Seven countries just warned that attackers are still hunting forgotten FTP, DNS and Struts servers — find yours this weekend

By George Bailey   Published: 10/09/26   6 min read

Somewhere on your network there is probably an FTP server nobody has logged into since 2016, or a DNS box that “just works,” or an old Java app still running Struts 2.3. On October 8, cyber agencies from seven countries put out a joint advisory saying that’s exactly what one long-running China-linked operation keeps finding and breaking into.

The bugs are old: 2014, 2015, 2016, 2021, 2023. CISA added five of them to its Known Exploited Vulnerabilities list the same day and gave federal agencies until Sunday, October 11, to deal with them. Everyone else gets the same advice with no deadline attached. Use the weekend anyway.

Nobody needed a zero-day. They needed the server you forgot you still had.

What happened

The FBI, CISA, NSA and partner agencies in the UK, Australia, Canada, Japan, New Zealand and Spain released advisory AA26-281A on October 8. It describes threat actors enabled by Integrity Technology Group, a China-based company the agencies say has links to the Chinese government. Their tradecraft overlaps with activity tracked publicly as Flax Typhoon, Ethereal Panda and Red Juliett.

Based on evidence from multiple FBI investigations, the advisory describes a mix of automated and hands-on work:

The advisory lists eight vulnerabilities the actors exploited successfully. CISA added the five not already in its catalog to KEV on October 8: ProFTPD mod_copy (CVE-2015-3306), ISC BIND TKEY (CVE-2015-5477), Apache Struts (CVE-2016-3081), ONLYOFFICE Docs (CVE-2021-3199) and Strapi (CVE-2023-22894). The other three are Bash “Shellshock” (CVE-2014-6278), Pulse Connect Secure (CVE-2019-11510) and GitLab (CVE-2021-22205).

The same day, the Justice Department and FBI announced the seizure of seven domains tied to the group’s scanning and spear-phishing tools.

Why it matters

This isn’t a story about one product. It’s about everything that fell off the patch list because it was old, quiet or owned by a team that no longer exists. The targets the agencies name include government, critical manufacturing, healthcare and IT, and also education, law enforcement and religious organizations. In other words: organizations that look a lot like most of our readers.

The mail theft is the part that hurts. Once these actors have a mailbox, or an app registration that can read mailboxes, a patch on the original server doesn’t get them out.

What to do first

Forward this

For whoever owns our servers and Microsoft 365: on October 8, agencies from seven countries warned that a China-linked group is breaking into organizations through old, forgotten servers (FTP, DNS, Struts, Strapi, ONLYOFFICE) and then stealing email. Can we confirm by Monday that we don’t have any of the listed versions exposed, and that nobody outside IT can read mailboxes through an app registration?

Details

Hunt / verify

Slack paste: AA26-281A (Oct 8, 7 countries): China-linked actors exploiting old servers (ProFTPD 1.3.5, BIND TKEY, Struts 2.3 S2-032, ONLYOFFICE 5.x, Strapi ≤4.5.5, plus Shellshock, Pulse, GitLab), Exchange password spraying, SoftEther VPN persistence, M365 mail theft. KEV due Sun Oct 11. Action: find and patch/retire exposed FTP/DNS/Struts, MFA on webmail, review mail-read app registrations, load the STIX IOCs.

Sources

George Bailey

George Bailey is the byline of the CyberExperts editorial desk, the team behind the CyberExperts Daily Brief. The desk covers vulnerabilities, breaches and security news from vendor advisories, CISA alerts and other primary sources, and links those sources in every story. Questions or corrections: [email protected].