TLP:GREEN  ·  States / Public Sector
Citrix NetScaler Under Active Attack:

State Government Agencies Face 48-Hour Patch Deadline

ELEVATED. Unchanged from 26 August, driven by an actively exploited Citrix NetScaler vulnerability with a 29 August CISA compliance deadline, continued nation-state pre-positioning activity against government networks, and a refreshed ransomware delivery infrastructure targeting public sector endpoints. CISA added six vulnerabilities to its KEV catalog in a single day — an unusually high volume signaling broad exploitation activity across the threat landscape.

I am a
My sector

DateDevelopmentSignificance
24 AugCISA added CVE-2026-21962 (Oracle WebLogic, CVSS 10.0) to KEV72-hour federal patch mandate activated
24 AugSalt Typhoon (UNC5807) threat database updated with refreshed targeting indicatorsNation-state telecommunications and government network threat
25–26 AugChina-nexus campaign (UNC6201/Murky Panda) confirmed deploying RIBTWIST/STONECLAM malware against government targets via USB/DLL sideloadingNation-state espionage targeting government endpoints
25 AugCISA published "A Tale of Two SOCs" red team advisory (AA26-237A)SOC detection gap findings relevant to state operations
26 AugCISA added 6 KEVs including CVE-2026-8452 (Citrix NetScaler, CVSS 8.8)Active exploitation of state VPN/remote access infrastructure
26–27 AugClearFake/FAKEUPDATES C2 infrastructure refreshed with new domainsRansomware delivery pipeline reactivated
27 AugGoTo RAT phishing campaign identified using Vercel-hosted infrastructureLegitimate RMM tool weaponized against organizations
27 AugMicrosoft documents active exploitation of AI platforms (LiteLLM, RAGFlow, Kestra)New attack surface for agencies deploying AI tools
27 AugApache Log4j2 deserialization bypass disclosed (no CVE yet)Potential future risk for legacy Java applications

WeekKey EventsThreat Category
4–10 AugVolt Typhoon (UNC5135) last confirmed infrastructure updateNation-state pre-positioning
11–17 AugMuddyWater (UNC5667) confirmed targeting Siemens S7 PLCs across 7+ U.S. statesICS/SCADA targeting
18 AugCISA Advisory AA26-231A on MuddyWater PLC targetingCritical infrastructure
19–23 AugIRGC-affiliated groups conducting wastewater facility disruption across 12 U.S. statesCritical infrastructure
24 AugSalt Typhoon (UNC5807) threat database updated; Oracle WebLogic KEVNation-state / vulnerability
25–26 AugRIBTWIST/STONECLAM government campaign; FAKEUPDATES targeting 25 countriesEspionage / ransomware delivery
26–27 Aug6 KEVs added (NetScaler lead); AI platform exploitation; ClearFake refreshVulnerability / emerging threats

What it is: a memory buffer overflow in Citrix NetScaler ADC and NetScaler Gateway (CVSS 8.8) that causes denial-of-service when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. This is confirmed actively exploited.

Why it matters for state government: NetScaler is widely deployed across state agencies for remote workforce access, contractor VPN, and application delivery. A successful exploit takes down remote access for entire agencies — during a period when back-to-school and seasonal staffing transitions increase remote access dependency.

Critical context: this is the second actively exploited NetScaler vulnerability in recent months (following CVE-2026-19490). This pattern suggests threat actors are systematically probing Citrix infrastructure, likely including nation-state actors known to favor edge device exploitation (Volt Typhoon, Salt Typhoon).

Patch versions: NetScaler ADC/Gateway 14.1-72.61+, 13.1-63.18+, 14.1-FIPS 14.1-72.61+, 13.1-FIPS 13.1.37.272+.

T1190

Two China-nexus actors with confirmed government targeting missions remain active in threat databases: Volt Typhoon (UNC5135) — last confirmed infrastructure update 12 August 2026 (15 days prior); mission is pre-positioning in critical infrastructure for potential disruption during geopolitical crisis; no new operational reporting since that date, consistent with successful embedding rather than cessation of activity. Salt Typhoon (UNC5807) — threat database updated 24 August 2026; mission is telecommunications and government network access for intelligence collection; continued active targeting posture.

Both actors are known to exploit edge devices (exactly the type of infrastructure now vulnerable via CVE-2026-8452) and employ living-off-the-land techniques that evade standard endpoint detection.

Additionally, two Iranian threat actor groups remain active against U.S. state infrastructure: MuddyWater (UNC5667), MOIS-affiliated, actively targeting Siemens S7 PLCs across 7+ U.S. states; and IRGC-affiliated groups conducting wastewater facility disruption operations across 12 U.S. states since late July 2026.

The ClearFake/FAKEUPDATES (SocGholish) ecosystem — a proven ransomware delivery pipeline operated by UNC1543 — refreshed its command-and-control infrastructure on 26–27 August with new domains. This ecosystem delivers initial access that is subsequently handed off to ransomware operators including BlackSuit (ROYAL SPIDER), Akira (PUNK SPIDER), and Qilin (REVENANT SPIDER) — all of which have active campaigns targeting state and local government.

Separately, fresh malware samples attributed to PINCHY SPIDER (GandCrab/REvil operators) were published on 27 August, along with Sality botnet (SALTY SPIDER) activity — indicating continued commodity threat activity that could serve as initial access for more targeted operations.

T1189T1059.007T1219T1059.005

Microsoft Security documented active exploitation of three AI/ML platforms:

PlatformCVEImpact
LiteLLM (AI gateway)CVE-2026-42271Command injection via MCP endpoints
Starlette (ASGI framework)CVE-2026-48710Host-header validation bypass enabling unauth RCE
Kestra (workflow orchestration)CVE-2026-49869Authentication bypass

Why state agencies should care: these platforms aggregate high-value credentials (OpenAI, Azure, Anthropic API keys). Attackers are harvesting these keys, deploying cryptominers, and establishing persistence via SSH key injection. State agencies increasingly deploy AI tools for citizen services, document processing, and internal automation — often in pilot environments with minimal security oversight.

T1190T1003T1496

A phishing campaign delivers password-protected ZIP archives containing obfuscated VBS scripts that install GoTo RAT — a legitimate LogMeIn remote management tool repurposed by threat actors. The campaign uses Vercel-hosted infrastructure for payload staging and convincing "shared file" lure themes.

This continues an accelerating trend: legitimate remote management tools (GoTo, ConnectWise ScreenConnect, AnyDesk) are the preferred post-exploitation mechanism because they blend with authorized IT management traffic.

T1219T1059.005

ScenarioProbabilityTimeframeBasis
Additional CVE-2026-8452 exploitation reports as actors weaponize the KEV disclosure windowHIGH (>70%)48–72 hoursHistorical pattern: KEV publication accelerates exploitation as actors race to hit unpatched targets
ClearFake drive-by campaign wave targeting state employee endpointsMODERATE (40–60%)7–14 daysInfrastructure refresh + back-to-work/back-to-school period increases browsing exposure
China-nexus actors leverage NetScaler vulnerability for initial accessLOW-MODERATE (25–40%)30 daysVolt Typhoon/Salt Typhoon known preference for edge device exploitation; CVE-2026-8452 fits their playbook
Ransomware incident at a state/local government entity via FAKEUPDATES pipelineMODERATE (40–60%)14–30 daysActive infrastructure + multiple ransomware operators (BlackSuit, Akira, Qilin) with government targeting
AI platform compromise at a state agency with exposed development environmentLOW (15–25%)30–60 daysAttack surface exists but exploitation requires internet-exposed AI platforms — likely limited to shadow IT

PriorityWhat to MonitorATT&CK TechniqueDetection Approach
CRITICALNetScaler exploitation attemptsT1190 (Exploit Public-Facing Application)Monitor NetScaler syslog for crash events, unexpected restarts, and memory corruption indicators. Alert on any Gateway/AAA service interruption.
HIGHClearFake/FAKEUPDATES deliveryT1189 (Drive-by Compromise), T1059.007 (JavaScript)Web proxy logs for connections to appservice-platform[.]net, swiftcurrento[.]net, google-meet-verification[.]icu. Alert on injected JavaScript loading from unfamiliar domains on legitimate sites.
HIGHGoTo RAT / unauthorized RMMT1219 (Remote Access Software), T1059.005 (Visual Basic)EDR alerts for gotoresolve.com connections from endpoints without authorized GoTo licenses. Alert on .vbs execution from user temp directories.
HIGHVolt Typhoon / Salt Typhoon LOTL persistenceT1053 (Scheduled Task), T1136 (Create Account), T1090 (Proxy)Hunt for new local admin accounts on perimeter devices, unusual scheduled tasks, and outbound connections to residential IP ranges from network appliances.
MEDIUMAI platform credential theftT1190, T1003 (Credential Dumping), T1496 (Resource Hijacking)Monitor for connections to 45.150.109[.]151, 135.125.10[.]56, 172.232.38[.]92. Alert on unexpected cryptomining pool connections (c3pool[.]org).
MEDIUMCredential phishing surgeT1566.002 (Spearphishing Link), T1204.001 (Malicious Link)Email gateway alerts for Vercel-hosted URLs in messages. Monitor for bulk credential harvesting page visits.
IOC Blocking Table:
appservice-platform[.]netswiftcurrento[.]netgoogle-meet-verification[.]icutrf.kookapp[.]proflorencevillesharedyou[.]vercel[.]appreliableseeds[.]vercel[.]appzvdns[.]com45.150.109.151.sslip[.]ioauto.c3pool[.]org45.150.109[.]151135.125.10[.]56172.232.38[.]92

Block the above at perimeter firewalls, proxies, and DNS. Hashes: 9fca09e9e7f8cfdaf9ab324932c2f1a9, c2f02ab993f0c4c023cc0cabfd2b1881, c3a136405b36363fe8bab7d581199b09, b0edca2c0d1abb72857beff1eed2bd5aef54f1c122096ff3623d023248d151da, c3aa1d6a6a3260367e2a98ca277a0d41fadf9ad0a51af27205e1ea218ad9d624, e3cc0c919ab412538f21c2fb9ece7691d2d258c9b7b7a979be195f6d1d53a981, bc49db2f5268419e720ce76b374d2e147b9d16540ff9a2a9161f1d4e2c1d2169. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
Hypothesis: Unpatched NetScaler appliances have already been probed or exploited.
Hunt: Review NetScaler access logs for anomalous authentication patterns, unexpected administrative sessions, or core dumps in the last 7 days. - Technique: T1190, T1499.004
HUNT 02 · T1189
Hypothesis: ClearFake JavaScript injection is present on state-hosted or state-visited websites.
Hunt: Proxy logs for state employee browsing sessions that loaded JavaScript from domains registered in the last 30 days with .net or .icu TLDs. - Technique: T1189, T1059.007
HUNT 03 · T1219
Hypothesis: Unauthorized RMM tools are already installed on state endpoints.
Hunt: EDR telemetry for GoTo, AnyDesk, ConnectWise ScreenConnect, or RustDesk binaries not on the approved software list. Cross-reference with IT asset management for authorized installations. - Technique: T1219
HUNT 04 · T1136
Hypothesis: China-nexus actors have established persistence on perimeter appliances.
Hunt: Audit all NetScaler, PAN-OS GlobalProtect, and Cisco ASA/FTD devices for: new admin accounts created in last 60 days, modified startup configurations, unusual cron/scheduled tasks, and outbound connections to residential ISP IP ranges. - Technique: T1136, T1053, T1090

Financial Services
State Treasury, Revenue, Tax Systems
Primary threat
Credential phishing campaigns (5 active this cycle) targeting financial system credentials. ClearFake drive-by compromise on financial news/vendor sites.
Secondary threat
Watch for unusual bulk data exports from tax/revenue databases; lateral movement from compromised endpoints toward financial application servers.
Actions
  • Enforce hardware FIDO2 tokens for all treasury and revenue system administrators
  • Deploy conditional access policies blocking authentication from unmanaged devices
Energy
State-Operated Utilities, Grid Coordination
Primary threats
MuddyWater (UNC5667), MOIS-affiliated, actively targeting Siemens S7 PLCs across 7+ U.S. states. IRGC-affiliated groups disrupting wastewater facilities across 12 states.
Secondary threat
Watch for anomalous Modbus/TCP or S7comm traffic; new connections from engineering workstations to external IPs; changes to PLC ladder logic outside maintenance windows.
Actions
  • Validate network segmentation between IT and OT environments
  • Confirm Siemens SIMATIC firmware is current
  • Ensure all PLC programming workstations are air-gapped or on dedicated VLANs with no internet access
Healthcare
State Health Agencies, Medicaid Systems
Primary threats
Ransomware operators (BlackSuit, Akira, Qilin) targeting healthcare for maximum disruption leverage. GoTo RAT phishing campaigns could provide initial access to health agency networks.
Secondary threat
Watch for mass file encryption indicators (high-volume file rename operations); unauthorized RMM tool installations; connections to known ransomware C2 infrastructure.
Actions
  • Verify offline backup integrity for Medicaid claims processing and electronic health record systems
  • Test ransomware recovery playbooks
  • Block unauthorized RMM tools at the endpoint level
Government
Executive Branch Agencies, Courts, Legislature
Primary threats
China-nexus pre-positioning (Volt Typhoon, Salt Typhoon) via edge device exploitation. RIBTWIST/STONECLAM USB-based espionage campaign targeting government endpoints.
Secondary threat
Watch for USB device insertion events on sensitive systems; new admin accounts on network appliances; DLL sideloading indicators (unsigned DLLs loaded by legitimate executables in unusual paths).
Actions
  • Patch NetScaler immediately (CVE-2026-8452)
  • Disable USB autorun on all government endpoints
  • Implement application allowlisting on high-value systems (executive offices, legal, legislative)
Aviation / Logistics
State DOT, Ports, Transit Authorities
Primary threat
Nation-state pre-positioning in transportation control systems. Supply chain compromise through logistics software vendors.
Secondary threat
Watch for unusual VPN connections to OT segments outside business hours; changes to traffic signal timing or transit dispatch configurations; vendor account activity anomalies.
Actions
  • Audit all vendor remote access connections to transit/traffic management systems
  • Ensure SCADA/traffic management networks are segmented from corporate IT
  • Review vendor security assessments for logistics platform providers
No sector cards match the selected filters.

Patch all Citrix NetScaler ADC and Gateway appliances to versions 14.1-72.61+ or 13.1-63.18+ (CVE-2026-8452). CISA compliance deadline: 29 August. Verify no Gateway/AAA instances remain unpatched.
Incident Responder
Block ClearFake C2 domains at DNS and web proxy: appservice-platform[.]net, swiftcurrento[.]net, google-meet-verification[.]icu. Run a retrospective log search for any prior connections.
SOC Analyst
Block GoTo RAT phishing infrastructure at the email gateway: florencevillesharedyou[.]vercel[.]app, reliableseeds[.]vercel[.]app. Create a detection rule for .vbs files within password-protected ZIP attachments.
SOC Analyst
Block AI attack infrastructure IPs: 45.150.109[.]151, 135.125.10[.]56, 172.232.38[.]92. Block mining pool domain auto.c3pool[.]org.
SOC Analyst
Confirm the incident response retainer is active and the ransomware playbook is current. Verify contact information for the IR provider given elevated ransomware delivery activity.
CISO / Exec
No immediate actions for the selected roles.
Audit all Microsoft SQL Server instances for CVE-2019-1068 (RCE, CVSS 8.8, now in KEV despite 2019 disclosure). Patch or isolate any vulnerable instances.
Incident Responder
Inventory all AI/ML platforms deployed across state agencies (LiteLLM, RAGFlow, Kestra, or equivalents) including development and pilot environments. Verify none are internet-exposed without authentication. Patch LiteLLM to ≥1.83.7.
Incident Responder
Conduct a proactive threat hunt on perimeter appliances (NetScaler, PAN-OS GlobalProtect, Cisco ASA) for living-off-the-land persistence: unusual admin accounts, modified scheduled tasks, outbound connections to residential IP ranges.
Threat Hunter
Audit RMM tool inventory — confirm only authorized remote management tools are installed. Create EDR detection rules for GoTo Resolve, AnyDesk, RustDesk, or other unauthorized RMM binaries.
SOC Analyst
Brief agency heads on the current threat posture, emphasizing the NetScaler deadline, AI platform risks, and the importance of reporting suspicious emails (GoTo RAT lures).
CISO / Exec
No 7-day actions for the selected roles.
Audit Red Hat/Linux systems for CVE-2015-3246 (libuser) and CVE-2022-0995 (kernel OOB write) — both now in KEV. Prioritize internet-facing Linux hosts. CISA deadline: 9 September 2026.
Incident Responder
Evaluate zero-trust network access (ZTNA) migration to reduce dependency on perimeter VPN appliances. Two NetScaler KEVs in recent months demonstrate concentration risk in edge device architecture.
CISO / Exec
Approve alternative OSINT feed procurement — 13 consecutive days of open-source intelligence degradation represents an unacceptable blind spot for legislative monitoring and supply chain threat intelligence.
CISO / Exec
Validate IT/OT network segmentation for all state-operated SCADA systems (water/wastewater, traffic management, building automation). Confirm Siemens SIMATIC firmware is current given active MuddyWater targeting.
ICS / OT
Commission a tabletop exercise simulating a simultaneous ransomware attack on citizen services and edge device compromise by a nation-state actor. Test communication protocols, recovery priorities, and decision authority chains.
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

State government agencies are operating in an environment where your VPN infrastructure is actively under attack — CVE-2026-8452 is not theoretical, it is being exploited now, and the CISA compliance deadline is 48 hours away. Nation-state actors are likely already inside perimeter devices: Volt Typhoon's operational silence since 12 August is consistent with successful pre-positioning, not departure, and Salt Typhoon remains actively updated and postured against telecommunications and government networks. Every unpatched NetScaler, every unaudited Cisco ASA, is a potential foothold. Ransomware operators have refreshed their delivery infrastructure and are specifically targeting state and local government — the ClearFake/FAKEUPDATES pipeline feeds directly into BlackSuit, Akira, and Qilin operations. And AI tools are creating ungoverned attack surfaces that aggregate high-value credentials and may be internet-exposed in development environments your security team doesn't know about. The actions in this brief are not aspirational — they are the minimum required to maintain defensible posture through the end of this week.

1
Patch NetScaler today.
2
Block the IOCs today.
3
Hunt your perimeter devices this week. Everything else follows from whether those three things happen.
No items found.