Five exploited bugs due Sunday, two AWS library fixes, and two Talos reports from 8 October.
- CISA added BIND, Apache Struts, Strapi, ONLYOFFICE Docs, and ProFTPD bugs on 8 October, due 11 October.
- AWS says databases-on-aws before 1.7.1 can turn crafted content into an OS command if an agent calls its helper.
- AWS says aws-cdk-lib before 2.267.0 can emit a symlink the build did not put in.
- Talos says event invitations are relaying a live Google sign-in, including the MFA step.
- Talos says malware is planting plaintext instructions aimed at the model that triages the file.
Security
CISA added five exploited bugs on 8 October, and the federal due date is 11 October
CISA Known Exploited Vulnerabilities catalog
CISA’s catalog, version 2026.10.08, lists five additions dated 8 October, each with a due date of 11 October: CVE-2015-5477 (ISC BIND, denial of service via TKEY queries), CVE-2016-3081 (Apache Struts, command injection via method:prefix when Dynamic Method Invocation is enabled), CVE-2023-22894 (Strapi, cleartext storage of sensitive information), CVE-2021-3199 (ONLYOFFICE Docs, path traversal when JWT is used), and CVE-2015-3306 (ProFTPD, improper access control via site cpfr and site cpto). The catalog’s required action on each is to apply vendor mitigations under BOD 26-04, or discontinue use if mitigations are unavailable. For Strapi, the catalog says the product could be end of life or end of service and that the bug can be chained with CVE-2023-22621 to achieve remote code execution. It hits anyone still running any of these, which are mostly old bugs in long-lived services.
This week. If you still run BIND, Apache Struts, Strapi, ONLYOFFICE Docs, or ProFTPD, apply the vendor fix or take that service offline before 11 October. Where the catalog sets forensic triage to yes, do that on any copy that faced the internet. For Strapi, the catalog’s own note is to move off an end-of-life build, and it says CVE-2023-22894 can be chained with CVE-2023-22621.
A crafted database command can become a shell if an agent runs the AWS helper
AWS Security Bulletin 2026-130-AWS, published 8 October and rated Important, covers CVE-2026-107322 in databases-on-aws, versions 1.0.0 through 1.7.0. AWS says a remote unauthenticated actor could supply crafted content that an agent ingests, and that operating-system command execution happens only if the agent then invokes the local helper with that database command value. The command runs with the permissions of the helper process, and AWS says Aurora DSQL itself is not affected. AWS says the fix is in 1.7.1 and later, available from the marketplace since 26 August, and that a pinned revision should use commit 8b13a503746a4ebb0402b936645163224058bde3 or later rather than a 1.7.1 release tag. It hits teams running agents with this plugin.
This week. Upgrade the databases-on-aws plugin to 1.7.1 or later, or move a pinned checkout to commit 8b13a503746a4ebb0402b936645163224058bde3 or later, and confirm the running agent loaded that build. Until then, do not let the agent call the local helper.
CDK asset bundling before 2.267.0 can emit a symlink the build did not put in
AWS Security Bulletin 2026-131-AWS, published 8 October and rated Important, covers CVE-2026-107608. AWS says that when an asset is bundled with a Docker file, aws-cdk-lib before 2.267.0 could let that Docker file insert a symlinked file or directory into the bundling output even though the symlink was not provided as input. Every version before 2.267.0 is affected, and 2.267.0 is the fix. It hits any CDK project that bundles assets with Docker.
This week. Upgrade aws-cdk-lib to 2.267.0 or later on every project that bundles assets with Docker, and rebuild the assets.
Event invitations are relaying a live Google sign-in, including the MFA step
Talos, in a post dated 8 October, says it observed the UAT-11985 campaign in mid-2026 against people affiliated with Taiwan research organizations, impersonating the Taiwan European Union Centre, NCCU Institute of International Relations, and the Taiwan Research Institute. Talos says the kit relays the victim’s identifier to Google, including a passkey check, then the password and any further MFA step. Talos says it cannot conclusively determine that a large language model wrote the emails, but that the campaign shows strong evidence of AI-assisted content. It names ClamAV signature Html.Phishing.UAT11985-10060614-0, Snort2 SID 1:67198, and Snort3 SID 7:31. It hits researchers, and anyone else who gets an event invitation.
This week. Do not finish a Google sign-in, including an MFA or passkey prompt, on a page opened from an event email or a QR code on a poster. Confirm the event on a channel you already use with that organization, and review Google login alerts for anyone who received the invitation.
Malware is planting plaintext instructions for the model that triages the file
Talos, in a post dated 8 October, covers four malware families, FRUITSHELL, PLOTSAFE, HOLLOWCLAD, and MANTLEMAZE, representing 84 distinct samples collected from January 2025 through July 2026. Talos says the best of these techniques steered the outcome in the attacker’s favor in about 35% of its test runs, and that the text must stay plaintext. That figure comes from Talos’s test, which triaged each string and sample combination with a panel of five local LLMs, not from anything we measured. Talos concludes that keeping sample text out of the instruction channel is the defense. It hits teams that feed strings extracted from files into an LLM for triage.
This week. In any job that sends strings extracted from a file to a model, put those strings in a block the prompt treats as data. Do not place that block where a system instruction would go.
Leave a Reply