| Date | Development | Impact |
|---|---|---|
| Pre-July 14 → Present | INC Ransomware (UTA0533) actively exploiting SonicWall SMA1000 (CVE-2026-15409/15410) against U.S. government targets | Ransomware-aligned actors maintaining persistent access via VPN appliance exploitation |
| July 25, 2026 | DHS discloses Salt Typhoon and Volt Typhoon persistent access in state agency and National Guard networks | Confirmed nation-state pre-positioning; no remediation reported |
| July 30, 2026 | CISA issues renewed water/wastewater PLC targeting alert; Schneider Electric IGSS SCADA advisory published | Expanded critical infrastructure threat surface |
| August 1, 2026 | CVE-2026-18577 exploitation confirmed in the wild against MSP environments | RMM supply chain compromise active |
| August 2, 2026 | APT29 "CaptiveCrunch" campaign stealing M365 credentials via compromised hotel Wi-Fi; Kali365 device-code OAuth token theft campaign active against government M365 users | Russian intelligence credential harvesting and OAuth token theft both active |
| August 3, 2026 | CISA adds CVE-2026-18577 to KEV catalog; 55%+ of N-central cloud servers remain unpatched; Silent Ransom Group (Luna Moth) confirmed actively targeting organizations with limited security maturity | Federal patch mandate issued; majority of servers still exposed; encryption-free extortion threat active |
| August 4, 2026 | ChainDrop npm worm actively spreading — 56+ packages compromised within a single hour | Software supply chain under active attack |
| Timeframe | Actor / Campaign | Target | Status |
|---|---|---|---|
| Pre-July 14 → Present | INC Ransomware (UTA0533) | U.S. government via SonicWall SMA1000 (CVE-2026-15409/15410) | Active exploitation |
| July 25 → Present | Salt Typhoon / Volt Typhoon (Chinese MSS) | State agency & National Guard networks | Persistent pre-positioning confirmed |
| August 1 → Present | Unknown actors (ransomware-aligned) | State/local gov via N-able N-central MSPs | Active exploitation, 9+ orgs compromised |
| August 2 → Present | APT29 / Midnight Blizzard (Russian SVR) | Government travelers via hotel Wi-Fi | Active credential harvesting |
| August 3 → Present | BANISHED KITTEN (IRGC-affiliated) | Water/wastewater PLCs across 7+ U.S. states | Active, confirmed physical consequences |
| August 4 → Present | ChainDrop (unattributed) | npm ecosystem / CI/CD pipelines | Active worm propagation |
| Active | Silent Ransom Group (Luna Moth) | Orgs with limited security maturity | Callback phishing → data extortion |
| Active | Kali365 (unattributed) | Government M365 users via device-code phishing | OAuth token theft |
CVE-2026-18577 is an incomplete patch for an earlier vulnerability (CVE-2026-18556) in N-able N-central, a remote monitoring and management platform widely used by MSPs that serve state and local government. Attackers are exploiting this flaw to bypass authentication entirely, gain administrative console access, and then pivot to every endpoint managed by that N-central instance using the built-in "Take Control" remote access feature.
Why it matters for state government: If your agency — or any MSP partner serving your agency — runs N-central, a single compromised console grants attackers administrative remote access to potentially thousands of state endpoints. Huntress has confirmed compromises across at least 9 organizations under a single partner account. Attackers are deploying Cloudflare tunnels for persistent backdoor access and dropping malicious executables disguised as system processes.
Scale of exposure: Over 55% of N-central cloud servers remained unpatched days after the hotfix was released. The CISA KEV deadline for federal agencies is August 6, 2026.
A self-propagating worm is spreading through the npm package ecosystem by stealing maintainer authentication tokens and publishing compromised versions of legitimate packages. Dozens of packages were poisoned within a single hour, including widely-used caching libraries (cache-manager, cacheable, flat-cache, file-entry-cache) and packages under organizational scopes. The worm uses obfuscated preinstall scripts to download a Bun runtime and harvest CI/CD credentials, with command-and-control communications routed through Ethereum blockchain dead-drop infrastructure.
Why it matters for state government: Any state agency building citizen-facing web applications, portals, or internal tools on Node.js/npm stacks may have transitive dependencies on compromised packages. A single poisoned dependency deep in the dependency tree can expose CI/CD pipeline credentials, enabling further supply chain attacks against your production systems.
CISA issued a renewed alert on July 30 documenting a "significant increase" in threat actors targeting programmable logic controllers (PLCs) in water and wastewater systems. This follows confirmed attacks attributed to Iran-linked actors (assessed BANISHED KITTEN alignment) that expanded from Minnesota to 7+ U.S. states by August 3, with confirmed physical consequences including manipulation of water treatment parameters.
Why it matters for state government: State agencies with oversight responsibility for municipal water systems, or those operating their own water/wastewater treatment facilities, face direct risk. Additionally, a new Schneider Electric IGSS SCADA vulnerability (advisory ICSA-26-211-04) affects systems commonly deployed in water treatment and building management — both relevant to state operations.
Silent Ransom Group (also known as Luna Moth), a Conti ransomware successor, has refined a data extortion model that deliberately avoids deploying ransomware. They use callback phishing — sending emails with fake IT support numbers — to trick employees into installing legitimate remote access tools (AnyDesk, Zoho Assist, Atera). Once inside, they exfiltrate sensitive data via WinSCP or Rclone and demand payment to prevent publication. They operate a botnet across 18 countries with Fast Flux DNS for resilience.
Why it matters for state government: SRG explicitly targets organizations with "limited cybersecurity maturity and regulatory pressure" — a description that matches many state agencies operating under tight budgets with significant compliance obligations. Because they never deploy ransomware, traditional ransomware detection (file encryption behavior, ransom notes) will not trigger. The first indication of compromise may be the extortion demand itself.
Chinese MSS-affiliated groups Salt Typhoon and Volt Typhoon maintain confirmed persistent access in state agency and National Guard networks per the July 25 DHS disclosure. No remediation has been publicly reported. APT29 (Russian SVR) launched the "CaptiveCrunch" campaign on August 2, stealing Microsoft 365 credentials from government travelers via compromised hotel Wi-Fi captive portals. The Kali365 campaign continues exploiting Microsoft's device-code authentication flow to steal OAuth tokens from government employees — a technique that bypasses traditional phishing detection because victims authenticate on Microsoft's legitimate login page.
| Scenario | Probability | Basis |
|---|---|---|
| Additional N-central exploitation with ransomware deployment as follow-on | 75% (HIGH) | 55%+ servers unpatched; confirmed active exploitation; ransomware operators historically monetize RMM access within days |
| ChainDrop worm scope expands; additional compromised packages discovered affecting state dev pipelines | 50% (MODERATE) | Worm is self-propagating; state agencies likely have transitive dependencies on affected packages |
| Silent Ransom Group or similar extortion actor targets a state/local government entity via callback phishing | 40% (MODERATE) | Explicit targeting of orgs with limited maturity + regulatory pressure; state gov matches this profile |
| Volt Typhoon / Salt Typhoon activity surfaces in state network telemetry | 20% (LOW) | Pre-positioning designed to remain silent; detection would require proactive hunting, not passive alerting |
| Iran-linked PLC manipulation expands to additional states or causes service disruption | 35% (MODERATE) | Campaign already expanded from 1 to 7+ states; CISA alert confirms "significant increase" in targeting |
What to look for: Windows service named "Cloudflared" on any endpoint; svchost.exe present in user Documents folders (not System32); anomalous Take Control sessions from the mspsupport@n-able.com account; connections to Synology/QuickConnect dynamic DNS domains Detection logic: Query EDR for process creation events where svchost.exe parent path is NOT C:\Windows\System32\; alert on new Windows service installations matching "Cloudflared"; monitor DNS for .synology.me and .quickconnect.to resolutions Log sources: N-central BASupSrvc logs (C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz), Windows System event log (service installations), firewall/proxy logs
What to look for: Unexpected preinstall script execution in CI/CD pipelines; Bun runtime downloads on build servers; outbound connections from CI/CD runners to Ethereum RPC endpoints; modified lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml) with unexpected version bumps Detection logic: Monitor build systems for unexpected binary downloads (Bun runtime); alert on CI/CD secret access patterns outside normal deployment windows; diff lockfiles against known-good baselines
What to look for: Installation of AnyDesk, Zoho Assist, or Atera on endpoints where these tools are not sanctioned; large outbound file transfers via WinSCP or Rclone; employees reporting calls from "IT support" they didn't initiate Detection logic: Application allowlisting alerts for unauthorized RAT installations; NetFlow analysis for large (>500MB) outbound transfers to cloud storage or unfamiliar endpoints; DNS analytics for Fast Flux patterns (high TTL variance, many IPs per domain)
What to look for: Azure AD sign-in logs showing device-code authentication from unexpected locations or for user accounts (not service accounts/kiosks); OAuth token grants without corresponding interactive sign-in; Conditional Access policy gaps for device-code flow Detection logic: Azure AD sign-in logs filtered for authenticationProtocol = deviceCode where user is not in approved device-code user group; alert on device-code authentications from non-corporate IP ranges
| Threat | ATT&CK |
|---|---|
| Hypothesis 1: N-central compromise via CVE-2026-18577 | T1078 T1021 T1090 T1133 T1569 |
| Hypothesis 2: ChainDrop npm supply chain compromise | T1195.002 T1059.007 T1552.001 T1102.001 |
| Hypothesis 3: Silent Ransom Group callback phishing | T1566.003 T1219 T1567 T1048 T1568.001 |
| Hypothesis 4: Kali365 device-code token theft | T1528 T1078.004 |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
- Implement application allowlisting on systems processing financial data to prevent unauthorized RAT installation (AnyDesk, Zoho Assist, Atera)
- Monitor for bulk data access patterns on tax/benefits databases that deviate from normal business hours or volume
- Restrict device-code authentication flow via Conditional Access
- Inventory all Schneider IGSS installations across state facilities
- Apply vendor patches per advisory
- Validate network segmentation between IT and OT/BMS networks — no direct internet exposure for any SCADA/BMS system
- Immediately confirm with all MSP partners whether they use N-central and verify patch status
- If unpatched, demand emergency remediation or disconnect managed endpoints from the platform
- Review BAA obligations — an MSP compromise may trigger HIPAA breach notification requirements
- Conduct emergency inventory of all RMM tools in use across agencies — not just N-central but any remote management platform
- Implement network-level monitoring for Cloudflare tunnel traffic (cloudflared service) which attackers are using for persistent access
- Brief all agency security liaisons on the callback phishing threat
- With election infrastructure preparation underway, validate that no election management systems are accessible via MSP remote management tools
- Audit all Node.js applications supporting transportation operations
- Freeze npm dependency updates until lockfiles are verified clean
- Specifically check for compromised packages: cache-manager@7.2.10, cacheable@2.5.1, flat-cache@6.1.24, file-entry-cache@11.1.6
svchost.exe in user Documents folders, connections to IOC IPs listed above. Review all Take Control remote sessions from the past 14 days.mousears.synology[.]me, wagoosh.direct.quickconnect[.]to, who-ripped-one.direct.quickconnect[.]to) and IPs at DNS, proxy, and firewall layers.cache-manager@7.2.10, cacheable@2.5.1, flat-cache@6.1.24, file-entry-cache@11.1.6). If any are found, rotate ALL CI/CD tokens and secrets immediately.The exploitation of N-able N-central is not a future risk — it is happening now, against state and local government environments, with confirmed victims. The CISA KEV deadline of August 6 is two days away. Every hour an unpatched N-central instance remains exposed is an hour that attackers have administrative remote access to every endpoint it manages. But patching alone is insufficient. If your environment was exposed before the patch, you must assume compromise and hunt. The indicators are specific and actionable. The attacker tradecraft — Cloudflare tunnels, dynamic DNS for C2, abuse of built-in remote access features — is detectable with the right queries. Beyond the immediate crisis, this week's intelligence paints a clear picture: the attack surface for state government is expanding faster than most agencies' defensive capabilities. The organizations that will weather this threat environment are those that hunt proactively, verify their supply chain partners' security posture, and treat every remote management tool as a potential adversary access vector until proven otherwise.