Skip to content

Image: securityaffairs.com · rights & removal

Executive Summary

The Cybersecurity and Infrastructure Security Agency (CISA) added five specific vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: SITE CPFR and SITE CPTO commands/.. sequence in an image upload parameter, which can potentially execute code remotely when Dynamic Method Invocation is enabled. These five flaws are linked to cyber operations attributed to China-linked actors associated with Integrity Technology Group. This update occurs alongside a joint advisory from multiple nations, including the U.S., Australia, Canada, Japan, New Zealand, Spain, and the United Kingdom. Authorities have also taken action against tools associated with Integrity Tech used in cyber espionage. Reports indicate that eight vulnerabilities were exploited to gain initial access and steal information by attackers who used scanning tools, XSS, and password-spraying attacks on Microsoft Exchange servers, leveraging VPN software and scripts for access and data extraction.
The campaign involved the seizure of two tools, Microscan and FishHub, by the U.S. Department of Justice and FBI, allegedly operated by the Chinese company Integrity Tech. Microscan was used for network scanning, and FishHub was used to deliver malware via spear-phishing for remote access and file theft against critical infrastructure and other organizations globally. The joint advisory emphasizes the risks associated with tools combining large-scale scanning with exploitation. Federal agencies are required to address these vulnerabilities by October 11, 2026, as mandated by Binding Operational Directive (BOD) 22-01. Experts advise private organizations to review the catalog and address the flaws in their infrastructure.

Facts Only

* CISA added SITE CPFR and SITE CPTO commands/.. sequence in an image upload parameter to KEV catalog.
* The vulnerability allows for potential remote code execution when Dynamic Method Invocation is enabled.
* The five vulnerabilities are linked to cyber operations by China-linked actors associated with Integrity Technology Group.
* The update coincides with a joint advisory from Australia, Canada, Japan, New Zealand, Spain, the United Kingdom, and the United States.
* U.S. authorities took action against tools associated with Integrity Tech used in cyber espionage.
* Eight vulnerabilities were reportedly exploited to gain initial network access and steal sensitive information.
* Attackers utilized scanning tools, cross-site scripting (XSS), and password-spraying attacks against Microsoft Exchange servers.
* VPN software and scripts were used by attackers to maintain access and extract emails/credentials.
* The U.S. Department of Justice and FBI seized Microscan and FishHub tools allegedly operated by the Chinese company.
* Microscan was used to scan networks for vulnerable systems.
* FishHub utilized spear-phishing emails to deliver malware, enable remote access, and steal files.
* FCEB agencies must address identified vulnerabilities by October 11, 2026, under BOD 22-01.

Full Take

The narrative centers on the intersection of state-linked cyber operations, vulnerability disclosure management, and law enforcement action against specific toolsets. The pattern reveals a strategy where known technical flaws are weaponized not just for general exploitation but specifically to facilitate targeted espionage activities attributed to a geopolitical entity. The mention of Integrity Technology Group, coupled with the seizure of Microscan and FishHub by the FBI/DOJ, suggests a coordinated effort involving technical reconnaissance (scanning) followed by social engineering (spear-phishing) and system penetration. This moves the threat from accidental exposure (KEV) to intentional offensive action against specific targets.
The mechanism being highlighted is the amplification of risk through integrated toolchains that combine broad vulnerability scanning with targeted intrusion techniques, as emphasized by the joint advisory. This juxtaposition—publicly cataloged flaws versus covert operational use—forces a recognition that the threat landscape involves actors deliberately weaponizing technical knowledge and systemic weaknesses for geopolitical objectives. The call for federal agencies and private organizations to act based on CISA's listing and BOD mandates reflects an attempt to create a unified defensive posture against actors employing these integrated methods.
The implications touch upon cognitive sovereignty by exposing how large-scale cyber infrastructure, even when seemingly governed by official advisories, can be leveraged into instruments of foreign influence. The core tension lies in the gap between the public safety directive (patching vulnerabilities) and the underlying reality of state-sponsored exploitation using specific, seized tools. This raises questions about the efficacy of layered security when actors possess both technical knowledge and access to law enforcement mechanisms to disrupt those operations. What assumptions about agency—whether governmental or corporate—are being tested by the mandate to address these systemic toolsets? How does an organization respond when the threat attribution shifts from a general vulnerability warning to evidence of specific state-linked operational methodologies?

From the original · Security Affairs (Pierluigi Paganini)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: SITE CPFR and SITE CPTO commands./.. sequence in an image upload parameter to potentially execute code remotely.method: prefixes when Dynamic Method Invocation is enabled.The five vulnerabilities have been added to a broader list of flaws…
Read the full story at securityaffairs.com

Sentinel — Human

Confidence

This text reads like a synthesized summary of official cybersecurity news, combining facts from various sources into a coherent narrative about an ongoing cyber campaign.

Signals Detected
low severity: Moderate sentence length variance; direct, factual reporting style.
low severity: Clear informational flow linking vulnerability disclosure to attributed actors and subsequent law enforcement action.
low severity: Structured reporting that follows a chain of events (vulnerability added -> joint advisory -> tool seizure -> directive issued).
medium severity: Claims are heavily based on official-sounding references (CISA, DOJ, BOD) and attributed actions, requiring careful checking.
Human Indicators
The text relies heavily on citing specific organizational entities (CISA, DOJ, FBI, BOD), which suggests grounding in official reporting.
The structure flows logically from technical disclosure to geopolitical attribution and regulatory response.
U.S. CISA adds ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND flaws to its Known Exploited Vulnerabilities catalog | Huntaegis