AA26-281A: China-Linked Hackers Are Exploiting Flaws Up to 12 Years Old
On October 8, 2026, the Canadian Centre for Cyber Security and partner agencies in six other countries published joint advisory AA26-281A, warning that hackers linked to the Chinese government are stealing email, credentials and sensitive data from organizations worldwide. The striking detail is how they get in. The eight vulnerabilities the advisory lists as successfully exploited were all disclosed between 2014 and 2023, and every one has had a fix available for years.
For Canadian small businesses, that makes AA26-281A less a story about espionage and more a story about patching, exposed services and email logins. This post summarizes what the advisory says, with sources, and what to check this week.
What Is Joint Advisory AA26-281A?
AA26-281A is a joint cybersecurity advisory released on October 8, 2026 by the FBI, CISA and NSA with partners in the UK, Australia, Canada, Japan, New Zealand and Spain, including the Cyber Centre. According to the CISA advisory page, it covers threat actors enabled by Integrity Technology Group, a China-based company "with links to the Chinese government," and gives defenders detection and mitigation guidance.
The key facts, as stated in the advisory and CISA's announcement:
- Who is named: Integrity Technology Group (Integrity Tech), a for-profit company that the agencies say acquires or builds hacking tools, hosts infrastructure and compromises networks.
- Industry names: The actors use techniques consistent with activity publicly known as Flax Typhoon, Ethereal Panda and Red Juliett. The advisory cautions that private-sector tracking may not match the US government's one to one.
- Who was targeted: US government, critical manufacturing, healthcare and IT organizations, plus law enforcement, education and religious organizations, and organizations in Southeast Asia, Africa and North America.
- Where the evidence comes from: multiple FBI investigations related to Integrity Tech.
CISA's announcement of the advisory adds that, to keep long-term access, these actors target edge devices "that are not closely monitored by the targeted organization."
This is not the first Canadian warning about the company. In September 2024, the Communications Security Establishment joined a joint advisory on a router and IoT botnet stating that Integrity Technology Group controlled and managed a botnet active since 2021, made up of tens to hundreds of thousands of compromised devices such as small office routers, firewalls and network storage.
How Do the AA26-281A Hackers Get In?
Mostly through doors that should already be closed. The advisory describes automated scanning for weak spots, followed by hands-on work once a target looks vulnerable. It notes that the actors rely on open source scanning tools commonly found on GitHub, which "suggests the threat actors tend to look for more vulnerable targets."
The techniques most relevant to a small business:
- Scanning for exposed services: The actors focus on ports used for file transfer (FTP), remote administration (SSH), DNS, websites and proxies.
- Password spraying against email: A tool called EBurst tries passwords across many email accounts on Microsoft Exchange servers and in Microsoft's Office 365 cloud, through interfaces that include Outlook Web Access, Exchange Web Services and ActiveSync.
- Fake login prompts: Cross-site scripting (XSS) code, injected into vulnerable websites, displays username and password fields to harvest credentials.
- Hidden persistence: Once inside, the actors install SoftEther, a legitimate VPN program, often naming the installer conhost.exe or dllhost.exe so it looks like a normal Windows file. The advisory says endpoint detection software is less likely to flag it because it is legitimate software.
- Email theft: Scripts pull mailbox content, calendars and contacts through Exchange Web Services and upload them to attacker servers.
Which Vulnerabilities Does AA26-281A List?
Appendix B of the full advisory (PDF) lists eight vulnerabilities as successfully exploited. None of them is new:
- CVE-2014-6278: GNU Bash, the command shell on many Linux systems (one of the 2014 Shellshock flaws). Remote code execution.
- CVE-2015-3306: ProFTPD file transfer server. Unauthorized file read.
- CVE-2015-5477: ISC BIND DNS server. Denial of service.
- CVE-2016-3081: Apache Struts web framework. Remote code execution.
- CVE-2019-11510: Pulse Connect Secure VPN, now an Ivanti product. Unauthorized file read.
- CVE-2021-22205: GitLab code hosting. Remote code execution.
- CVE-2021-3199: ONLYOFFICE Document Server. Unauthorized file write.
- CVE-2023-22894: Strapi content management system. Information disclosure.
The same day, CISA added five of them (CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2021-3199 and CVE-2023-22894) to its Known Exploited Vulnerabilities catalog, the US government's list of flaws attackers are known to use. The Hacker News reported that US federal agencies were given until October 11, 2026 to patch them or stop using the affected software, and that the other three were already on the list.
Why do old flaws still work? Because they sit in software that is easy to forget: a file transfer server set up years ago, a self-hosted code repository, a document editor installed for one project, a VPN appliance nobody updated. Our patch management guide cites Verizon's 2026 Data Breach Investigations Report, which found the median time to fully patch a vulnerability rose to 43 days, and that companies fully patched only 26% of the vulnerabilities on CISA's catalog.
Should a Canadian Small Business Worry About a State-Sponsored Advisory?
Yes, but for practical reasons rather than geopolitical ones. The advisory's intended audience is government and critical infrastructure, yet its techniques are everyday ones: scanning the internet for anything unpatched and spraying passwords at email accounts. Automated scanning does not check the size of the company it finds. CISA also says the advisory is based on real-world investigations and activity observed in North America, Southeast Asia and Africa.
There is a supply chain angle too. A small firm that serves government, healthcare, manufacturing or technology customers holds email threads and credentials that can be useful to someone targeting those customers.
What Should You Do After AA26-281A?
Start with the advisory's own priorities, then map them to the Cyber Centre's Baseline Controls. The agencies' key actions are to disable unused services and ports, sanitize input in web applications, and require multi-factor authentication (MFA) for services "to the extent possible." The full mitigation list adds applying patches, replacing end-of-life products and monitoring for unusual logins and outbound traffic.
A checklist for owners and managers:
- List everything you expose to the internet. Websites, VPNs, remote access portals, file transfer servers and email. The advisory suggests attack surface management services or internet search platforms to find exposed services and ports.
- Check for the eight listed products. Ask whether you, or any provider, run ProFTPD, BIND, Apache Struts, Pulse Connect Secure, GitLab, ONLYOFFICE, Strapi or an outdated Bash on an internet-facing Linux system, and whether each is on a fixed, supported version.
- Turn off what you do not use. Secure configuration is Baseline Control BC.4, and our hardening checklist recommends disabling remote management interfaces, file sharing protocols and legacy protocols that are not in active use.
- Require MFA on email and remote access. Password spraying is far less effective against accounts that need a second factor. Our MFA guide notes Microsoft research finding that MFA blocks more than 99.2% of automated account compromise attacks.
- Replace end-of-life software. A product that no longer receives fixes will stay vulnerable. The Cyber Centre recommends identifying and replacing end-of-life software as a priority, as our patch management control page explains.
- Look for the persistence signs. Ask your IT provider to check for unexpected VPN software such as SoftEther, and for files named conhost.exe or dllhost.exe in unusual locations. The advisory publishes its indicators of compromise in STIX format, which many security tools can import.
Where Do You Report Suspicious Activity in Canada?
The advisory directs Canadian organizations to report incidents to the Cyber Centre at contact@cyber.gc.ca, (613) 949-7048 or 1-833-CYBER-88. If you suspect a crime such as data theft or extortion, our guide on how to report a cyber attack in Canada explains when to also use the RCMP's National Cybercrime and Fraud Reporting System and your local police.
One Question for Your IT Provider
Ask this: "Do we run any of the eight products in AA26-281A, and can you show me the version and last patch date of every system we expose to the internet?" If that answer takes more than a day to produce, the inventory itself is the first gap to close.
To see how your business measures up on patching, secure configuration, authentication and the other Baseline Controls, take our free cybersecurity assessment. It takes under 30 minutes and shows where to start.
How prepared is your business?
Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.
Check Your ScoreFrequently Asked Questions
What is joint advisory AA26-281A?
AA26-281A is a joint cybersecurity advisory published on October 8, 2026 by the FBI, CISA, NSA and agencies from the UK, Australia, Canada, Japan, New Zealand and Spain, including the Canadian Centre for Cyber Security. It describes hackers enabled by Integrity Technology Group, a China-based company the agencies say has links to the Chinese government, and lists their techniques, indicators of compromise and recommended mitigations.
Which vulnerabilities are listed in AA26-281A?
The advisory lists eight vulnerabilities as successfully exploited: CVE-2014-6278 (GNU Bash), CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2019-11510 (Pulse Connect Secure), CVE-2021-22205 (GitLab), CVE-2021-3199 (ONLYOFFICE Document Server) and CVE-2023-22894 (Strapi). All were disclosed between 2014 and 2023, and fixes have been available for years.
Does AA26-281A matter to Canadian small businesses?
Yes, for practical reasons. The advisory is written for government and critical infrastructure, but the techniques it describes are common ones: automated scanning for unpatched internet-facing systems and password spraying against email accounts. Patching, turning off unused services and requiring multi-factor authentication on email and remote access address most of what it describes.
Where should a Canadian organization report activity related to AA26-281A?
The advisory directs Canadian organizations to report incidents to the Canadian Centre for Cyber Security at contact@cyber.gc.ca, (613) 949-7048 or 1-833-CYBER-88. Suspected crimes such as data theft or extortion should also be reported through the RCMP's National Cybercrime and Fraud Reporting System and to local police.
Cite This Page
Suggested citation:
Cybersecurity Canada (2026). AA26-281A: China-Linked Hackers Are Exploiting Flaws Up to 12 Years Old. Retrieved from https://cybersecuritycanada.ca/news/posts/aa26-281a-china-linked-hackers-exploit-old-unpatched-flaws/
Permanent URL: https://cybersecuritycanada.ca/news/posts/aa26-281a-china-linked-hackers-exploit-old-unpatched-flaws/ · Published October 11, 2026
Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.
Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.
How does your organization measure up?
Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.
Take the Free Assessment