All Posts
Anomali Cyber Watch
Public Sector
1
min read

When One Phishing Click Costs 1.3 Million Records: The Converging Threats State Governments Cannot Ignore

Published on
October 7, 2026
Table of Contents
<p><strong>Threat Assessment Level: ELEVATED (trending toward HIGH)</strong></p> <p><em>Changed from baseline ELEVATED. The convergence of a critical Veeam Backup RCE (CVSS 9.4), two Chrome sandbox-escape zero-days (CVSS 9.6), confirmed PeopleSoft exploitation against a federal government contractor, and a catastrophic state court system breach collectively push the threat environment toward the HIGH threshold. The prior cycle's triple Citrix NetScaler zero-day and actively exploited FortiMail vulnerability remain unresolved for many organizations.</em></p> <h2><strong>Introduction</strong></h2> <p>This week, the FBI fired a contractor after a missed Oracle PeopleSoft patch handed the ShinyHunters criminal group terabytes of sensitive data &mdash; including the home addresses of HUMINT operatives. A state governments court system disclosed that a single employee clicking a malicious link led to the theft of 1.3 million records spanning three decades of court data, orders of protection, and foster care reports. And Veeam just disclosed a CVSS 9.4 remote code execution vulnerability in its Backup &amp; Replication product &mdash; the same product ransomware operators target first to eliminate your ability to recover.</p> <p>These are not abstract threats. They are confirmed incidents and active vulnerabilities that map directly to the technology stacks, data holdings, and operational realities of state government IT. If your state runs PeopleSoft for HR and payroll, Veeam for backup, Chrome on endpoints, or Citrix for remote access, this report demands your immediate attention.</p> <h2><strong>What Changed This Week</strong></h2> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Date</strong></p> </td> <td> <p><strong>Event</strong></p> </td> <td> <p><strong>Severity</strong></p> </td> <td> <p><strong>State Gov Impact</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p><strong>Oct 1&ndash;3</strong></p> </td> <td> <p>Three Citrix NetScaler zero-days (CVE-2026-88771, CVE-2026-88772, CVE-2026-88779) actively exploited; CISA KEV deadline Oct 7</p> </td> <td> <p><strong>CRITICAL</strong></p> </td> <td> <p>Citrix widely used for remote access across state agencies</p> </td> </tr> <tr> <td> <p><strong>Oct 4&ndash;6</strong></p> </td> <td> <p>Fortinet confirms active exploitation of FortiMail CVE-2026-104286 (CVSS 9.8) via dynamic linker hijacking; patches still pending for some branches</p> </td> <td> <p><strong>CRITICAL</strong></p> </td> <td> <p>FortiMail deployed in many state email security stacks</p> </td> </tr> <tr> <td> <p><strong>Oct 6</strong></p> </td> <td> <p>Veeam discloses CVE-2025-64393 (CVSS 9.4) &mdash; Backup Viewer role &rarr; SYSTEM RCE via insecure deserialization</p> </td> <td> <p><strong>CRITICAL</strong></p> </td> <td> <p>Veeam is the dominant backup platform in state data centers</p> </td> </tr> <tr> <td> <p><strong>Oct 6</strong></p> </td> <td> <p>Google Chrome 154.0.8037.39+ patches CVE-2026-106197 and CVE-2026-106358 (CVSS 9.6 each) &mdash; sandbox-escape use-after-free flaws</p> </td> <td> <p><strong>HIGH</strong></p> </td> <td> <p>Chrome is the standard browser across most state agencies</p> </td> </tr> <tr> <td> <p><strong>Oct 6</strong></p> </td> <td> <p>CISA publishes six ICS advisories affecting Hitachi Energy (REB500, RTU500, SOI, Asset Suite), Johnson Controls EasyIO FG, and Savannah lwIP SMTP</p> </td> <td> <p><strong>HIGH</strong></p> </td> <td> <p>Directly affects state-owned utility, building automation, and transportation infrastructure</p> </td> </tr> <tr> <td> <p><strong>Oct 7</strong></p> </td> <td> <p>Arizona court system breach disclosed &mdash; 1.3M records stolen via phishing; intrusion began Sep 24</p> </td> <td> <p><strong>HIGH</strong></p> </td> <td> <p>Direct analog to every state judiciary IT environment</p> </td> </tr> <tr> <td> <p><strong>Oct 7</strong></p> </td> <td> <p>FBI drops Accenture contractor after ShinyHunters exploited unpatched PeopleSoft, stealing 2&ndash;3 TB of sensitive data</p> </td> <td> <p><strong>HIGH</strong></p> </td> <td> <p>Many states run PeopleSoft for HR, finance, and payroll</p> </td> </tr> <tr> <td> <p><strong>Oct 7</strong></p> </td> <td> <p>CERT-UA identifies UAC-0277 operating 100+ compromised sites delivering LUNEXSTEALER via ClickFix technique with blockchain-backed C2</p> </td> <td> <p><strong>MODERATE-HIGH</strong></p> </td> <td> <p>State employees using search engines are at risk of drive-by compromise</p> </td> </tr> <tr> <td> <p><strong>Oct 7</strong></p> </td> <td> <p>BlueKit PhaaS platform reaches 1,000+ customers; offers AI-generated phishing templates targeting Citrix, Salesforce, and enterprise SSO</p> </td> <td> <p><strong>HIGH</strong></p> </td> <td> <p>Templates directly target state government technology stack</p> </td> </tr> <tr> <td> <p><strong>Oct 7</strong></p> </td> <td> <p>Volt Typhoon and Salt Typhoon both show anomalous 7+ day absence from reporting &mdash; likely improved OPSEC, not cessation of activity</p> </td> <td> <p><strong>HIGH</strong></p> </td> <td> <p><strong>These groups maintain documented pre-positioning in U.S. government and critical infrastructure networks</strong></p> </td> </tr> <tr> <td> <p><strong>Sep 30</strong></p> </td> <td> <p>Europol's Operation KillSwitch dismantles KillSec ransomware &mdash; first law-enforcement-validated AI-built ransomware infrastructure</p> </td> <td> <p><strong>MODERATE</strong></p> </td> <td> <p>Confirms AI is accelerating ransomware development lifecycle</p> </td> </tr> <tr> <td> <p><strong>Within 7-day window</strong></p> </td> <td> <p>Elastic/Kibana CVE-2026-102406 (CVSS 8.8) &mdash; cross-tenant data interception; patched in 8.19.22, 9.4.7, 9.5.4</p> </td> <td> <p><strong>MODERATE-HIGH</strong></p> </td> <td> <p>Elastic/Kibana widely used in state SIEM and log analytics deployments</p> </td> </tr> </tbody> </table> <h2><strong>Threat Timeline: September 24 &ndash; October 7, 2026</strong></h2> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Date</strong></p> </td> <td> <p><strong>Actor / Campaign</strong></p> </td> <td> <p><strong>Action</strong></p> </td> <td> <p><strong>Target</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>Sep 24</p> </td> <td> <p>Unattributed</p> </td> <td> <p>Phishing email clicked by Arizona court employee; intrusion begins</p> </td> <td> <p>Arizona Judiciary</p> </td> </tr> <tr> <td> <p>Sep 24</p> </td> <td> <p>Arizona court IT</p> </td> <td> <p>Intrusion detected on backup server; shut down within ~2 hours</p> </td> <td> <p>&mdash;</p> </td> </tr> <tr> <td> <p>Sep 30</p> </td> <td> <p>Europol</p> </td> <td> <p>Operation KillSwitch dismantles KillSec ransomware group</p> </td> <td> <p>KillSec infrastructure</p> </td> </tr> <tr> <td> <p>Oct 1</p> </td> <td> <p>Unattributed</p> </td> <td> <p>Active exploitation of Citrix NetScaler CVE-2026-88771 begins</p> </td> <td> <p>Internet-facing NetScaler appliances</p> </td> </tr> <tr> <td> <p>Oct 1</p> </td> <td> <p>CISA</p> </td> <td> <p>FortiMail CVE-2026-104286 added to KEV catalog</p> </td> <td> <p>FortiMail deployments</p> </td> </tr> <tr> <td> <p>Oct 1&ndash;3</p> </td> <td> <p>Unattributed</p> </td> <td> <p>CVE-2026-88772 and CVE-2026-88779 exploitation confirmed</p> </td> <td> <p>Citrix NetScaler</p> </td> </tr> <tr> <td> <p>Oct 4</p> </td> <td> <p>CISA</p> </td> <td> <p>CVE-2026-88779 added to KEV; federal remediation deadline set for Oct 7</p> </td> <td> <p>Federal/state Citrix deployments</p> </td> </tr> <tr> <td> <p>Oct 4&ndash;6</p> </td> <td> <p>Fortinet</p> </td> <td> <p>Confirms active exploitation of CVE-2026-104286 (CVSS 9.8) with persistence via dynamic linker hijacking</p> </td> <td> <p>FortiMail appliances</p> </td> </tr> <tr> <td> <p>Oct 6</p> </td> <td> <p>Veeam</p> </td> <td> <p>Emergency patch for CVE-2025-64393 (CVSS 9.4) &mdash; Backup Viewer &rarr; SYSTEM RCE</p> </td> <td> <p>Veeam B&amp;R v12 through 12.3.2.4854</p> </td> </tr> <tr> <td> <p>Oct 6</p> </td> <td> <p>Google</p> </td> <td> <p><strong>Chrome 154.0.8037.39+ released with 247 fixes including 4 Critical (CVE-2026-106197, CVE-2026-106358 at CVSS 9.6)</strong></p> </td> <td> <p>All Chrome users</p> </td> </tr> <tr> <td> <p>Oct 6</p> </td> <td> <p>CISA</p> </td> <td> <p>Six ICS advisories: Hitachi Energy REB500/RTU500/SOI/Asset Suite, Johnson Controls EasyIO FG, Savannah lwIP SMTP</p> </td> <td> <p><strong>Critical infrastructure operators</strong></p> </td> </tr> <tr> <td> <p>Oct 7</p> </td> <td> <p>ShinyHunters</p> </td> <td> <p>FBI confirms PeopleSoft exploitation led to catastrophic data breach; Accenture contractor terminated</p> </td> <td> <p>FBI (via contractor)</p> </td> </tr> <tr> <td> <p>Oct 7</p> </td> <td> <p>UAC-0277</p> </td> <td> <p>CERT-UA identifies 100+ compromised websites delivering LUNEXSTEALER via ClickFix + blockchain C2</p> </td> <td> <p>Windows users via search engines</p> </td> </tr> <tr> <td> <p>Oct 7</p> </td> <td> <p>"petrushka"</p> </td> <td> <p>BlueKit PhaaS platform documented with 1,000+ customers, 97 brands, AI-generated content, US smishing numbers</p> </td> <td> <p>Enterprise SSO, Citrix, Salesforce</p> </td> </tr> <tr> <td> <p>Oct 7</p> </td> <td> <p>Arizona Courts</p> </td> <td> <p>Public disclosure: 1.3M records stolen including 30 years of court data, protection orders, foster care records</p> </td> <td> <p>Arizona Judiciary</p> </td> </tr> </tbody> </table> <h2><strong>Key Threat Analysis</strong></h2> <h3><strong>1. PeopleSoft Under Active Exploitation &mdash; The ShinyHunters Government Campaign</strong></h3> <p>The FBI's decision to terminate its Accenture contractor is an extraordinary event that underscores a simple, devastating truth: <strong>unpatched ERP systems in government environments are being actively exploited by sophisticated criminal groups.</strong></p> <p><strong>ShinyHunters</strong> &mdash; a well-known data theft and extortion group &mdash; exploited a PeopleSoft vulnerability for which Oracle had released a patch in June 2026. The contractor failed to apply it. The result: 2&ndash;3 terabytes of stolen data including counterintelligence roles, home addresses of HUMINT operatives, and medical/psychiatric records.</p> <p><strong>Why this matters for state government:</strong> Oracle PeopleSoft is the backbone of HR, finance, and payroll operations for numerous state agencies. The same vulnerability class &mdash; exploitation of public-facing applications (ATT&amp;CK T1190) followed by credential abuse (T1078) and mass data exfiltration (T1567) &mdash; applies to any unpatched PeopleSoft instance. If your state's June Oracle Critical Patch Update has not been applied, you face the same risk the FBI just experienced.</p> <p><strong>Relevant ATT&amp;CK Techniques:</strong>T1190 (Exploit Public-Facing Application), T1078 (Valid Accounts), T1530 (Data from Cloud Storage Object), T1567 (Exfiltration Over Web Service)</p> <h3><strong>2. Veeam Backup RCE &mdash; The 48-Hour Ransomware Window</strong></h3> <p>CVE-2025-64393 is a CVSS 9.4 insecure deserialization vulnerability in Veeam Backup &amp; Replication that allows any user with the <strong>Backup Viewer</strong> role to execute arbitrary code as SYSTEM on the backup server. It affects all v12 builds through 12.3.2.4854.</p> <p>This is not a theoretical concern. Ransomware operators &mdash; including LockBit (BITWISE SPIDER) and Qilin (REVENANT SPIDER) &mdash; have a documented pattern of weaponizing Veeam vulnerabilities within 48&ndash;72 hours of patch disclosure. Their operational playbook is consistent: <strong>compromise backup infrastructure first, then deploy ransomware, eliminating the victim's ability to recover without paying.</strong></p> <p>Three additional Veeam CVEs were patched simultaneously:</p> <p>1. <strong>CVE-2026-58069</strong> (CVSS 8.3) &mdash; Cloud Connect file read</p> <p>2. <strong>CVE-2026-93026</strong> (CVSS 6.1) &mdash; Master key modification</p> <p>3. <strong>CVE-2025-64392</strong> (CVSS 4.8) &mdash; Enterprise Manager XSS</p> <p><strong>Relevant ATT&amp;CK Techniques:</strong>T1485 (Data Destruction), T1490 (Inhibit System Recovery)</p> <p><strong>The clock is ticking.</strong> Veeam has warned that attackers could reverse-engineer the patch to develop exploits. Every hour of delay increases the probability that ransomware operators will reach your backup servers before your patch team does.</p> <h3><strong>3. Chrome Sandbox Escapes &mdash; Drive-By Compromise at Scale</strong></h3> <p>Google's October 6 Chrome release patched <strong>247 security vulnerabilities</strong>, including two Critical sandbox-escape flaws:</p> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>CVE</strong></p> </td> <td> <p><strong>CVSS</strong></p> </td> <td> <p><strong>Component</strong></p> </td> <td> <p><strong>Impact</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>CVE-2026-106197</p> </td> <td> <p>9.6</p> </td> <td> <p>Browser (use-after-free)</p> </td> <td> <p>Code execution outside sandbox &mdash; full OS compromise</p> </td> </tr> <tr> <td> <p>CVE-2026-106358</p> </td> <td> <p>9.6</p> </td> <td> <p>Navigation (use-after-free)</p> </td> <td> <p>Code execution outside sandbox &mdash; full OS compromise</p> </td> </tr> <tr> <td> <p>CVE-2026-106240</p> </td> <td> <p>8.8</p> </td> <td> <p>V8 JavaScript (type confusion)</p> </td> <td> <p>Code execution inside sandbox</p> </td> </tr> </tbody> </table> <p>Sandbox escapes are the most valuable class of browser vulnerability because they convert a simple website visit into full operating system compromise &mdash; no additional exploitation steps required (ATT&amp;CK T1189: Drive-by Compromise). A state employee visiting a compromised vendor portal, a constituent-facing website, or clicking a link in a phishing email could have their workstation fully compromised.</p> <h3><strong>4. Arizona Court Breach &mdash; A Warning to Every State Judiciary</strong></h3> <p>The Arizona court system breach is the most operationally relevant event in this report for state government leaders because it is not a hypothetical &mdash; it is a confirmed attack against a peer organization with an architecture that mirrors most state judiciaries.</p> <p><strong>What happened:</strong> An employee clicked a malicious link in an email (T1566.001). Attackers pivoted to a backup server (T1530) and exfiltrated:</p> <p>4. <strong>1.3 million records</strong> of individuals with unpaid court fees/fines/restitution spanning 30 years</p> <p>5. <strong>~30,000 active and inactive orders of protection</strong> &mdash; domestic violence victims, stalking victims</p> <p>6. <strong>150,000 foster care review board reports</strong> dating to 2010</p> <p>Court technology staff detected the intrusion within approximately two hours on September 24 and shut down the affected server. Despite the rapid detection, the volume of data stolen was catastrophic.</p> <p><strong>The structural problem:</strong> State court systems typically maintain decades of records in legacy databases with long retention requirements. They hold some of the most sensitive PII in government &mdash; protection orders reveal the identities and locations of domestic violence survivors. The combination of legacy architecture, long data retention, and sensitive data makes judiciary systems uniquely high-value targets.</p> <h3><strong>5. ClickFix and LUNEXSTEALER &mdash; Social Engineering Evolves</strong></h3> <p>CERT-UA has identified threat actor <strong>UAC-0277</strong> operating over 100 compromised legitimate websites that inject malicious JavaScript presenting fake Cloudflare verification pages. When a Windows user arrives via a search engine, the <strong>ClickFix</strong> technique tricks them into running a command that downloads an MSI package delivering <strong>LUNEXSTEALER</strong> (also known as Psychedelic Stealer).</p> <p>What makes this campaign technically notable:</p> <p>7. <strong>Blockchain-backed C2 (EtherHiding):</strong> UAC-0277 stores C2 configuration in Polygon/Ethereum smart contracts. Traditional takedown methods &mdash; domain seizure, IP blocking &mdash; are ineffective against immutable blockchain storage. This is a significant evolution in C2 resilience.</p> <p>8. <strong>Three MSI delivery variants:</strong> Direct install, BYOVD using CVE-2023-20598 (AMD driver vulnerability that can bypass EDR), and DLL sideloading via FnHotkeyUtility.exe + spkvol.dll.</p> <p>9. <strong>LUNARAXE browser extension:</strong> Masquerades as "Microsoft Office Word Editor" and provides full browser remote control, enabling session hijacking (T1185).</p> <p>We are now tracking <strong>two distinct ClickFix campaigns</strong> &mdash; UAC-0277 with LUNEXSTEALER and UNC6924/UNC7032 with FleetDeck/ScreenConnect remote management tools. The technique's proven success rate means additional threat actors will adopt it.</p> <p><strong>Relevant ATT&amp;CK Techniques:</strong>T1189, T1204.002, T1059.001, T1218.007, T1068, T1574.002, T1555, T1185, T1102</p> <h3><strong>6. BlueKit PhaaS &mdash; AI-Powered Credential Harvesting at Industrial Scale</strong></h3> <p><strong>BlueKit</strong> is a subscription-based Phishing-as-a-Service platform operated by a Russian-speaking threat actor known as "petrushka." First observed in April 2026, it now serves <strong>over 1,000 customers</strong> and offers <strong>97 brand templates across 176 phishing variants</strong>.</p> <p>The enterprise SSO templates are what should concern state IT leaders most:</p> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Template Category</strong></p> </td> <td> <p><strong>Targeted Brands</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>Enterprise SSO / Remote Access</p> </td> <td> <p>Citrix, Cloudflare, Cisco, Check Point</p> </td> </tr> <tr> <td> <p>CRM / Cloud Platforms</p> </td> <td> <p>Salesforce, HubSpot, GitHub</p> </td> </tr> <tr> <td> <p>Generative AI Platforms</p> </td> <td> <p>OpenAI, Anthropic</p> </td> </tr> <tr> <td> <p>Financial / Consumer</p> </td> <td> <p>Multiple banking and crypto brands</p> </td> </tr> </tbody> </table> <p>Key capabilities that elevate this threat:</p> <p>10. <strong>AI-assisted phishing content generation</strong> &mdash; grammatically perfect, contextually appropriate lures</p> <p>11. <strong>SMS sender with local US phone numbers</strong> &mdash; smishing campaigns that appear to originate domestically</p> <p>12. <strong>Digital fingerprinting</strong> &mdash; victim profiling to tailor the attack</p> <p>13. <strong>Single-dashboard campaign management</strong> &mdash; lowering the barrier to entry for less sophisticated attackers</p> <p>When combined with the <strong>EvilTokens</strong> platform (tracked since the prior cycle, targeting Microsoft 365 via device code phishing by Storm-2992), state agencies now face <strong>two concurrent PhaaS platforms</strong> specifically designed to harvest enterprise credentials at scale.</p> <p><strong>Relevant ATT&amp;CK Techniques:</strong>T1566.001, T1598.003, T1539, T1528</p> <h3><strong>7. Critical Infrastructure &mdash; Six ICS Advisories in 24 Hours</strong></h3> <p>CISA published six ICS advisories on October 6 affecting products commonly deployed in state government facilities:</p> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Vendor</strong></p> </td> <td> <p><strong>Product</strong></p> </td> <td> <p><strong>Relevance to State Gov</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>Hitachi Energy</p> </td> <td> <p>REB500</p> </td> <td> <p>Substation automation &mdash; state-owned utility infrastructure</p> </td> </tr> <tr> <td> <p>Hitachi Energy</p> </td> <td> <p>RTU500</p> </td> <td> <p>Remote terminal units &mdash; water treatment, transportation</p> </td> </tr> <tr> <td> <p>Hitachi Energy</p> </td> <td> <p>SOI (System Operation Interface)</p> </td> <td> <p>Grid operations</p> </td> </tr> <tr> <td> <p>Hitachi Energy</p> </td> <td> <p>Asset Suite</p> </td> <td> <p>Asset management for utilities</p> </td> </tr> <tr> <td> <p>Johnson Controls</p> </td> <td> <p>EasyIO FG</p> </td> <td> <p>Building automation &mdash; state office buildings, data centers</p> </td> </tr> <tr> <td> <p>Savannah</p> </td> <td> <p>lwIP SMTP</p> </td> <td> <p>Lightweight IP stack &mdash; embedded devices</p> </td> </tr> </tbody> </table> <p>These advisories arrive alongside the still-active FortiMail CVE-2026-104286 (CVSS 9.8), which Fortinet has confirmed is being exploited in the wild with persistence achieved through dynamic linker hijacking. Patches for some FortiMail branches remain pending.</p> <h3><strong>8. Persistent Nation-State Threat Landscape</strong></h3> <p>While no new Volt Typhoon, Salt Typhoon, or APT28 activity was attributed in this cycle, the broader nation-state threat picture remains active:</p> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Actor</strong></p> </td> <td> <p><strong>Origin</strong></p> </td> <td> <p><strong>Recent Activity</strong></p> </td> <td> <p><strong>State Gov Relevance</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p><strong>APT41</strong></p> </td> <td> <p>China (state-affiliated)</p> </td> <td> <p>Persistent targeting of government networks</p> </td> <td> <p><strong>HIGH &mdash; espionage against state databases</strong></p> </td> </tr> <tr> <td> <p><strong>Volt Typhoon</strong></p> </td> <td> <p>China (state-affiliated)</p> </td> <td> <p><strong>Anomalous 7+ day reporting absence</strong> &mdash; may indicate improved OPSEC, not cessation</p> </td> <td> <p><strong>CRITICAL &mdash; pre-positioned in US critical infrastructure</strong></p> </td> </tr> <tr> <td> <p><strong>Salt Typhoon</strong></p> </td> <td> <p>China (state-affiliated)</p> </td> <td> <p><strong>Anomalous 7+ day reporting absence</strong></p> </td> <td> <p><strong>HIGH &mdash; telecommunications targeting</strong></p> </td> </tr> <tr> <td> <p><strong>Longlegs / Storm-2603</strong></p> </td> <td> <p>China (state-affiliated)</p> </td> <td> <p>Active campaigns</p> </td> <td> <p><strong>MODERATE-HIGH</strong></p> </td> </tr> <tr> <td> <p><strong>APT28 (GRU)</strong></p> </td> <td> <p>Russia (military intelligence)</p> </td> <td> <p>Persistent operations</p> </td> <td> <p><strong>HIGH &mdash; government targeting</strong></p> </td> </tr> <tr> <td> <p><strong>APT29 (SVR)</strong></p> </td> <td> <p>Russia (foreign intelligence)</p> </td> <td> <p>Persistent operations</p> </td> <td> <p><strong>HIGH &mdash; government targeting</strong></p> </td> </tr> <tr> <td> <p><strong>PRIMITIVEBEAR (FSB-linked)</strong></p> </td> <td> <p>Russia</p> </td> <td> <p>Active campaigns</p> </td> <td> <p><strong>MODERATE</strong></p> </td> </tr> <tr> <td> <p><strong>UNC6916</strong></p> </td> <td> <p>Unattributed</p> </td> <td> <p>DERBSPARK campaigns targeting government (updated Oct 7)</p> </td> <td> <p><strong>HIGH</strong></p> </td> </tr> <tr> <td> <p><strong>UNC6727</strong></p> </td> <td> <p>China-origin</p> </td> <td> <p>SUNBRICKED targeting government</p> </td> <td> <p><strong>HIGH</strong></p> </td> </tr> <tr> <td> <p><strong>UNC7072</strong></p> </td> <td> <p>Unattributed</p> </td> <td> <p>CLOUDHAZE discovery activity in education/government</p> </td> <td> <p><strong>MODERATE-HIGH</strong></p> </td> </tr> <tr> <td> <p><strong>ShinyHunters</strong></p> </td> <td> <p>Cybercriminal</p> </td> <td> <p>Confirmed PeopleSoft exploitation against government</p> </td> <td> <p><strong>CRITICAL &mdash; active exploitation</strong></p> </td> </tr> </tbody> </table> <p><strong>Critical absence note:</strong> The 7+ day silence from Volt Typhoon and Salt Typhoon is anomalous. These Chinese state-affiliated groups have been persistently active against U.S. government networks throughout 2026. Their absence from reporting more likely reflects improved operational security than a cessation of activity. State agencies should not reduce vigilance.</p> <h2><strong>Predictive Analysis: Next 7 Days</strong></h2> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Prediction</strong></p> </td> <td> <p><strong>Probability</strong></p> </td> <td> <p><strong>Basis</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>Veeam CVE-2025-64393 weaponized by ransomware operators</p> </td> <td> <p><strong>&gt;75% (HIGH)</strong></p> </td> <td> <p>Historical pattern: LockBit/BITWISE SPIDER and Qilin/REVENANT SPIDER weaponize Veeam vulnerabilities within 48&ndash;72 hours of disclosure. Patch was released Oct 6.</p> </td> </tr> <tr> <td> <p>Chrome sandbox escapes incorporated into exploit kits</p> </td> <td> <p><strong>50&ndash;75% (MODERATE)</strong></p> </td> <td> <p>CVSS 9.6 sandbox escapes are premium exploit commodities. Drive-by compromise campaigns targeting government employees during normal browsing are likely.</p> </td> </tr> <tr> <td> <p>ClickFix campaigns expand to target .gov domains or government-adjacent websites</p> </td> <td> <p><strong>50&ndash;75% (MODERATE)</strong></p> </td> <td> <p>Two distinct actor groups (UAC-0277, UNC6924/UNC7032) already using the technique at scale. Government-themed lures are a logical next step.</p> </td> </tr> <tr> <td> <p>Additional PeopleSoft exploitation attempts against government targets</p> </td> <td> <p><strong>50&ndash;75% (MODERATE)</strong></p> </td> <td> <p>ShinyHunters' success against the FBI contractor validates the attack path. Other criminal groups will attempt the same.</p> </td> </tr> <tr> <td> <p>Volt Typhoon / Salt Typhoon activity resurfaces in reporting</p> </td> <td> <p><strong>25&ndash;50% (LOW-MODERATE)</strong></p> </td> <td> <p>Current absence is anomalous. Activity likely continues but with improved OPSEC.</p> </td> </tr> <tr> <td> <p>BlueKit PhaaS campaigns targeting state government SSO portals</p> </td> <td> <p><strong>50&ndash;75% (MODERATE)</strong></p> </td> <td> <p>1,000+ customers with Citrix and Salesforce templates; state agencies are natural targets.</p> </td> </tr> <tr> <td> <p>Ransomware group targets a state or local government entity using Veeam as the initial pivot</p> </td> <td> <p><strong>25&ndash;50% (LOW-MODERATE)</strong></p> </td> <td> <p>Dependent on patch adoption speed. Agencies that delay patching face elevated risk.</p> </td> </tr> </tbody> </table> <h2><strong>SOC Operational Guidance</strong></h2> <h3><strong>Immediate Detection Priorities</strong></h3> <p><strong>1. Veeam Exploitation Indicators (CVE-2025-64393)</strong></p> <p>14. <strong>Hunt hypothesis:</strong> An attacker with compromised Backup Viewer credentials exploits insecure deserialization in the Veeam Mount Service to achieve SYSTEM-level code execution on backup servers.</p> <p>15. <strong>Monitor:</strong> Anomalous process execution originating from Veeam Backup &amp; Replication services, particularly the Mount Service. Watch for unexpected child processes of Veeam services (cmd.exe, powershell.exe, certutil.exe).</p> <p>16. <strong>Detect:</strong> Audit Backup Viewer role assignments &mdash; any account with this role that should not have it is a pre-exploitation indicator. Alert on new Backup Viewer role grants.</p> <p>17. <strong>ATT&amp;CK:</strong>T1485 (Data Destruction), T1490 (Inhibit System Recovery)</p> <p>18. <strong>Defensive guidance:</strong> Isolate Veeam management interfaces from general network access. Verify backup integrity and test restore procedures. Ensure immutable/air-gapped backup copies exist.</p> <p><strong>2. PeopleSoft Exploitation (ShinyHunters TTPs)</strong></p> <p>19. <strong>Hunt hypothesis:</strong> An external attacker exploits an unpatched PeopleSoft web interface to gain initial access, then uses valid credentials to move laterally and exfiltrate HR/finance data.</p> <p>20. <strong>Monitor:</strong> Unusual HTTP requests to PeopleSoft web server endpoints, particularly those matching known exploitation patterns. Watch for bulk data queries against PeopleSoft databases outside normal business hours.</p> <p>21. <strong>Detect:</strong> Alert on large data exports from PeopleSoft (T1530), new or modified database queries, and authentication anomalies on PeopleSoft accounts (T1078).</p> <p>22. <strong>ATT&amp;CK:</strong>T1190 (Exploit Public-Facing Application), T1078 (Valid Accounts), T1567 (Exfiltration Over Web Service)</p> <p>23. <strong>Defensive guidance:</strong> Verify June 2026 Oracle Critical Patch Update is applied. Place PeopleSoft behind WAF with virtual patching rules. Restrict database-level access to least privilege.</p> <p><strong>3. LUNEXSTEALER / ClickFix Campaign (UAC-0277)</strong></p> <p>24. <strong>Hunt hypothesis:</strong> A state employee visits a compromised legitimate website via search engine, encounters a fake Cloudflare verification page, and executes a command that downloads LUNEXSTEALER via msiexec.</p> <p>25. <strong>Block IOCs:</strong></p> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Type</strong></p> </td> <td> <p><strong>Value</strong></p> </td> <td> <p><strong>Context</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>IPv4</p> </td> <td> <p>107[.]175.82.242</p> </td> <td> <p>C2/delivery server</p> </td> </tr> <tr> <td> <p>IPv4</p> </td> <td> <p>193[.]178.158.61</p> </td> <td> <p>C2/delivery server</p> </td> </tr> <tr> <td> <p>IPv4</p> </td> <td> <p>193[.]178.159.128</p> </td> <td> <p>C2/delivery server</p> </td> </tr> <tr> <td> <p>IPv4</p> </td> <td> <p>109[.]238.86.112</p> </td> <td> <p>C2/delivery server</p> </td> </tr> <tr> <td> <p>IPv4</p> </td> <td> <p>109[.]238.86.113</p> </td> <td> <p>C2/delivery server</p> </td> </tr> </tbody> </table> <p>26. <strong>Monitor for persistence indicators:</strong></p> <p>&ndash; Scheduled task named psychedelicloveUtils</p> <p>&ndash; DLL sideloading: FnHotkeyUtility.exe loading spkvol.dll in %PROGRAMDATA% subdirectories (e.g., SalmonLightSlateGray, SlateGrayChocolate, GrayLightCyan)</p> <p>&ndash; Browser extension claiming to be "Microsoft Office Word Editor" (LUNARAXE)</p> <p>27. <strong>Detect:</strong> Alert on msiexec.exe commands containing URLs (msiexec /i http...) &mdash; this is the primary ClickFix execution vector (T1218.007). Monitor for PowerShell execution triggered by the Windows Run dialog (T1059.001).</p> <p>28. <strong>ATT&amp;CK:</strong>T1189, T1204.002, T1059.001, T1218.007, T1068, T1574.002, T1555, T1185, T1102</p> <p>29. <strong>Defensive guidance:</strong> Restrict Windows Run dialog via GPO for standard users. Enforce browser extension allowlists. Block msiexec network fetches at the proxy/firewall level. Add blockchain RPC endpoints (Polygon, Ethereum mainnet) to network monitoring watchlists to detect EtherHiding C2 callbacks.</p> <p><strong>4. BlueKit / EvilTokens Credential Harvesting</strong></p> <p>30. <strong>Hunt hypothesis:</strong> State employees receive AI-generated phishing emails or SMS messages (from US local numbers) directing them to credential harvesting pages mimicking Citrix, Salesforce, or SSO login portals.</p> <p>31. <strong>Monitor:</strong> Conditional Access logs for impossible-travel or anomalous device-code authentication flows. Watch for new OAuth app consents in Azure AD/Entra ID. Monitor for MFA fatigue patterns (repeated push notifications).</p> <p>32. <strong>Detect:</strong> Alert on authentication from unfamiliar ASNs immediately following password entry on external sites. Monitor for session token replay from new IP addresses (T1539).</p> <p>33. <strong>ATT&amp;CK:</strong>T1566.001, T1598.003, T1539, T1528</p> <p>34. <strong>Defensive guidance:</strong> Deploy FIDO2/passkey authentication for privileged accounts &mdash; hardware-bound credentials defeat credential harvesting entirely. Implement token binding where supported. Review Conditional Access policies to require compliant devices.</p> <p><strong>5. Chrome Sandbox Escape Exploitation</strong></p> <p>35. <strong>Hunt hypothesis:</strong> A state employee visits a malicious or compromised website that exploits CVE-2026-106197 or CVE-2026-106358 to escape the Chrome sandbox and execute code on the underlying OS.</p> <p>36. <strong>Monitor:</strong> EDR alerts for unexpected child processes spawned by chrome.exe (particularly cmd.exe, powershell.exe, rundll32.exe, or any process writing to disk outside the Chrome profile directory).</p> <p>37. <strong>Detect:</strong> Browser crash reports correlated with network connections to unfamiliar domains. Unusual Chrome renderer process behavior.</p> <p>38. <strong>ATT&amp;CK:</strong>T1189 (Drive-by Compromise), T1203 (Exploitation for Client Execution)</p> <p>39. <strong>Defensive guidance:</strong> Push Chrome updates immediately. Enable Chrome's Enhanced Safe Browsing. Consider site isolation policies for high-risk browsing.</p> <h3><strong>Additional IOCs from Collection</strong></h3> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Type</strong></p> </td> <td> <p><strong>Value</strong></p> </td> <td> <p><strong>Context</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>IPv4</p> </td> <td> <p>188[.]135.15.49</p> </td> <td> <p>Associated with threat activity in collection</p> </td> </tr> <tr> <td> <p>Domain</p> </td> <td> <p>c0ce[.]org</p> </td> <td> <p>Suspicious domain from collection</p> </td> </tr> <tr> <td> <p>Domain</p> </td> <td> <p>p7cp[.]org</p> </td> <td> <p>Suspicious domain from collection</p> </td> </tr> <tr> <td> <p>Domain</p> </td> <td> <p>w3a01[.]net</p> </td> <td> <p>Suspicious domain from collection</p> </td> </tr> <tr> <td> <p>Domain</p> </td> <td> <p>f91j[.]org</p> </td> <td> <p>Suspicious domain from collection</p> </td> </tr> <tr> <td> <p>Domain</p> </td> <td> <p>gov-by[.]com</p> </td> <td> <p>Government domain impersonation</p> </td> </tr> </tbody> </table> <p>Additional IOCs for the campaigns discussed in this report are available through Anomali ThreatStream Next-Gen and partner feeds.</p> <h2><strong>Sector-Specific Defensive Priorities</strong></h2> <h3><strong>Financial Services (State Treasury, Revenue, Comptroller)</strong></h3> <p>40. <strong>Priority threat:</strong> ShinyHunters PeopleSoft exploitation. State financial agencies running PeopleSoft for payroll and accounting face the identical attack path that compromised the FBI contractor. Verify Oracle June 2026 patch immediately.</p> <p>41. <strong>Secondary threat:</strong> BlueKit PhaaS templates target financial brands and SSO gateways. Treasury and revenue staff handling sensitive financial data are high-value phishing targets.</p> <p>42. <strong>Action:</strong> Audit PeopleSoft patch status. Implement database activity monitoring on financial databases. Deploy FIDO2 for treasury staff with wire transfer authority.</p> <h3><strong>Energy and Utilities (State-Owned or Regulated)</strong></h3> <p>43. <strong>Priority threat:</strong> Six CISA ICS advisories (Oct 6) affect Hitachi Energy products (REB500, RTU500, SOI, Asset Suite) used in substation automation, remote terminal units, and grid operations. Johnson Controls EasyIO FG affects building automation.</p> <p>44. <strong>Secondary threat:</strong> Volt Typhoon's documented pre-positioning in U.S. critical infrastructure. Their 7+ day reporting absence does not indicate reduced risk.</p> <p>45. <strong>Action:</strong> Inventory Hitachi Energy and Johnson Controls deployments. Apply ICS patches per CISA advisories. Segment OT networks from IT networks. Conduct tabletop exercise for Volt Typhoon-style pre-positioning scenario.</p> <h3><strong>Healthcare (State Health Agencies, Medicaid, Public Health)</strong></h3> <p>46. <strong>Priority threat:</strong> Arizona court breach included foster care review board reports &mdash; health-adjacent PII. State health agencies hold similarly sensitive data (Medicaid records, mental health records, vital statistics).</p> <p>47. <strong>Secondary threat:</strong> Ransomware groups targeting backup infrastructure (Veeam CVE-2025-64393) could cripple health IT systems during a public health emergency.</p> <p>48. <strong>Action:</strong> Patch Veeam immediately. Audit access controls on Medicaid and vital statistics databases. Ensure HIPAA breach notification procedures are current. Verify immutable backup copies of critical health data.</p> <h3><strong>Government (Executive Agencies, Legislature, Elections)</strong></h3> <p>49. <strong>Priority threat:</strong> ClickFix social engineering campaigns (UAC-0277 and UNC6924/UNC7032) targeting government employees via compromised legitimate websites. State employees researching policy, legislation, or vendor information via search engines are at risk.</p> <p>50. <strong>Secondary threat:</strong> BlueKit PhaaS with Citrix and SSO templates directly targets the remote access infrastructure government agencies depend on.</p> <p>51. <strong>Action:</strong> Deploy GPO restrictions on Windows Run dialog for standard users. Enforce browser extension allowlists. Conduct targeted security awareness training on fake browser verification prompts. Implement Conditional Access policies requiring compliant/managed devices for all Citrix and SSO access.</p> <h3><strong>Aviation and Logistics (State DOT, Ports, Transit Authorities)</strong></h3> <p>52. <strong>Priority threat:</strong> ICS/SCADA vulnerabilities in Hitachi Energy RTU500 (remote terminal units used in transportation infrastructure) and Johnson Controls EasyIO FG (building automation in transit facilities).</p> <p>53. <strong>Secondary threat:</strong> Chinese APT groups (APT41, Volt Typhoon) have documented interest in transportation infrastructure for both espionage and pre-positioning.</p> <p>54. <strong>Action:</strong> Inventory ICS/SCADA systems in transportation facilities. Apply CISA ICS advisory patches. Segment building automation systems from IT networks. Review remote access to OT systems &mdash; eliminate any direct internet exposure.</p> <h2><strong>Prioritized Defense Recommendations</strong></h2> <h3><strong>IMMEDIATE (Within 24 Hours)</strong></h3> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Priority</strong></p> </td> <td> <p><strong>Team</strong></p> </td> <td> <p><strong>Action</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>IMMEDIATE</p> </td> <td> <p>IT Ops</p> </td> <td> <p><strong>Verify Oracle PeopleSoft patch status across all state agencies. The June 2026 Oracle Critical Patch Update must be applied. The FBI/ShinyHunters breach confirms this exact vulnerability is being actively exploited against government PeopleSoft deployments.</strong></p> </td> </tr> <tr> <td> <p>IMMEDIATE</p> </td> <td> <p>IT Ops</p> </td> <td> <p><strong>Apply Veeam Backup &amp; Replication patch</strong> to build 12.3.2.4934 (12.3.2 P4) on all Veeam servers. CVE-2025-64393 allows Backup Viewer &rarr; SYSTEM RCE. Audit all accounts with Backup Viewer role and remove unnecessary grants. Ransomware weaponization expected within 48&ndash;72 hours.</p> </td> </tr> <tr> <td> <p>IMMEDIATE</p> </td> <td> <p>IT Ops</p> </td> <td> <p><strong>Push Google Chrome update</strong> to 154.0.8037.39+ (Windows/Mac) or 155.0.8059.39+ (Linux) across all managed endpoints. CVE-2026-106197 and CVE-2026-106358 (CVSS 9.6) enable OS-level code execution via a single website visit.</p> </td> </tr> <tr> <td> <p>IMMEDIATE</p> </td> <td> <p>IT Ops</p> </td> <td> <p><strong>Verify Citrix NetScaler remediation</strong> &mdash; CISA KEV deadline is today (Oct 7) for CVE-2026-88779. Confirm CVE-2026-88771 and CVE-2026-88772 are also patched.</p> </td> </tr> <tr> <td> <p>IMMEDIATE</p> </td> <td> <p>IT Ops</p> </td> <td> <p><strong>Verify FortiMail patching</strong> for CVE-2026-104286 (CVSS 9.8). Active exploitation confirmed with persistence via dynamic linker hijacking. Apply available patches; isolate unpatched appliances.</p> </td> </tr> </tbody> </table> <h3><strong>7-DAY</strong></h3> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Priority</strong></p> </td> <td> <p><strong>Team</strong></p> </td> <td> <p><strong>Action</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>7-DAY</p> </td> <td> <p>SOC</p> </td> <td> <p><strong>Deploy LUNEXSTEALER IOCs</strong> to SIEM/EDR blocklists (IPs: 107[.]175.82.242, 193[.]178.158.61, 193[.]178.159.128, 109[.]238.86.112, 109[.]238.86.113). Hunt for scheduled task psychedelicloveUtils and DLL sideloading via FnHotkeyUtility.exe + spkvol.dll.</p> </td> </tr> <tr> <td> <p>7-DAY</p> </td> <td> <p>SOC</p> </td> <td> <p><strong>Block msiexec.exe network fetches</strong> &mdash; alert on or block msiexec /i http... commands. Restrict Windows Run dialog via GPO for standard users. Enforce browser extension allowlists to prevent LUNARAXE-style malicious extensions.</p> </td> </tr> <tr> <td> <p>7-DAY</p> </td> <td> <p>IT Ops</p> </td> <td> <p><strong>Upgrade Elastic/Kibana</strong> to 8.19.22, 9.4.7, or 9.5.4 to remediate CVE-2026-102406 (cross-tenant data interception, CVSS 8.8). Audit Fleet package upload history for unauthorized packages.</p> </td> </tr> <tr> <td> <p>7-DAY</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Brief judiciary IT leadership</strong> on the Arizona court system breach. Recommend audit of court case management system access controls, backup server network segmentation, and phishing resilience assessment for court staff.</p> </td> </tr> <tr> <td> <p>7-DAY</p> </td> <td> <p>SOC</p> </td> <td> <p><strong>Add blockchain RPC monitoring</strong> &mdash; watch for outbound connections to Polygon and Ethereum mainnet RPC endpoints from state network endpoints. This detects EtherHiding C2 callbacks used by LUNEXSTEALER.</p> </td> </tr> </tbody> </table> <h3><strong>30-DAY</strong></h3> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Priority</strong></p> </td> <td> <p><strong>Team</strong></p> </td> <td> <p><strong>Action</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>30-DAY</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Evaluate FIDO2/passkey deployment for high-value accounts to defeat credential harvesting by BlueKit and EvilTokens PhaaS platforms. Hardware-bound credentials are the only reliable defense against AI-generated phishing at scale.</strong></p> </td> </tr> <tr> <td> <p>30-DAY</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Commission phishing resilience assessment</strong> specifically testing AI-generated phishing content and ClickFix-style fake browser verification prompts. Traditional phishing simulations may not reflect the current threat.</p> </td> </tr> <tr> <td> <p>30-DAY</p> </td> <td> <p>IT Ops</p> </td> <td> <p><strong>Review ICS/SCADA patching posture</strong> for Hitachi Energy (REB500, RTU500, SOI, Asset Suite) and Johnson Controls (EasyIO FG) products deployed in state facilities. Six CISA ICS advisories published Oct 6.</p> </td> </tr> <tr> <td> <p>30-DAY</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Conduct state-wide PeopleSoft inventory and patch compliance audit.</strong> The FBI/ShinyHunters incident reveals that even sophisticated organizations fail to patch ERP systems promptly. State agencies with less mature patch management are at higher risk.</p> </td> </tr> <tr> <td> <p>30-DAY</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Procure secondary OSINT intelligence source</strong> (e.g., Recorded Future, GreyNoise) to eliminate single-vendor dependency in threat intelligence collection. Current single-source dependency degrades corroboration capability and represents an unacceptable intelligence gap.</p> </td> </tr> </tbody> </table> <h3><strong>Executive and IR Preparedness</strong></h3> <table border="0" rules="all"> <thead> <tr> <td> <p><strong>Priority</strong></p> </td> <td> <p><strong>Team</strong></p> </td> <td> <p><strong>Action</strong></p> </td> </tr> </thead> <tbody> <tr> <td> <p>IMMEDIATE</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Confirm PeopleSoft patch status</strong> across all state agencies and report to CIO. This is a confirmed, active exploitation path against government targets.</p> </td> </tr> <tr> <td> <p>IMMEDIATE</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Authorize emergency Veeam patching window.</strong> The 48&ndash;72 hour weaponization timeline means standard change management processes may be too slow.</p> </td> </tr> <tr> <td> <p>7-DAY</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Direct judiciary IT</strong> to conduct phishing resilience assessment and backup server segmentation review, informed by the Arizona court breach.</p> </td> </tr> <tr> <td> <p>7-DAY</p> </td> <td> <p>IR Team</p> </td> <td> <p><strong>Update incident response playbooks</strong> to include Veeam compromise as a ransomware precursor scenario. Verify that backup recovery procedures work when the Veeam server itself is compromised.</p> </td> </tr> <tr> <td> <p>30-DAY</p> </td> <td> <p>CISO</p> </td> <td> <p><strong>Tabletop exercise:</strong> Simulate a scenario where ransomware operators exploit Veeam CVE-2025-64393 to destroy backups before deploying ransomware across state agency infrastructure. Test recovery from immutable/air-gapped copies.</p> </td> </tr> </tbody> </table> <h2><strong>The Convergence Pattern</strong></h2> <p>The most important strategic takeaway from this week's intelligence is not any single vulnerability or breach &mdash; it is the <strong>convergence of multiple threat vectors targeting the same infrastructure simultaneously.</strong></p> <p>Consider the attack chain a sophisticated adversary could construct today:</p> <p>55. <strong>Initial access</strong> via BlueKit-generated phishing targeting Citrix SSO credentials (T1566.001)</p> <p>56. <strong>Credential harvesting</strong> through AI-generated, contextually perfect phishing pages (T1539)</p> <p>57. <strong>Lateral movement</strong> to PeopleSoft via harvested credentials on an unpatched instance (T1190, T1078)</p> <p>58. <strong>Backup destruction</strong> via Veeam CVE-2025-64393 &mdash; Backup Viewer to SYSTEM (T1490)</p> <p>59. <strong>Ransomware deployment</strong> with no recovery option available</p> <p>Each link in this chain has a corresponding confirmed threat or active vulnerability documented in this report. The defense must be equally comprehensive.</p> <h2><strong>Bottom Line</strong></h2> <p><strong>Three facts define this threat cycle:</strong></p> <p>60. <strong>A peer organization lost 1.3 million records to a single phishing click.</strong> The Arizona court breach is not a cautionary tale about exotic tradecraft &mdash; it is a reminder that the most basic social engineering technique remains devastatingly effective against government infrastructure.</p> <p>61. <strong>The FBI terminated a major contractor over an unpatched ERP system.</strong> The June 2026 Oracle patch that would have prevented the ShinyHunters breach has been available for months. If your PeopleSoft patch status is unknown, it must be verified today.</p> <p>62. <strong>A CVSS 9.4 backup RCE was disclosed 24 hours ago, and ransomware operators are already working to weaponize it.</strong> Veeam CVE-2025-64393 is not a future risk &mdash; it is an active countdown. The 48&ndash;72 hour weaponization window closes before most standard change management cycles complete.</p> <p>The adversaries in this report are not waiting for your next maintenance window. The minimum acceptable response is: verify PeopleSoft patches, deploy the Veeam fix, push Chrome updates, and confirm Citrix and FortiMail remediation &mdash; today.</p> <h2><strong>Closing</strong></h2> <p>The events of this week leave no room for complacency. A peer state judiciary lost 1.3 million records to a single phishing click. The FBI terminated a major contractor over an unpatched ERP system. A CVSS 9.4 vulnerability in the backup software that protects your ability to recover from ransomware was disclosed 24 hours ago, and the clock is running.</p> <p>State government IT leaders face a narrow window of action. The PeopleSoft patch has been available since June &mdash; verify it today. The Veeam patch was released yesterday &mdash; deploy it now. Chrome updates are available &mdash; push them across your enterprise. These are not aspirational recommendations. They are the minimum actions required to maintain an acceptable security posture given the current threat environment.</p> <p>The adversaries documented in this report &mdash; from ShinyHunters exploiting government ERP systems to UAC-0277 weaponizing 100+ legitimate websites to BlueKit's 1,000+ customers generating AI-powered phishing campaigns &mdash; are not waiting for your next change management window.</p> <p>Neither should you.</p> <p><em>Anomali CTI Desk &mdash; 2026-10-07</em></p> <p><em>For questions or additional IOC feeds, contact your Anomali representative or access indicators directly via ThreatStream Next-Gen.</em></p>

FEATURED RESOURCES

October 7, 2026
Anomali Cyber Watch
Public Sector

When One Phishing Click Costs 1.3 Million Records: The Converging Threats State Governments Cannot Ignore

Read More
October 6, 2026
Anomali Cyber Watch

Anomali Cyber Watch: NeedyMantis, Warlock, Cloud Risks and more

Stay ahead of evolving cyber threats. Explore the latest on NeedyMantis malware, Warlock ransomware SharePoint exploitation, and corporate AI infostealers.
Read More
October 7, 2026
Operationalized Threat Intelligence

Sovereign AI: The Strategic Debt Nations Are Accumulating by Doing Nothing

Read More
Explore All