```

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five actively exploited security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their use by the China-linked threat cluster tracked as Flax Typhoon. Federal civilian agencies have until October 11 to remediate. The underlying lesson, however, reaches well beyond U.S. government networks: some of the newly catalogued flaws are a decade old, and intruders are still finding them exposed in the wild.

Reporting by The Hacker News on 9 October confirms the KEV additions cover five vulnerabilities abused by Flax Typhoon in real-world intrusions. Only one of the five is identified in the public summary available to this newsroom: CVE-2015-3306, a CVSS 10.0 improper access control flaw in the ProFTPD file transfer server. The full list of CVEs, affected products, and remediation deadlines should be pulled directly from CISA's KEV catalog and cross-checked against the National Vulnerability Database, rather than reconstructed from secondary reporting. This article deliberately does not attempt to itemise the remaining four.

An ancient flaw, still in the wild

CVE-2015-3306 warrants particular attention. Public advisories and exploit databases document the ProFTPD access control flaw as carrying a maximum severity score of 10.0 — and a vulnerability of this vintage being weaponised in 2026 is a stark illustration of a persistent gap in enterprise defence. Patch availability is rarely the bottleneck. Inventory and exposure are. Internet-facing services deployed years ago, forgotten, and never formally retired remain quietly exploitable long after upstream fixes shipped.

The practical takeaway for defenders is straightforward. Any organisation still running internet-reachable ProFTPD instances should treat them as a priority audit item — and in most environments, decommissioning or replacing the service is preferable to patching a file transfer daemon that has no legitimate business reason to be exposed to the public internet.

Why an actor's tradecraft matters

Flax Typhoon is tracked publicly — including by Microsoft's threat intelligence teams — as a China-nexus operation with a known history of opportunistic exploitation against edge devices and perimeter services, from management interfaces to VPN appliances. That history maps directly onto the class of flaws CISA has just catalogued.

For defenders, the pattern is the more durable signal than any single identifier. The actor targets whatever is exposed at the network boundary, regardless of vendor or product age. That is also why KEV inclusion should be read as a validated global threat signal rather than merely a U.S. compliance trigger: an entry in the catalog means there is credible evidence of in-the-wild exploitation, and for security teams in Hong Kong and the wider APAC region, that evidence justifies action on its own merits.

Scoping the October 11 deadline honestly

It is worth stating plainly. The October 11 remediation deadline binds U.S. federal civilian executive branch agencies under BOD 22-01. It imposes no legal obligation on Hong Kong organisations, private enterprises, or any entity outside the United States, and no local regulator has, as of this writing, issued a corresponding mandate tied to these specific KEV entries.

That said, the deadline remains a useful planning artefact. It sets out what CISA considers a reasonable remediation window for actively exploited vulnerabilities. Organisations that choose to align internal service-level agreements with it are adopting a defensible, evidence-based standard — not complying with a mandate.

Recommended actions for defenders
  1. Load the full five-CVE list from CISA's KEV catalog into vulnerability management tooling and scan against it. Do not work from secondary summaries.
  2. Audit internet-facing FTP and ProFTPD instances across all environments. Decommission where possible; the service is rarely essential.
  3. Review edge-device telemetry for anomalous authentication attempts and file-write activity on management interfaces and perimeter appliances — the surface Flax Typhoon has historically favoured.
  4. Treat October 11 as an outer bound, not a target. Actively exploited flaws with public exploit code should move faster than a compliance calendar.
Where to go next

Hong Kong organisations can cross-reference these vulnerabilities and report incidents through HKCERT (www.hkcert.org), which maintains local advisories and coordinates disclosure for the territory's IT community. CISA's KEV catalog remains the authoritative source for the full CVE list and federal remediation dates.

The broader lesson here is not about one threat actor or one deadline. It is that the perimeter still contains services nobody remembers deploying — and that somewhere, someone is checking whether they are still there.



美國網絡安全及基礎設施安全局(CISA)於星期四將五個正被活躍利用的安全漏洞加入其「已知被利用漏洞」(KEV)目錄,起因是與中國有關聯、代號 Flax Typhoon 的威脅組織曾利用這些漏洞。聯邦民政機構須於**10月11日**前完成修補。然而,此事的啟示遠不止於美國政府網絡:部分新列入目錄的漏洞已有十年歷史,而入侵者至今仍能在實戰中找到這些暴露在外的系統。

The Hacker News 於10月9日的報道證實,是次 KEV 新增項目涵蓋 Flax Typhoon 在實戰入侵中曾濫用的五個漏洞。在本新聞室可取得的公開摘要中,五個漏洞只有一個獲識別:**CVE-2015-3306**,即 ProFTPD 檔案傳輸伺服器中一個 CVSS 10.0 級別的存取控制不當漏洞。完整的 CVE 清單、受影響產品及修補期限,應直接從 CISA 的 KEV 目錄取得,並與國家漏洞數據庫(National Vulnerability Database)交叉核對,而非從二手報道重構。本文刻意不逐一列舉其餘四個漏洞。

### 一個古老漏洞,至今仍活躍於野外

CVE-2015-3306 值得特別留意。公開安全通告及 exploit 數據庫均記錄,ProFTPD 存取控制漏洞的最高嚴重性評分為 10.0 —— 一個如此陳舊的漏洞竟在2026年被武器化,正是企業防禦長期存在缺口的鮮明例證。補丁從來不是瓶頸,資產盤點和暴露面才是。多年前所部署、遭遺忘、從未正式停用而又對外開放的服務,即使上游早已推出修補,仍一直可被利用。

對防禦者而言,實務上的結論很清楚:任何仍然運行、可從互聯網訪問的 ProFTPD 實例,都應列為優先審計項目 —— 在大多數環境中,停用或更換該服務,比為一個毫無正當理由須向公網暴露的檔案傳輸 daemon 打補丁更為可取。

### 為何行為者的攻擊手法值得注意

Flax Typhoon 被公開追蹤 —— 包括 Microsoft 的威脅情報團隊 —— 屬中國背景的行動,有記錄在案的慣常做法,是機會主義式地利用邊界裝置和外圍服務,由管理介面至 VPN 裝置無所不包。這段歷史,正好對應 CISA 是次列入目錄的漏洞類別。

對防禦者而言,這種模式是比任何單一識別碼更持久的訊號。該行為者針對的,是一切在網絡邊界上暴露的東西,不論供應商或產品年份。這也是為何 KEV 收錄應被視為經核實的全球威脅訊號,而不只是美國的合規觸發條件:目錄中的每一個條目,都代表有實戰利用的可信證據;對香港及整個亞太地區的保安團隊而言,這份證據本身已足以構成行動的理據。

### 如實看待10月11日期限

有需要把話說清楚。10月11日的修補期限,是根據 BOD 22-01 對**美國聯邦民政行政部門機構**的約束。它對香港機構、私營企業或美國境外任何實體均不產生法律責任,截至本文撰寫時,本地監管機構亦未就這些特定 KEV 條目發出相應的強制要求。

儘管如此,該期限仍是一個有用的規劃參考。它列明 CISA 認為對活躍利用漏洞而言合理的修補時間表。機構若選擇將內部服務水平協議(SLA)與之對齊,是採納一套有理有據、站得住腳的標準 —— 而非遵守某項強制命令。

### 防禦者建議行動

1. **載入完整的五項 CVE 清單** —— 從 CISA 的 KEV 目錄取得 —— 至漏洞管理工具,並據此進行掃描。不要依賴二手摘要。
2. **審計所有環境中對外開放的 FTP 及 ProFTPD 實例**。可行的話應予以停用;該服務很少是必不可少的。
3. **檢視邊界裝置的遙測數據**,留意管理介面及外圍裝置上的異常認證嘗試和檔案寫入活動 —— 這正是 Flax Typhoon 歷來偏好的攻擊面。
4. **把10月11日視為最遲期限,而非目標**。已獲公開 exploit code 並正被活躍利用的漏洞,處理速度應較合規日程更快。

### 下一步可以到哪裡查詢

香港機構可透過 **HKCERT**(www.hkcert.org)交叉核對這些漏洞及報告事故。HKCERT 負責維護本地安全通告,並為香港 IT 社群協調漏洞披露。CISA 的 KEV 目錄則仍然是完整 CVE 清單及聯邦修補日期的權威來源。

這裡更廣泛的啟示,不在於某個威脅行為者或某個期限,而在於:網絡邊界上仍然存在著一些沒有人記得曾經部署的服務 —— 而在某處,有人正在查核它們是否仍然存在。

新聞來源 / Original News Source