ten, which is a pointed correction to the common pattern of monitoring OWA and leaving Autodiscover or ActiveSync unwatched. Domain-wide credential theft comes from DC.exe performing DCSync (T1003.006) over RPC against the domain controller.

Collection is similarly unglamorous and effective: a PHP bot built from Curlc4.txt that drives the Exchange Web Services API directly to pull mail, calendars and contacts, renames its child process to crypto, searches a fixed list of directories for a writeable staging location, and compresses — sometimes RC4- or AES-128-CBC-encrypting — before upload. A Linux binary called office-cli automates Outlook 365 exfiltration from client_id, tenant_id and secret config files, which the advisory notes evades detection precisely because it uses legitimate access methods. Stolen mail is then served through a custom web application that lets third parties retrieve specific accounts' content by URL arguments — the access-resale end of the business model. In some cases, the advisory says, access to exfiltrated data was restricted to IP addresses in Xiamen, China.

Why this belongs on an AI-security site

There is no AI component in AA26-281A, and we are not inventing one. It matters here for a structural reason. The same week Anthropic launched a program premised on frontier models compressing vulnerability discovery, a ten-nation investigation documented a decade-long campaign that needed none of it: commodity scanners, a 1,300-script library accumulated since 2017, legitimate VPN software for persistence, and bugs from 2015 that still land. The constraint on this adversary was never discovery capability. It was the long tail of unpatched, internet-exposed infrastructure — and that tail is unaffected by how fast anyone's model finds new bugs.

The second connection is the service model. Integrity Tech is described as a for-profit intermediary selling scanning, hosting and intrusion as capability to a state ecosystem. That is the same wholesale-capability structure now forming around AI-assisted offence, and it is the layer where attribution gets hard: the advisory itself warns that vendor cluster names do not map cleanly onto the US government's understanding, precisely because a shared contractor serves multiple consumers.

What to do

  • Re-run your KEV delta against the 8 October catalog. Five additions in one advisory, four of them from 2015–2016 and one from 2021. Age-weighted prioritisation will have deprioritised all of them. Check ProFTPD, BIND, Struts, ONLYOFFICE DocumentServer and Strapi exposure explicitly by version, using the ranges in Appendix B.
  • Hunt for SoftEther, not for malware. Look for VPN clients configured to auto-reconnect at startup that nobody provisioned, and for conhost.exe or dllhost.exe running from non-system paths. A legitimate-software persistence channel will not trip signature-based EDR.
  • Extend Exchange brute-force monitoring to all ten EBurst interfaces. Autodiscover, ActiveSync, MAPI, OAB and RPC are the ones most often left out of password-spray detection logic that was written around OWA.
  • Alert on unexpected Active Directory replication. The advisory names this as a specific mitigation, and DCSync from a non-DC host is one of the highest-signal detections available against this tradecraft.
  • Audit OAuth applications with mailbox access. office-cli works from client_id/tenant_id/secret tuples, which means revoking a user password does not evict it. Enumerate connected applications that can read mail and prune the ones nobody can account for.
  • Pull the machine-readable IOCs. CISA publishes AA26-281A indicators as STIX in both JSON and XML; load them rather than transcribing the nine SoftEther domains and natcloudservice[.]com infrastructure by hand.

Verification note: the advisory's release date and alert code, the ten authoring organisations, the Integrity Technology Group attribution and its stated Flax Typhoon / Ethereal Panda / Red Juliett overlap, the targeted sectors and regions, the scanning toolset and port list, MicroScan's 2017 timeframe and 1,300+ script count, the SoftEther persistence tradecraft and renamed installers, the EBurst interface list, the Curlc4/DC.exe/office-cli tooling descriptions, the Xiamen access restriction, the Appendix B CVE table with vendor/version/vulnerability-type columns, and the recommended mitigations were read by us directly from CISA's published advisory page. All five KEV addition dates, the three prior KEV dates, the catalog version 2026.10.08 and its 1,739-entry count were independently confirmed against CISA's machine-readable KEV JSON feed on 9 October 2026 rather than inferred from the advisory's asterisk notation. We did not retrieve or analyse the STIX IOC bundles, and the comparison to AI-assisted vulnerability discovery in the section above is our editorial assessment, not a claim made in the advisory.

Sources: