CISA Adds Five Flaws to KEV Catalog After Flax Typhoon Attacks
CISA added five security flaws to its Known Exploited Vulnerabilities catalog after they were abused by the China-linked group Flax Typhoon. Federal agencies have until October 11 to patch, including CVE-2015-3306 in ProFTPD with a CVSS score of 10.0.
- CISA added five flaws to its KEV catalog on Thursday
- Attacks are attributed to China-linked group Flax Typhoon
- CVE-2015-3306 in ProFTPD carries a CVSS score of 10.0
- Federal agencies must remediate by October 11
Read next
Security