BlackTree Security · Infrastructure · Automation · AI

Old Patches, Active Hunt

Replace unsupported software, preserve evidence and hunt beyond the patch.

On 8 October 2026, CISA added five vulnerabilities to its catalogue: CVE-2015-5477, CVE-2016-3081, CVE-2023-22894, CVE-2021-3199 and CVE-2015-3306.

The later retained catalogue was released at 20:09:18 UTC and contains 1,739 entries. Among these five records, only Strapi’s forensic-triage field changed from No to Yes. The current sequence for BIND, Struts, Strapi, ONLYOFFICE and ProFTPD is No, Yes, Yes, Yes and Yes.

The patch queue is now a hunt

The FBI, CISA, NSA and international partners published joint advisory AA26-281A on 8 October. Appendix B lists eight successfully exploited CVEs, including all five additions, but does not map each flaw to every target or victim.

The advisory links Integrity Tech to China-linked actors whose techniques resemble several private-sector labels, including Flax Typhoon, but says those actors may also operate independently.

Separately, an 8 October Justice Department release says unsealed court documents allege that actors working for Integrity Tech operated MicroScan and FishHub as part of activity known privately as Flax Typhoon. DOJ says seven domains were seized. It distinguishes scanning targets from some successful intrusions and says about 20 Taiwanese universities were confirmed FishHub victims.

Seizure reduces access to named infrastructure, but it does not establish that victim-side persistence or stolen credentials were removed.

All five catalogue records show an 11 October due date for applicable Federal Civilian Executive Branch assets under BOD 26-04. CISA’s implementation guidance makes the final response asset-specific. The date is useful urgency context for other organisations, but it is not a universal deadline. Every ransomware field is Unknown, which does not mean none.

Choose supported destinations

The advisory table is intrusion evidence, not lifecycle advice. Use the vendor evidence below to set product boundaries and a supported destination.

BIND: replace obsolete branches

The ISC advisory says a crafted TKEY query can terminate named on recursive or authoritative servers. Access controls and configurations that deny service do not prevent vulnerable processing. Historical fixes were 9.9.7-P2 and 9.10.2-P3, but ISC’s lifecycle table shows those branches are EOL. Confirm distribution backports, then move affected systems to a current supported BIND branch or vendor package.

Struts: verify Dynamic Method Invocation

Apache S2-032 covers Struts 2.3.20 through 2.3.28, excluding fixed releases 2.3.20.3 and 2.3.24.3. With Dynamic Method Invocation enabled, a crafted method: prefix can reach server-side code execution. Disable DMI where possible while planning the upgrade. The 2.3 branch is out of support, so use a currently supported Struts release rather than a historical 2.3 patch.

Strapi: resolve conflicting first-party ranges

AA26-281A lists Strapi through 4.5.5, while Strapi’s disclosure describes versions from 3.2.1 to below 4.8.0 as affected. The vendor timeline says 4.8.0 patched the flaw, while its summary says to use a version greater than 4.8.0. The current security policy supports only 5.x, making a supported 5.x release the defensible destination.

The flaw can expose administrator fields and reset tokens. A code-execution chain also needs the separate CVE-2023-22621 on an overlapping version through 4.5.5; that second issue is fixed from 4.5.6. Treat the chain as conditional, not as a universal outcome or one confirmed campaign.

ONLYOFFICE: keep three records distinct

The retained CISA entry says the flaw occurs when JWT is used and an image-upload path traversal may reach code execution; it does not state an affected-version floor. AA26-281A lists versions 5.1.5 through 5.6.2. The upstream 5.6.3 changelog confirms a path-traversal fix but does not name this CVE, JWT or code execution. ONLYOFFICE says it supports only the latest stable version. Identify JWT-enabled deployments, restrict exposure while upgrading and preserve upload and application logs.

ProFTPD: code execution remains environmental

ProFTPD 1.3.5 with mod_copy can allow unauthenticated file copying through SITE CPFR and SITE CPTO. The 1.3.5a notes record the historical fix, while the upstream patch adds a CopyEngine control and rejects unauthenticated use. Remote code execution depends on writable executable or loaded paths. Disable the module or feature where unnecessary, then use a current upstream or supported distribution release. The latest-release record showed 1.3.9d at retrieval, but no formal support-period policy was found.

Preserve, compare, then evict

  1. Match assets precisely. Record product, version, enabled feature, internet exposure and package origin.
  2. Preserve before disruptive changes. Retain relevant web, network, VPN, identity, email, endpoint and cloud logs.
  3. Test the advisory. Compare its indicators with retained telemetry for scanning, unusual connections, web attacks, abnormal accounts, unexpected VPN clients and outbound uploads.
  4. Contain and scope in parallel. Promptly isolate identified compromised hosts; safely preserve evidence, scope in parallel and use collected evidence to inform eviction.
  5. Move to a maintained target. Treat historical fixes as defect boundaries, then use a current supported release or vendor package.
  6. Strengthen access. Disable unused services and require MFA where possible.

Evidence boundary

The established Watch recorded a byte-identical catalogue check at 02:11:16 CEST on 9 October. This article makes no later-freshness claim. The catalogue and joint advisory establish exploitation at record and investigated-activity level. Neither source establishes how any reader’s environment was affected.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *