Operation MicroScan & FishHub: FBI Takedown of Integrity Tech Infrastructure and Emergency CISA KEV Order

Operation MicroScan and FishHub Global Takedown
📌
Security Roundup Series: Week of October 9, 2026 • 4 min read deep dive
🏛️
OPERATION MICROSCAN & FISHHUB: INFRASTRUCTURE TAKEDOWN Multinational law enforcement action led by FBI, DOJ, CISA, NSA, and Five Eyes + Spain + Japan targeting Beijing-based Integrity Technology Group. 7 core command and operational domains seized under federal court warrants on October 8, 2026 Disrupted "MicroScan" (reconnaissance framework with 1,300+ exploits) and "FishHub" (phishing & exfiltration system) Infrastructure operated on behalf of state-sponsored threat groups Flax Typhoon, RedJuliett, and Ethereal Panda CISA adds 5 weaponized vulnerabilities to KEV with emergency October 11, 2026 compliance deadline under BOD 26-04

On October 8, 2026, the United States Department of Justice and the Federal Bureau of Investigation, in coordination with international cybersecurity agencies from the United Kingdom, Australia, Canada, New Zealand, Japan, and Spain, announced the court-authorized seizure of seven internet domains used to host and control MicroScan and FishHub. The two weaponized platforms were developed and managed by Beijing-based government contractor Integrity Technology Group to support state-backed cyber espionage campaigns conducted by threat actors known as Flax Typhoon.

Disrupted Infrastructure: MicroScan & FishHub

The joint advisory published by CISA, FBI, and international partners reveals the operational architecture deployed by Integrity Technology Group to support Chinese military and intelligence reconnaissance:

  • MicroScan: A distributed vulnerability scanning and automated exploitation platform containing over 1,300 pre-packaged penetration testing scripts. The platform was used to mass-scan government agencies, telecommunications providers, universities, and defense contractors across North America, Europe, and the Indo-Pacific, automatically probing perimeters for known unpatched flaws.
  • FishHub: A credential harvesting and spear-phishing management framework that automated target enumeration, email lure delivery, two-factor authentication proxying, and automated exfiltration of sensitive victim documents.

Emergency CISA KEV Catalog Additions (BOD 26-04)

Following the takedown, CISA issued an urgent update to its Known Exploited Vulnerabilities (KEV) catalog on October 8–9, ordering Federal Civilian Executive Branch (FCEB) agencies to remediate five specific legacy flaws weaponized by Flax Typhoon within 72 hours (by October 11, 2026):

🚨
Mandatory CISA KEV Additions — Remediation Deadline: October 11, 2026: CVE-2015-3306: ProFTPD mod_copy improper access control allowing arbitrary file upload and remote code execution. CVE-2021-3199: ONLYOFFICE Docs path traversal in JWT handling leading to remote code execution. CVE-2023-22894: Strapi CMS cleartext storage of sensitive information exposing administrative credentials. CVE-2016-3081: Apache Struts command injection via Dynamic Method Invocation (DMI). CVE-2015-5477: ISC BIND reachable assertion denial-of-service triggered by malformed TKEY queries.

Operational Impact & Strategic Analysis

This action follows the September 2024 disruption of the "Raptor Train" botnet, which compromised over 200,000 SOHO routers and IoT devices under Integrity Tech's control. By seizing the command domains for MicroScan and FishHub, law enforcement has severed the command pipeline used by Flax Typhoon to orchestrate zero-day discovery and high-velocity exfiltration against Western critical infrastructure.

Actionable Enterprise Defensive Guidance

  1. Audit for KEV Flaws: Immediately scan all internet-facing systems for the five KEV vulnerabilities listed above. Legacy instances of ProFTPD, old Strapi backends, or unpatched ONLYOFFICE document servers must be isolated or decommissioned immediately.
  2. Block Seized Command Domains: Ingest the indicators of compromise published in the FBI/CISA joint advisory and ensure DNS sinkholing is configured for all domain names associated with the MicroScan and FishHub command infrastructure.
  3. Monitor for SOHO Proxy Botnets: Flax Typhoon frequently routes administrative access through consumer routers. Enforce behavioral geofencing and inspect inbound administrative traffic originating from residential ISP ranges.

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther