What happened
Chinese threat actors, operating through the Integrity Technology Group, are using automated scanners and botnets to locate vulnerable Microsoft Exchange servers and VPN endpoints. They exploit a series of disclosed CVEs, conduct credential‑spraying and XSS attacks, establish persistence via VPN software, and exfiltrate emails and credentials with custom scripts.
Why it matters for trust and compliance
- The advisory highlights the control objective of timely vulnerability remediation and strong identity‑access safeguards, both of which provide defensible evidence for audit and regulatory readiness.
- Demonstrates the need for continuous patch‑management evidence to satisfy vulnerability‑remediation controls across frameworks.
- Shows that MFA enforcement and disabling unused services generate auditable proof of robust access‑control posture.
Who is affected
ENERGY_UTIL TELCO MANUF_IND
Recommended actions
- Create an inventory of all Exchange and VPN assets and verify they run supported, patched versions.
- Apply the latest patches for each listed CVE and enable automated patching where feasible.
- Enforce multifactor authentication for all remote and privileged accounts.
- Disable any unused services, ports, or legacy protocols.
- Implement web‑application firewalls and input‑sanitization to block XSS and injection attacks.
- Enable comprehensive logging and integrate alerts into a SIEM for rapid detection of scanning or credential‑spraying activity.
Details
- CVEs
- CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894