Integrity Tech seizure: of at least eight scanned targets, the affidavit alleges breaches at two universities
The FBI affidavit behind the seizure of seven Integrity Technology Group domains describes breaches at two Taiwanese universities among at least eight scanned targets. The 58-page joint advisory, co-sealed by the NCSC, lists only one of the seven seized domains.
By Parminder Kumar Sharma · · 20 min read

Two breaches are described; at least six other scan targets are not said to have been breached
The sworn affidavit behind the seizure of seven Integrity Technology Group domains describes two intrusions that followed MicroScan scans. Both victims were universities in Taiwan, scanned on or about 7 August 2022 and 21 March 2023 and, the FBI special agent swears, compromised soon after. The Justice Department release lists at least eight MicroScan scan targets (our count: a power company in South Carolina, a multi-national NGO, two airports, two Taiwanese gas and power companies, and those two universities). For the rest, at least six, the affidavit says one thing: they were scanned, between 26 April and 29 December 2022. That window is 247 days (derived), and it closed 1,379 days, about three years and nine months (derived), before the announcement on 8 October 2026.
That does not show the six were safe. The documents are silent on whether the power company, the airports, the NGO or the gas and power companies were breached, and BleepingComputer reports that the FBI did not disclose it. It does not show that any UK organisation was scanned or breached: none is mentioned in the affidavit, the release, the advisory or the NCSC's own news item. And it dates almost nothing to the present. The latest dated intrusion evidence in the affidavit is 19 August 2024, 780 days (derived) before the announcement. What is recent is the tooling: FishHub was on a server as of March 2026, and a MicroScan login page was still reachable on about 9 September 2026.
Everything here is an allegation. The affidavit was sworn on 6 October 2026 before a magistrate judge, at the probable-cause standard, to justify seizing domain names under computer-intrusion, conspiracy and money-laundering statutes. It is not a judgement. The release describes the seizures, names no defendant and announces no charge or arrest. Flax Typhoon is Microsoft's name for a China-based activity cluster; the affidavit uses it for the actors it describes and says private security firms apply it to Integrity Tech's tools and activity.
FishHub: the release says about 20 universities, the affidavit says six
The release says confirmed victims of FishHub activity "included approximately 20 Taiwanese universities". The Record repeats about 20. The affidavit, sworn two days earlier, says something narrower: the server that hosted FishHub held data and files from more than 20 different entities, and commands from that server showed that six of them were universities in Taiwan. The agent infers, from training and experience, that the actors stole the files with FishHub. BleepingComputer followed the affidavit (more than 20 organisations, six of them Taiwanese universities).
The two counts may not conflict. "More than 20 entities" could be six universities plus others, and the release may rely on material that is not in the affidavit. But neither document reconciles them, so a reader cannot tell whether the victim list is about 20 universities or six universities and a larger group that is not described. Coverage that says "about 20 universities" is relying on the release alone.
As the affidavit describes it, FishHub worked through spear phishing: it delivered a file to victims, and that file used five of the seven seized domains to fetch further programs, which listed files, searched for specific ones, compressed documents and sent the selection to the server. The seventh domain, the one the release does not name, is tied in the affidavit to SoftEther, a legitimate VPN program, installed on servers at the two universities in August 2024.
The advisory is a different document from the affidavit
The joint advisory, AA26-281A, was published on 8 October 2026 and runs to 58 pages. By the page numbers in its own contents list, 39 pages (19 to 57) are indicator tables, 18 are narrative, technique tables, response, mitigations and contacts, and 1 (page 58) is the table of CVEs (all derived). Indicators are 67 per cent of the document (39 divided by 58, derived).
It was authored by ten organisations from seven countries, counted from its cover: the FBI, CISA and NSA for the United States; the NCSC for the United Kingdom; the Australian Signals Directorate's cyber centre; the Canadian Centre for Cyber Security; two Japanese bodies, the National Police Agency and the National Cybersecurity Office; the New Zealand NCSC; and Spain's Centro Nacional de Inteligencia. The UK is one of them: the NCSC's own news item says it co-sealed the advisory.
What the 58 pages leave out matters as much as what they hold. FishHub is mentioned zero times, Mirai zero times and Taiwan zero times. MicroScan gets one paragraph and one screenshot. No victim is counted: victims are described by sector (in the US, government services and facilities, critical manufacturing, healthcare and public health, and information technology, plus law enforcement, education and religious organisations) and by region (Southeast Asia, Africa and North America). Of the seven seized domains, one appears in the advisory, as a host for the VPN software, in the body text and in the tables. The other six appear nowhere in it. The machine-readable STIX file linked from the advisory page, which we read in a browser tab and did not save, holds 773 indicator objects and shows the same one of seven (derived, by string search).
The advisory's time spans are looser than the headlines. It says MicroScan has been used "as early as 2017", about nine years before publication (derived), and that initial access has come through exploit utilities "since at least mid-January 2021", about 5.7 years (derived). Setting aside the entries the advisory marks with an asterisk as registration expiry dates, its indicator tables end on 9 November 2025, 333 days before publication (derived). The advisory warns that several indicators go back to 2016 and should be vetted before blocking.
Read beside the affidavit, that leaves a gap. FishHub was on a server in March 2026 and the MicroScan login page was up in September 2026, while the advisory's newest observation date is eleven months earlier and six of the seven seized domains are not on its list. A blocklist built from the advisory alone would have covered one of the seven seized domains.
Stated and not stated
The coverage, the release, the affidavit and the advisory are four documents with four jobs. The table sets what each says beside what none of them says. All were read between 09:05 and about 09:33 BST on 9 October 2026.
Where the coverage or the release goes beyond the documents, and what the documents do not state. Sources: the Justice Department release, the affidavit, the warrant, the advisory, the CISA release and the NCSC item, 6 to 8 October 2026.
| In the coverage or the release | What the documents say | Not stated |
|---|---|---|
| Seven domains seized, two tools disrupted | The warrant directs the registry to redirect seven domain names to FBI name servers. The release names six of the seven. | Whether the servers behind the names, or the tools' code, were taken. Whether the actors have moved. |
| The tools breached critical infrastructure | Scans of a power company, airports, an NGO and gas and power firms in 2022. Breaches described: two universities. The release says the tools were used to "scan and, in some cases, hack". | Whether any scanned infrastructure target was breached. |
| About 20 universities | Release: approximately 20 Taiwanese universities were confirmed FishHub victims. Affidavit: files from more than 20 entities, six of them universities. | How the counts reconcile. Which entities. When. |
| A Mirai botnet behind the scans | Affidavit: in use from at least 23 July 2021 to about 13 September 2024; about 5 June 2024, over 1.2 million records and over 260,000 actively infected. Release: the 2024 botnet had "more than 200,000" devices. | Any botnet size in 2026. Whether MicroScan still uses one. |
| Flax Typhoon is Integrity Tech | Advisory: methods "consistent with" Flax Typhoon and two other names; the actors "may also perform activity not associated with Integrity Tech". One label, "the threat actors", covers the company and those it enables. | Which intrusions were staff and which were customers. |
| Hired by the Ministry of State Security (The Record) | Release and affidavit: Integrity Tech "has contracts with the PRC government". Advisory: "links to the Chinese government". | Any ministry, contract or tasking. No primary read names one. |
| AI-enabled hacking | NCSC item: actors "uniquely using AI tools, such as automated scanning". The advisory says "automated scanning tools" and never uses the word AI. | Any AI component, model or vendor. |
| Edge devices that are not closely monitored | CISA release: actors are "targeting edge devices that are not closely monitored". The advisory mentions edge devices once, as a place to segment internally. | How many intrusions began at an edge device. |
Three of those rows are labels doing work the evidence does not. "Critical infrastructure" is, for the named targets, scanned and not shown breached. "AI" is automated scanning. "Edge devices" is one line of advice in the advisory and a sentence in a press release. None of the three is absurd as a statement of concern. In each case the label is wider than the evidence the advisory or the affidavit gives. A seizure notice is a label too: it says the names now point at the FBI, not that the tools are gone.
The eight CVEs are 3 to 12 years old
Appendix B of the advisory lists eight CVEs it calls successfully exploited, and the MicroScan paragraph says they were recovered from the tool's penetration-testing scripts. Counted from CVE.org publication dates to 8 October 2026, they are between 3.5 and 12.0 years old, with a median of 8.9 years (all derived). Seven of the eight were published before 2022.
The advisory's eight CVEs, with products as the advisory names them. Published dates from CVE.org records; catalogue status from CISA's Known Exploited Vulnerabilities JSON, version 2026.10.08.
| CVE | Product | Published | On KEV before 8 Oct |
|---|---|---|---|
| CVE-2014-6278 | GNU Bash | 30 Sep 2014 | Yes, since 2 Oct 2025 |
| CVE-2015-3306 | ProFTPD | 18 May 2015 | No, added 8 Oct 2026 |
| CVE-2015-5477 | ISC BIND | 29 Jul 2015 | No, added 8 Oct 2026 |
| CVE-2016-3081 | Apache Struts | 26 Apr 2016 | No, added 8 Oct 2026 |
| CVE-2019-11510 | Pulse Secure Pulse Connect Secure | 8 May 2019 | Yes, since 3 Nov 2021 |
| CVE-2021-22205 | GitLab | 23 Apr 2021 | Yes, since 3 Nov 2021 |
| CVE-2021-3199 | ONLYOFFICE DocumentServer | 22 Jan 2021 | No, added 8 Oct 2026 |
| CVE-2023-22894 | Strapi | 19 Apr 2023 | No, added 8 Oct 2026 |
Five of the eight were added to CISA's Known Exploited Vulnerabilities catalogue on 8 October 2026, and the catalogue version of that date shows a due date of 11 October for each, three days later (derived). The other three were already listed.
The table is thinner than the text around it. The MicroScan paragraph names seven service families: OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins and Apache Struts. Only one of them, Struts, has a CVE in Appendix B, and seven of the eight Appendix B products are not named in the paragraph (both derived). The advisory gives no date, victim or count for any CVE.
Inference, not stated by the advisory: a flaw that is 12 years old is not a patch-speed problem. It is an inventory problem, a system that is unsupported, forgotten or missing from the register.
How the advisory says the actors get in, stay in and take mail
The advisory's technical content is about eight pages. At the level a defender needs, and without the names of files or tools beyond what a hunt requires:
Stages as the advisory describes them, with its own mitigation advice beside each. Advisory AA26-281A, pages 5 to 16.
| Stage | What the advisory says | What it asks of you |
|---|---|---|
| Find targets | Open-source scanners plus MicroScan, over 1,300 scripts, used since as early as 2017. Scans focus on ports 21, 22, 53, 80, 443 and 1080. | Attack-surface management. Disable unused services and ports. Reveal as little as possible on login pages and banners. |
| Get in | Command-line utilities built on exploit code. A script that turns a vulnerable third-party web page into a fake login and offers a download. Password spraying and guessing against ten Exchange and Microsoft 365 interfaces. | Patch the eight CVEs. Sanitise web input against cross-site scripting. MFA on webmail, VPNs and accounts that reach critical systems. Review web logs for traversal and command-injection attempts. |
| Stay in | A legitimate VPN client, SoftEther, set to reconnect at start-up, with installers renamed to look like Windows components. Endpoint detection is less likely to flag it. | Hunt for unexpected VPN clients and system-looking names. Protective DNS. Segment so one device reaches nothing sensitive. |
| Take credentials and mail | Directory replication to copy credentials, groups and trusts. A mail-collection script using Exchange Web Services. A Linux utility that reads Microsoft 365 mailboxes with a client ID, tenant ID and secret. A web application giving third parties access to stolen mail. | Watch for unexpected Active Directory replication. Review cloud-connected applications that can read mail. Watch for large outbound uploads. |
The ten interfaces the advisory tells defenders to cover against password spraying are Exchange Control Panel, Exchange Web Services, Offline Address Book, Outlook Web Access, Remote Procedure Call, the API, MAPI, PowerShell, Autodiscover and ActiveSync. If an interface is not needed, it should not answer the internet.
On edge devices, the CISA release says the actors target devices "not closely monitored". The advisory's own advice is narrower: segment edge devices internally as a lower-effort option, replace end-of-life products, and review perimeter firewall configurations for unauthorised changes. Microsoft's 2023 description of Flax Typhoon, where the name comes from, is plainer still: initial access by "exploiting known vulnerabilities in public-facing servers", including VPN, web, Java and SQL applications, and defence that "begins with vulnerability and patch management" on internet-facing systems. Whatever faces the internet is the front door. Brief 217 shows the other failure on mail appliances: implants found, entry route unstated.
The contractor point, as the documents state it
The advisory calls Integrity Tech "a China-based for-profit company with links to the Chinese government" whose employees support malicious cyber activity by acquiring or building tools "for use and sale", acquiring and hosting infrastructure, and compromising networks. The release says the company "has contracts with the PRC government". The FBI's Cyber Division, through its assistant director, says the PRC "relies on contractor and enabling companies" to expand its reach. The UK sanctioned the company on 9 December 2025, for controlling and managing a covert cyber network and giving technical help to others carrying out attacks, adding that targets "have included UK public sector IT systems". The US sanction of January 2025 is reported elsewhere; we did not read the Treasury notice.
Three limits apply. First, the advisory does not separate what company staff did from what customers did: it uses one label, "the threat actors", for the company and the actors it enables. Second, it names no individual and no ministry. The Record's statement that the company was hired by the Ministry of State Security is not in the release, the affidavit, the advisory, the CISA release or the NCSC item; an earlier US government statement may carry it, and we did not read one. Third, the affidavit's route from botnet to company runs through a name: the botnet's management application had a user guide whose first line mentions a team called KRlab, and the affidavit says the company's own website carries a public page for that team as a subdivision. That is a probable-cause chain, not a trial finding.
Integrity Tech's response: we found no statement from the company or the Chinese embassy on the 8 October action by about 09:33 BST on 9 October 2026. In January 2025, after the US sanctions, the company said in a public notice, as reported by the Global Times, that the designation lacked a factual basis and that it had no US subsidiaries, business or assets. That is the company's position on a different action.
For a UK buyer, the usable reading is narrower than the geopolitics. A supplier with state contracts that also builds tools for state actors does not show up in a procurement file. A sanctions listing and a supplier's own subcontractor list do. Ask for both.
What it means in the UK
The NCSC is one of the ten authors and published its own news item on 8 October, typed as an alert. Neither document names a UK victim, and neither says whether a UK organisation was scanned. The NCSC item says it acted with "eight international partners from six countries"; the advisory's cover lists nine other agencies in six other countries (derived), a difference of counting we note and do not explain. The broader UK statement is the December 2025 sanction notice, which says Integrity Tech targets have included UK public sector IT systems. That is about the company over time, not about this advisory.
UK guidance already covers the exposure the advisory points to. The table sets each source beside what it leaves unsaid for this case.
UK sources read for this brief, in the part cited. NCSC and Crown copyright pages read on 9 October 2026.
| Source | What it says | What it does not do here |
|---|---|---|
| NCSC alert, 27 August 2026 | For organisations outside OT: keep an accurate inventory of internet-facing systems, understand edge device functions and data flows, apply vendor updates promptly, retire end-of-life equipment, disable SNMP v1, v2 and Telnet, monitor configuration changes and outbound connections, and register for Early Warning. | Written about OT targeting by a range of actors, not about this advisory. |
| NCSC executive summary, 23 April 2026 | Map and baseline edge device traffic, especially VPN and remote access. Covert networks of compromised devices make static block lists age fast. | About the infrastructure actors hide behind, not these CVEs. Only the summary page was read. |
| NCSC vulnerability management guidance | Best-practice clocks: 5 days for internet-facing services and software, 7 days for operating systems and applications, 14 days for internal and air-gapped. If an internet-facing flaw is being exploited, check for compromise before you update. | The clocks start at a fix's release. A 2015 fix is long past any clock. |
| Cyber Essentials v3.3, April 2026, Security Update Management | Covers servers, firewalls and routers among others. Software must be licensed and supported, and removed when unsupported unless cut off from the internet. Critical or high updates within 14 days of release. | Says what to do with unsupported software. Does not find it for you. |
| Cyber Assessment Framework, A3.a, B4.d, C2.a | A3.a: inventories kept up to date. B4.d is not achieved if externally exposed vulnerabilities are not mitigated promptly, or unsupported software is not suitably mitigated. C2.a: hunting only on a tip off from a reputable source is partially achieved. | A framework for regulated essential functions. This advisory is the tip off C2.a describes. |
| NCSC Early Warning | Free for any UK organisation. Sign up with public IP addresses and domain names. Alerts on malware and vulnerabilities seen by NCSC's feed suppliers. | Not a substitute for your own controls; the page says so. |
The clocks matter for new fixes, and brief 241 compares the NCSC and Cyber Essentials clocks in more detail. These eight CVEs make a different point. The test is not how fast you patch; it is whether you know the system exists. The CAF says so in regulatory language: a neglected, out-of-date inventory fails A3.a, and so does not mitigating unsupported software under B4.d.
For an operator of critical national infrastructure, note that the advisory's sector list is US critical infrastructure sectors and names no UK sector. For a supplier to such an operator, the question your customer is most likely to ask is the first one in the list below.
What to do, in order
Take this with you
What a UK operator, or a supplier to one, can check, in the order worth doing it
- Today: sign up to the NCSC Early Warning service with every public IP range and domain you own, and ask your hosting and managed-service suppliers whether they have done the same.
- Today: read the advisory's CVE table against your external attack surface by product and version, including test, development and supplier-hosted systems: GNU Bash, ProFTPD, ISC BIND, Apache Struts, Pulse Connect Secure, GitLab, ONLYOFFICE DocumentServer and Strapi.
- Today: if anything matches and faces the internet, check for signs of compromise before you update, as the NCSC guidance says, then update, replace or remove it.
- This week: list every internet-facing system you cannot name an owner for. An unknown is the finding. Retire or cut off anything the vendor no longer supports.
- This week: hunt for the behaviours, not only the indicators: unexpected VPN clients, system-looking names on servers, directory replication from machines that are not domain controllers, and large uploads from servers. The advisory says its older indicators need vetting before blocking.
- This week: for Exchange and Microsoft 365, list which of the ten interfaces the advisory names are reachable from the internet, switch off those you do not use, and require MFA on webmail and VPNs.
- This week: list the cloud applications and service credentials that can read mailboxes, and remove any without an owner and a reason.
- This month: for edge devices, baseline their normal traffic (the NCSC April advice), segment them so one compromised device reaches nothing sensitive (the advisory's lighter option), and log configuration changes.
- This month: check supplier and procurement records against the UK government sanctions listing for Integrity Technology Group, and ask suppliers who they subcontract tooling and hosting to.
- If you find something: report a significant incident through the NCSC incident reporting service, as the advisory directs UK organisations.
What is not established, and what we could not read
Not established by anything we read: a victim list; any UK victim; how many devices any botnet holds today; whether the seizure removed the capability (the warrant covers domain names, not the servers behind them or the tools' code); whether the actors have moved infrastructure; when any of the 20 or more FishHub entities were breached; and whether the two described breaches are all of them, since the affidavit says "multiple victim entities" and describes two.
What we could not read: the 2024 Justice Department botnet release (a bot-verification page answered, which we did not attempt to pass), the US Treasury designation notice, Integrity Tech's own January 2025 notice (we read the Global Times account of it), and the Associated Press and Reuters reports. We read the affidavit, the warrant and the Justice Department release in full, the advisory in full (PDF and CISA web page, which match), the CISA release, the NCSC items, the UK sanction notice, Microsoft's 2023 post, and the press pieces cited. This account can be overtaken within hours: a company statement, a UK victim notice or a new indicator release would change it.
The question that exposes the gap
The scans of a power company and two airports ended on 29 December 2022, and the documents do not say whether anything came of them. Nobody outside those organisations can say. The question for your own estate is the one the documents cannot answer for you.
If a scanner found a flaw published in 2015 on one of your internet-facing systems tonight, which register would tell you that the system exists, who owns it, and whether anything has used it since?
Key facts
Sources
- PrimaryPress release 26-1155, 8 October 2026, "Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers". Read in full: the seizure, the scan target list, the approximately 20 Taiwanese universities, the 2024 botnet figure and the absence of any defendant or charge. No domain name, address or person is reproduced in the articleUS Department of Justiceaccessed 2026-10-09
- PrimaryThe FBI seizure affidavit, 21 pages, sworn 6 October 2026, posted by the Justice Department. Read in full: probable-cause standard, scan window, the two university intrusions, more than 20 entities and six universities on the FishHub server, botnet figures for June 2024, the KRlab link. It is an allegation, not a judgementUS Department of Justice, Western District of Pennsylvaniaaccessed 2026-10-09
- PrimaryThe seizure warrant and Attachment A, 5 pages, issued 6 October 2026: seven domain names, redirect by the registry to FBI name servers, execution by 20 October. Used to show the warrant covers domain names, not servers or codeUS Department of Justice, Western District of Pennsylvaniaaccessed 2026-10-09
- PrimaryJoint advisory AA26-281A, "Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data", 8 October 2026, 58 pages. Read in full: ten authoring organisations, page split of 18, 39 and 1, the MicroScan paragraph, initial access, persistence, collection, mitigations, the eight CVEs and the indicator tables. No indicator is reproduced in the articleFBI Internet Crime Complaint Center (joint advisory)accessed 2026-10-09
- PrimaryCISA's web copy of AA26-281A, which matches the PDF text. Its linked machine-readable STIX JSON file (773 indicator objects) was read in a browser tab and not saved, to check which seized domains it listsCISAaccessed 2026-10-09
- PrimaryCISA press release, 8 October 2026. The source of the statement that the actors target edge devices that are not closely monitored, which the advisory body does not makeCISAaccessed 2026-10-09
- PrimaryNCSC news item of 8 October 2026 (type: alert). Read in full: the NCSC co-sealed the advisory, the wording on AI tools and automated scanning, the count of partners, the reference to the 2025 UK sanction. No UK victim is namedUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryNCSC alert of 27 August 2026 on internet-exposed systems and edge devices. Read in full. Used for the actions for organisations outside OT, Early Warning, the CAF and Cyber Essentials referencesUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryExecutive summary of the 23 April 2026 covert networks advisory. Only the summary page was read, not the full advisory. Used for the advice to map and baseline edge device trafficUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryVulnerability management guidance, update by default. Read for the best-practice timescales of 5, 7 and 14 days and the instruction to check for compromise before updating an exploited internet-facing serviceUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryCyber Essentials Requirements for IT Infrastructure v3.3, April 2026, section 3 Security Update Management, pages 17 and 18: scope, supported software, removal, and the 14-day rule for critical or high updatesUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryCyber Assessment Framework principle B4, indicator B4.d Vulnerability Management, read for the not achieved statements on exposed vulnerabilities and unsupported softwareUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryCyber Assessment Framework principle A3, indicator A3.a Asset Management, read for the inventory statementsUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryCyber Assessment Framework principle C2, indicator C2.a Threat Hunting, read for the partially achieved example of hunting on a tip offUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryNCSC Early Warning service page: free, any UK organisation, registration by public IP addresses and domain names, and the statement that it should not be the only layer of defenceUK National Cyber Security Centreaccessed 2026-10-09
- PrimaryNotice of 9 December 2025 announcing UK sanctions on Integrity Technology Group and another China-based company. Read in full; the statement that targets have included UK public sector IT systemsUK Foreign, Commonwealth and Development Officeaccessed 2026-10-09
- PrimaryMicrosoft's 24 August 2023 description of Flax Typhoon, the origin of the name: targets in Taiwan, initial access through known vulnerabilities in public-facing servers, VPN software for persistence. Does not mention Integrity Tech or MicroScanMicrosoft Security Blogaccessed 2026-10-09
- PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.10.08 (released 8 October 2026, 20:09 UTC, 1,739 entries). Read for the date added and due date of each of the eight CVEsCISAaccessed 2026-10-09
- PrimaryCVE.org record for CVE-2014-6278, published 30 September 2014. The other seven CVEs in the advisory's table were read the same way for their publication dates, from which the ages are computedCVE Program (CVE.org)accessed 2026-10-09
- Reported byCoverage of 8 October 2026. A pointer to the primaries; the source of the statement that the FBI did not disclose whether the named power companies, airports and energy providers were breachedBleepingComputeraccessed 2026-10-09
- Reported byCoverage of 8 October 2026. A pointer to the primaries; the source of the about 20 universities figure as repeated from the release and of the Ministry of State Security statement that no primary read supportsThe Record from Recorded Future Newsaccessed 2026-10-09
- Reported byCoverage of 8 October 2026, read for how it describes the advisory and the Mirai-variant botnetCyberScoopaccessed 2026-10-09
- Reported byCoverage of 8 October 2026, published 22:59 UTC. Read for the seven-government framing and the five CVEs added to the KEV catalogueThe Registeraccessed 2026-10-09
- Reported byCoverage of 8 October 2026, read in a browser tab because a plain request was blocked. Used as a cross-check of our own reading of the advisory, not as a source for any figureThe Hacker Newsaccessed 2026-10-09
- Reported byState-run outlet's January 2025 account of Integrity Tech's public notice rejecting the US sanctions. The company's own notice was not read. Used only for the company's earlier positionGlobal Timesaccessed 2026-10-09


