BREACH WATCH BRIEF High 🏛️ Advisory

Chinese State‑Linked Actors Use Automated Scanning and Exploits (incl. Exchange CVEs) to Harvest Sensitive Data Across Global Critical Infrastructure

CISA’s latest advisory details a campaign by Chinese government‑linked groups that combine large‑scale scanning, botnets, and manual exploitation of known Microsoft Exchange and VPN vulnerabilities to steal data. The threat underscores the need for rigorous patch management, MFA, and continuous monitoring to meet audit‑ready control objectives.

SeverityHigh
Type🏛️ Advisory
ConfidenceHigh
ReportedOct 8, 2026
Other / Unknown ENERGY_UTIL TELCO MANUF_IND Vulnerability Exploit Data Exfiltration

What happened

Chinese threat actors, operating through the Integrity Technology Group, are using automated scanners and botnets to locate vulnerable Microsoft Exchange servers and VPN endpoints. They exploit a series of disclosed CVEs, conduct credential‑spraying and XSS attacks, establish persistence via VPN software, and exfiltrate emails and credentials with custom scripts.

Why it matters for trust and compliance

  • The advisory highlights the control objective of timely vulnerability remediation and strong identity‑access safeguards, both of which provide defensible evidence for audit and regulatory readiness.
  • Demonstrates the need for continuous patch‑management evidence to satisfy vulnerability‑remediation controls across frameworks.
  • Shows that MFA enforcement and disabling unused services generate auditable proof of robust access‑control posture.

Who is affected

ENERGY_UTIL TELCO MANUF_IND

Recommended actions

  1. Create an inventory of all Exchange and VPN assets and verify they run supported, patched versions.
  2. Apply the latest patches for each listed CVE and enable automated patching where feasible.
  3. Enforce multifactor authentication for all remote and privileged accounts.
  4. Disable any unused services, ports, or legacy protocols.
  5. Implement web‑application firewalls and input‑sanitization to block XSS and injection attacks.
  6. Enable comprehensive logging and integrate alerts into a SIEM for rapid detection of scanning or credential‑spraying activity.

Details

CVEs
CVE-2014-6278, CVE-2015-3306, CVE-2015-5477, CVE-2016-3081, CVE-2019-11510, CVE-2021-22205, CVE-2021-3199, CVE-2023-22894

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.