View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

FBI Disrupts Chinese Espionage Platform Targeting U.S. Agencies

🚨 ACTIVE EXPLOITATION

  • FBI Disrupts Chinese Espionage Platform Targeting U.S. Agencies
    The FBI disrupted a Chinese espionage proxy network targeting U.S. agencies.
    • QTFY, linked to China-based Nanjing Xinjiuwei Network Technology Company, targeted NASA, the Federal Reserve, and other U.S. agencies.
    • The operation also affected healthcare, defense, energy, financial, university, aerospace, and software organizations.
    • QScan scanned and exploited vulnerable internet-of-things devices, while QTRouter managed access and routing.
    • The Fast Labyrinth relay network used compromised IoT devices, commercial proxies, and leased VPS infrastructure to conceal attackers’ origins.
    • Authorities seized qtproxy[.]xyz, qt-proxy[.]org, and qt-team[.]com; the platforms reportedly enabled access to sensitive networks for more than eight years.
      πŸ“Ž Coverage: cyberscoop.com Β· πŸ‘ via CyberScoop

πŸ”“ CVEs & KEV

  • CVE-2026-70419 β€” CVSS 9.1 β€” Dell Cloud Disaster Recovery RCE via OS Command Injection

  • CVE-2026-74770 β€” CVSS 8.8 β€” Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutr...

  • CVE-2026-79938 β€” CVSS 7.6 β€” Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper...

  • CVE-2026-54245 β€” CVSS 7.6 β€” Fleet: SQL injection in Okta conditional access endpoint allows host-controll...

  • CVE-2026-66003 β€” CVSS 7.1 β€” Frappe: Access control bypass via REST API dot-notation fields on linked doct...

  • CVE-2026-71054 β€” CVSS 6.5 β€” Vulnerability in Oracle Java SE (component: 2D). Supported versions that are ...

  • CVE-2026-49809 β€” CVSS 6.5 β€” Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Imprope...

  • CVE-2026-47842 β€” CVSS 6.5 β€” Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows ...

  • CVE-2026-74771 β€” CVSS 6.5 β€” Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization ...

  • CVE-2026-46371 β€” CVSS 6.5 β€” Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on App...

  • CVE-2026-47848 β€” CVSS 6.1 β€” Reactor Netty WebSocket Client Leaks Credentials On RedirectIn specific scena...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check