Flax Typhoon Actively Exploits Five Known Vulnerabilities — CISA Issues October Deadline
The China-linked threat actor Flax Typhoon is actively exploiting five known vulnerabilities, including critical flaws in ProFTPD and ONLYOFFICE Docs, to gain initial access and exfiltrate data from targeted systems. These vulnerabilities were already documented and catalogued, meaning organizations had the opportunity to patch before exploitation occurred — a classic failure of timely patch management. CISA's mandate for federal agencies underscores that known, unpatched vulnerabilities remain one of the most preventable yet persistent attack vectors. The fact that nation-state actors are leveraging these flaws highlights the real-world consequences of delayed remediation, particularly for critical infrastructure and government systems.
Tactical Insight
Immediate actions
- Apply all patches listed in CISA's KEV catalog for ProFTPD, ONLYOFFICE Docs, and the other three affected products before the October 11 deadline.
- Audit your asset inventory immediately to identify any internet-facing instances of affected software versions.
- Isolate or take offline any systems running vulnerable software that cannot be patched within the mandated timeframe.
Long-term improvements
- Establish a formal SLA-driven patch management process that prioritizes CISA KEV entries with a 72-hour remediation window for critical flaws.
- Maintain a continuously updated, authoritative inventory of all software and firmware across your environment using an automated CMDB or SBOM.
- Implement network segmentation to limit lateral movement and data exfiltration opportunities if initial access is achieved.
Detection measures
- Subscribe to CISA KEV catalog alerts and integrate them directly into your vulnerability management platform for automated triage.
- Deploy file integrity monitoring and egress filtering to detect anomalous data exfiltration attempts consistent with Flax Typhoon TTPs.
- Enable threat intelligence feeds tied to Chinese state-sponsored actor indicators of compromise (IOCs) within your SIEM.