| Development | Why It Matters for State Government |
|---|---|
| CVE-2026-7273 added to CISA... | Chinese-nexus actor mass-exploiting Zyxel GS1900... |
| CVE-2026-32996 public... | Trivial local privilege escalation to SYSTEM on... |
| LockBit 5.0 breach claims resume... | First fresh LockBit signal in several cycles... |
| TASK#STOMP backdoor campaign... | Sophisticated, unattributed Windows backdoor... |
| CVE-2026-90817 — REDCap... | Any state health department or university partner... |
| WordPress Click2Shell... | Same Chinese-nexus actor exploiting Zyxel... |
| 7 ICS advisories published by... | Schneider Electric Modicon M340, Hitachi Energy... |
| DPRK TraderTraitor (Lazarus... | Weaponized Terraform files delivering FLATROOF... |
| Software supply chain threats... | Malware embedded in runtime application code... |
| BigDiskBuster Defender bypass... | Proof-of-concept silently blocks Windows Defender... |
| Date | Event | Severity |
|---|---|---|
| August 2026 | Chinese-nexus actor begins mass exploitation of... | 🔴 Critical |
| 14 Sep 2026 | Public proof-of-concept released for... | 🟠 High |
| 17 Sep 2026 | CISA publishes 7 ICS advisories affecting... | 🟡 Moderate |
| 18 Sep 2026 | CISA adds three Linux kernel CVEs to KEV catalog... | 🟠 High |
| 21 Sep 2026 | CISA adds CVE-2026-7273 (Zyxel GS1900) to KEV... | 🔴 Critical |
| 21 Sep 2026 | LockBit 5.0 claims breach of Siinqee Bank; 11... | 🟠 High |
| 21 Sep 2026 | BigDiskBuster proof-of-concept documented —... | 🟠 High |
| 22 Sep 2026 | Securonix publishes TASK#STOMP analysis —... | 🟡 Moderate |
| 22 Sep 2026 | Detailed technical analyses of CVE-2026-32996... | 🟠 High |
| 22 Sep 2026 | WordPress patches Click2Shell vulnerability... | 🟡 Moderate |
A Chinese-speaking actor exploited a stack-based buffer overflow in Zyxel GS1900-48HPv2 switches (firmware under 2.90) to compromise ~996 devices across 48 countries. The US is among the top five affected nations, with confirmed exfiltration of government records. No authentication required - a crafted HTTP request to the management interface...
A low-privileged local user reads an elevated session GUID from a plaintext log file, then replays it over a named pipe to execute commands as NT AUTHORITY\SYSTEM - no special tools required, and the PoC is public. Most state agencies contract MSPs for backup management, and those MSPs almost certainly deploy Veeam Agent - a compromised...
LockBit 5.0 resurfaced with 11 claimed breaches across financial, government, energy, entertainment, retail, and technology sectors - government remains an explicitly named target industry across 115 countries.
TASK#STOMP is a purpose-built document-theft backdoor targeting Word, PDF, Excel, and...
CVE-2026-90817 (CVSS 9.8): unauthenticated RCE in REDCap, widely used by state health departments and universities for research data collection. No patch is currently available - any entity running an affected version with public survey access faces critical risk.
BigDiskBuster: a public PoC silently...
DPRK's TraderTraitor group weaponizes Terraform lock files in fake job-interview GitHub repos, delivering FLATROOF and ROOFDECK macOS backdoors - a supply chain threat to state IT developer staff. The npm indexed-btree campaign embeds malware in runtime code rather than install-time scripts, defeating traditional scanning. Volt Typhoon and Salt...
| Scenario | Probability | Basis |
|---|---|---|
| CVE-2026-7273 (Zyxel) exploitation expands to... | HIGH (>70%) | Active campaign, trivial exploit, 996 devices... |
| CVE-2026-32996 (Veeam) sees in-the-wild... | MODERATE-HIGH (50-65%) | Public PoC, trivial exploitation, ransomware... |
| LockBit 5.0 claims a US state or local government... | MODERATE (40-60%) | Resumed operational tempo, government as named... |
| TASK#STOMP or similar document-theft backdoor is... | MODERATE (35-50%) | Sophisticated evasion techniques make detection... |
| CVE-2026-90817 (REDCap) is exploited against a US... | MODERATE (40-55%) | CVSS 9.8, unauthenticated, no patch available... |
| Additional Chinese-nexus exploitation of network... | MODERATE (40-55%) | Three active network device exploitation... |
Hunt Hypothesis: Compromised...
Hunt Hypothesis: An attacker...
Block immediately at DNS/proxy:...
Hunt Hypothesis: Ransomware...
Continuing from prior cycle: The...
| Threat | ATT&CK |
|---|---|
| Priority 1 — Zyxel GS1900 Exploitation... | T1190 T1059... |
| Priority 2 — Veeam Agent Exploitation Indicators... | T1134 T1059... |
| Priority 3 — TASK#STOMP Indicators | T1059.001 T1059.005... |
| Priority 4 — LockBit 5.0 / Ransomware Precursors | T1003 T1021... |
Block the above at perimeter firewalls, proxies...
- Verify backup infrastructure is patched against CVE-2026-32996; validate offline backup restoration
- Cross-reference ICS advisories against OT inventory; verify OT network switches are patched
- Determine REDCap version in use; restrict public survey access immediately if vulnerable
- Emergency audit Zyxel switches across all agency locations; coordinate MSP Veeam patching confirmation
- Review ICS advisories against transportation OT inventories; verify segmentation from general agency networks
The threats documented in this report are not speculative. A Chinese-nexus actor is actively stealing government records through network switches that may be deployed in your branch offices right now. A public exploit for your backup infrastructure is circulating. LockBit 5.0 is back and listing government as a target. A CVSS 9.8 vulnerability in a platform used by state health departments has no patch. The two decisions that cannot wait: authorize emergency Zyxel patching or isolation across...