TLP:GREEN  ·  States / Public Sector
Fortinet Under Active Exploitation · OT Zero-Days Go Public · ClickFix Bypasses Email Security:

What State CISOs Must Act On Today

ELEVATED. Three converging threats demand action from state IT leadership today. CISA added a third critical FortiSandbox flaw to its KEV catalog — CVE-2026-25089 (CVSS 9.8), an unauthenticated RCE confirmed exploited in the wild in a security appliance many agencies rely on for malware analysis. A full exploitation chain for Siemens ROX II OT switches is now public, handing adversaries a blueprint for persistent root on water and energy backbone devices. And ClickFix credential theft is rendering email security irrelevant by making the user the execution engine — now feeding directly into ransomware. Meanwhile a presidential accusation of Chinese election-data theft signals new federal compliance mandates may arrive within weeks.

I am a
My sector

DevelopmentDateWhy It Matters for State Government
CVE-2026-25089 added to CISA KEV2026-07-16Third FortiSandbox critical RCE this quarter — unauthenticated, network-exploitable, confirmed in the wild. Agencies running FortiSandbox are exposed now.
Siemens ROX II zero-day chain published (CVE-2025-40947/40948/40949)2026-07-16Full details for chaining file disclosure → command injection → persistent root cron on OT switches. Any state-overseen utility running these devices faces elevated risk.
ACR Stealer ClickFix campaigns escalatingApr–Jul 2026Steals M365 tokens, browser credentials and synced OneDrive/SharePoint files via steganographic JPEG payloads. Bypasses email gateways entirely — the user is the execution engine.
5 Rockwell Automation ICS advisories in one day2026-07-16CompactLogix, ControlLogix, GuardLogix, Flex 5000, FactoryTalk DataMosaix — DoS and code execution across the PLC families common in state water/wastewater SCADA.
China election-data breach allegation2026-07-17Presidential-level attribution. Expect CISA emergency directives or BODs targeting state election infrastructure within 7–14 days.
Fresh APT28 malware samples identified2026-07-15/16GRU Unit 26165 actively targeting government entities with updated tooling — Russian military-intelligence operations against government networks are ongoing.
Ransomware landscape: 8 groups updatedPast 14 daysAkira, Deadlock, Krybit, Interlock, INC Ransom, Qilin, LockBit5 and BrainCipher all updated with active government targeting; Krybit added government entities on Jul 17.
NadMesh botnet targeting AI infrastructureEarly Jul 2026First "product-grade" autonomous botnet scanning for Ollama, ComfyUI, Docker and Kubernetes — relevant to any agency running AI pilots on exposed infrastructure.

DateEventActor / CVEImpact
2026-07-13US/UK/EU sanction 24+ Russian cyber entities; FSB Center 16 attributed to DynoWiper attacks on Poland's power gridFSB Center 16 / DynoWiperConfirms state-level destructive capability against power infrastructure
2026-07-14/16CISA adds 6 vulnerabilities to KEV in 48 hours, including Oracle EBS and SonicWall SMA1000CVE-2026-46817, CVE-2026-15409Unprecedented patch velocity required for agencies running these products
2026-07-15/16Fresh APT28 malware samples identified targeting government entitiesAPT28 (GRU Unit 26165)Active Russian military-intelligence operations against government networks
2026-07-16CVE-2026-25089 (FortiSandbox, CVSS 9.8) added to CISA KEVCVE-2026-25089Third FortiSandbox critical in one quarter — exploitation confirmed
2026-07-1610 ICS advisories published (Rockwell, Siemens, AutomationDirect, SALTO, NASA cFS)N/A (vendor disclosure)Largest single-day OT advisory volume this quarter
2026-07-16Siemens ROX II chained zero-day exploitation details published by Unit 42CVE-2025-40947/40948/40949Full attack chain now public — weaponization timeline compressed
2026-07-17President accuses China of massive U.S. election-data breachChina-nexus (alleged)Political signal — expect compliance mandates for state election systems
2026-06Confirmed destructive breach of a California water utilityVOID MANTICORE (Iran/IRGC)Iran-nexus actors actively targeting U.S. state water infrastructure

CVE-2026-25089 is an unauthenticated OS command-injection vulnerability affecting FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8 and all 4.2.x releases, including Cloud/PaaS variants. It requires no credentials, is exploitable over the network with low complexity, and is now confirmed exploited in the wild.

This is the third critical FortiSandbox CVE added to CISA's KEV catalog this quarter, joining CVE-2026-39808 (CVSS 9.8, with public PoC on GitHub) and CVE-2026-25836 (CVSS 7.2) — a confirmed exploitation chain against a product designed to protect organizations from malware.

The irony is not lost: your malware-analysis sandbox may be the initial access vector into your network.

T1190T1059.004

ACR Stealer campaigns from late April through mid-July 2026 use a social-engineering technique called "ClickFix". Instead of a malicious attachment or link the email gateway can scan, attackers instruct users to paste a command into the Windows Run dialog (Win+R). The user becomes the execution engine.

Two delivery chains are documented — disk-based (WebDAV + DLL sideloading) and fileless (mshta.exe → steganographic JPEG → reflective .NET execution in memory). Once executed, ACR Stealer harvests browser passwords and cookies, Microsoft 365 authentication tokens, synced OneDrive/SharePoint documents and credential-manager contents.

The campaign has used fake "Claude Code" installer pages (hosted at claude-desktop[.]gitlab[.]io) as lures; expect state-government lure themes to rotate toward tax compliance, benefits portals or IT-helpdesk impersonation.

Critical insight: this technique is now used as a hand-off to ransomware operators — ClickFix provides initial access and credential theft, which is then transferred to ransomware affiliates for deployment.

T1204.002T1218.005T1027.003T1555T1539T1114.002

On July 16, CISA published 10 ICS advisories covering products directly relevant to state-overseen critical infrastructure:

VendorProductImpactState Gov Relevance
Rockwell AutomationCompactLogix / ControlLogix / GuardLogixDenial of ServiceWater/wastewater SCADA PLCs
Rockwell Automation1756-EN2/EN3/ENBT Ethernet modulesDenial of ServicePLC communication modules
Rockwell AutomationFlex 5000 AdapterDenial of ServiceI/O expansion in SCADA
Rockwell AutomationFactoryTalk DataMosaixXSS / Script InjectionIndustrial data analytics
Rockwell AutomationArenaArbitrary Code ExecutionSimulation / modeling
SiemensROX II OT SwitchesChained root exploitationNetwork backbone for energy/water
SiemensSICAM 8Multiple vulnerabilitiesEnergy distribution monitoring

The Siemens ROX II chain (CVE-2025-40947/40948/40949, combined CVSS up to 9.1) is particularly dangerous because full exploitation details are now public: file disclosure → privilege escalation via command injection in feature-key validation → persistent root via cron. Firmware V2.17.1 patches all three.

Context: in June 2026, VOID MANTICORE (Iran/IRGC) conducted a confirmed destructive breach of a California water utility. Public OT exploitation techniques plus confirmed nation-state targeting of U.S. water infrastructure create material risk for state-overseen utilities.

T1190T0890T1053.003T0831T0816

Russia: fresh APT28 (GRU Unit 26165) malware samples were identified July 15–16 targeting government entities. Coordinated US/UK/EU sanctions on July 13 attributed FSB Center 16 to destructive DynoWiper attacks on Poland's power grid and GRU Unit 29155 to hybrid-warfare operations. MUSTANGPANDA IOCs were refreshed July 17.

China: the presidential accusation of Chinese election-data theft (July 17) is a political signal, not a technical finding — but it carries operational implications: expect increased scanning of state election infrastructure, potential new CISA directives, and budget/compliance pressure. Volt Typhoon and Salt Typhoon remain active, though no new indicators surfaced this cycle.

Iran: VOID MANTICORE's confirmed destructive breach of a California water utility in June 2026 shows Iranian actors are actively targeting U.S. state critical infrastructure — for destruction, not just espionage.

While no confirmed state/local government victim was reported on July 17, the following RaaS operations were updated in the past two weeks with active government targeting: Akira, Deadlock, Krybit, Interlock, INC Ransom, Qilin, LockBit5 and BrainCipher. Krybit specifically updated its targeting profile on July 17 to include government entities.

The ClickFix-to-ransomware hand-off pipeline means credential theft today becomes ransomware deployment tomorrow. The two threats are no longer separate — they are stages in the same kill chain.

ScenarioProbabilityBasis
Published exploitation details for CVE-2026-25089 (FortiSandbox) appear on exploit forumsHIGH (80%)7–14 days. PoC already exists for sister CVE-2026-39808; pattern of rapid weaponization for Fortinet vulns.
ClickFix campaigns rotate to state-government lure themes (tax portals, benefits, IT helpdesk)HIGH (75%)14–30 days. Parallels observed Indian GST phishing pattern; state gov is a high-value target.
CISA issues an emergency directive or BOD for state election-system hardeningMODERATE-HIGH (65%)14–30 days. Presidential-level attribution of China election breach; political pressure.
Ransomware group claims a state/local government victim using ClickFix initial accessMODERATE (55%)30–60 days. Hand-off pipeline documented; 8 groups actively targeting government.
Exploitation of the Siemens ROX II chain against U.S. utility infrastructureMODERATE (50%)30–90 days. Full chain public; VOID MANTICORE precedent for water-utility targeting.
NadMesh or similar botnet compromises state-agency AI pilot infrastructureLOW-MODERATE (35%)60–90 days. Early-stage botnet; depends on agency exposure of Docker/Kubernetes.

1. ClickFix / ACR Stealer Execution Chain:
ATT&CKDetection LogicPriority
T1218.005Alert on mshta.exe spawning PowerShell or making outbound network connectionsCRITICAL
T1204.002Monitor for rundll32.exe loading DLLs from WebDAV paths (UNC paths with .google pattern)CRITICAL
T1027.003Flag processes downloading JPEG/PNG from ImgBB or similar hosting, followed by .NET Assembly.Load callsHIGH
T1053.005Detect new scheduled tasks named to mimic software-update services, created outside SCCM/IntuneHIGH
T1555Alert on credential-store access by non-browser processesHIGH
2. FortiSandbox Exploitation (CVE-2026-25089):
ATT&CKDetection LogicPriority
T1190Monitor FortiSandbox management-interface logs for unexpected command execution or auth-bypass indicatorsCRITICAL
T1059.004Alert on outbound connections from FortiSandbox appliances to non-Fortinet IPs (potential post-exploitation C2)CRITICAL
3. OT/ICS Anomaly Detection:
ATT&CKDetection LogicPriority
T0816Alert on unexpected PLC restarts or communication drops on Rockwell CompactLogix/ControlLogixHIGH
T0831Monitor for unauthorized configuration changes to Siemens ROX II switches or SICAM 8 devicesHIGH
T1053.003Where OT monitoring is available, flag new cron entries on Siemens ROX II devicesHIGH
IOC Blocking Table:
creativecommunityinfo[.]art enhanceblabber[.]cc claude-desktop[.]gitlab[.]io 165.154.41[.]213

creativecommunityinfo[.]art — ACR Stealer payload hosting. enhanceblabber[.]cc — ACR Stealer C2. claude-desktop[.]gitlab[.]io — ClickFix lure page (fake Claude Code installer). 165.154.41[.]213 — associated threat infrastructure. Block at web proxy and DNS; sinkhole at the resolver level. Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1218.005
Is ClickFix active in our environment?
If so, we will see mshta.exe or conhost.exe spawned from explorer.exe (the Run dialog) with command-line arguments containing URLs or encoded PowerShell, followed by credential-store enumeration within 60 seconds.
HUNT 02 · T1190
Has CVE-2026-25089 been exploited against our FortiSandbox?
If so, we will see anomalous outbound connections from the appliance's management IP, unexpected cron jobs or shell processes, or configuration changes not correlated with admin activity.
HUNT 03 · T1053.003
Have Siemens ROX II switches in our utility networks been compromised?
If so, we will see new cron entries, unexpected SSH-key additions, or file-system changes in the feature-key validation directory.
Investigation Triggers:
  • Any mshta.exe execution with network activity → escalate immediately
  • FortiSandbox appliance making outbound connections to unknown IPs → isolate and investigate
  • Scheduled-task creation outside change windows → correlate with ClickFix indicators
  • M365 impossible-travel alerts coinciding with new device registrations → potential token theft from ACR Stealer

Financial Services
State Treasury, Revenue, Benefits Systems
Primary threat
ACR Stealer targeting M365 tokens and synced financial documents; ClickFix lures themed around tax compliance, payment processing or audit notifications
Actions
  • Enable Conditional Access requiring compliant devices for Treasury SharePoint sites; implement token binding where supported
  • Watch for ClickFix lures themed around tax compliance, payment processing or audit notifications
  • Monitor for unusual bulk access to tax/revenue databases and credential stuffing against citizen-facing portals
Energy
State-Overseen Utilities, Grid Operators
Primary threat
Siemens ROX II zero-day chain (CVE-2025-40947/40948/40949) + SICAM 8 vulnerabilities; VOID MANTICORE (Iran/IRGC) has shown willingness to conduct destructive attacks on U.S. water/energy infrastructure
Actions
  • Inventory all Siemens ROX II switches and SICAM 8 devices; verify firmware V2.17.1 deployment
  • Ensure OT network segmentation prevents lateral movement from a compromised switch
  • Watch for unauthorized SSH to OT switches, new cron entries, and file-system modifications in feature-key directories
Healthcare
State Health Agencies, Medicaid Systems
Primary threat
Ransomware (Krybit, Akira, INC Ransom) targeting government health data; credential theft enabling lateral movement to patient records
Actions
  • Verify offline backup integrity for Medicaid enrollment and claims systems; ensure MFA on all EHR/claims portals
  • Segment health-data networks from general state IT
  • Watch for ClickFix lures themed around benefits enrollment, HIPAA compliance or health-portal access
Government
Executive Branch Agencies, Elections
Primary threat
China-nexus espionage targeting election data; APT28 targeting government entities; ClickFix credential theft of M365 accounts
Actions
  • Audit election-system network segmentation; verify no shared credentials with general state IT
  • Prepare for a potential CISA emergency directive on election hardening
  • Watch for unusual queries against voter-registration databases, new Entra ID device enrollments from unexpected geolocations, and living-off-the-land activity
Aviation / Logistics
State DOT, Transit Authorities
Primary threat
Rockwell Automation PLC vulnerabilities (DoS) affecting traffic-management and transit SCADA; supply-chain compromise through MSP access
Actions
  • Audit Rockwell CompactLogix/ControlLogix firmware in traffic-management systems
  • Verify MSP access is scoped and monitored; ensure safety systems have independent fail-safes
  • Watch for unexpected PLC restarts or communication drops and MSP credential usage outside normal hours
No sector cards match the selected filters.

Patch FortiSandbox to version 5.0.6+ across all agency deployments. CVE-2026-25089 (CVSS 9.8) is unauthenticated, confirmed exploited and on CISA KEV — no workaround exists, patching is the only remediation.
Incident Responder
Block ACR Stealer infrastructure at web proxy and DNS: creativecommunityinfo[.]art, enhanceblabber[.]cc, claude-desktop[.]gitlab[.]io. Sinkhole at the resolver level.
SOC Analyst
Deploy ClickFix detection rules: alert on mshta.exe spawning PowerShell with network connections; rundll32.exe loading DLLs from WebDAV paths; conhost.exe spawned from explorer.exe with encoded arguments.
SOC Analyst
Verify SonicWall SMA1000 patch status — CVE-2026-15409 (CVSS 10.0) was added to KEV on July 14 with active exploitation confirmed.
Incident Responder
No immediate actions for the selected roles.
Upgrade Siemens ROX II firmware to V2.17.1 on all OT switches in state-overseen utility networks. The full exploitation chain is now public — the weaponization timeline is compressed.
ICS / OTIncident Responder
Implement GPO to disable the Win+R Run dialog for standard users and block mshta.exe via WDAC or AppLocker — this eliminates the ClickFix vector at the endpoint.
SOC Analyst
Audit Rockwell CompactLogix/ControlLogix/GuardLogix firmware in water/wastewater SCADA environments and apply patches per ICSA-26-197-06.
ICS / OT
Enable token protection / Continuous Access Evaluation in Entra ID for all M365 E5 tenants to limit the value of stolen ACR Stealer session tokens.
IAM Analyst
Hunt for FortiSandbox compromise indicators: review management-interface logs for anomalous command execution; check for unexpected outbound connections from appliance IPs; verify no unauthorized cron jobs or SSH keys.
Threat Hunter
No 7-day actions for the selected roles.
Commission an inventory of AI/ML pilot deployments (Docker, Kubernetes, Ollama, ComfyUI, Open WebUI) across all agencies; assess exposure to NadMesh-class autonomous exploitation and ensure no AI infrastructure is internet-exposed without authentication.
CISO / Exec
Brief the election-security team on the China election-data breach allegations; prepare a response plan for a potential CISA BOD or state-level directive, and pre-identify budget and resource requirements.
CISO / Exec
Conduct a tabletop exercise simulating the ClickFix-to-ransomware kill chain: credential theft via paste-and-run → M365 token exfiltration → lateral movement → ransomware deployment. Test detection, containment and recovery.
Incident ResponderCISO / Exec
Complete an OT asset inventory for all state-overseen critical infrastructure. Without knowing which PLCs, switches and controllers are deployed where, ICS advisories remain informational — this is the binding constraint on OT security posture.
ICS / OTCISO / Exec
Evaluate OSINT feed diversification. Current collection has a single-vendor dependency; adding AlienVault OTX, MISP community feeds or sector-specific ISACs improves coverage and reduces blind spots.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The threat environment facing state government has shifted. Security appliances are being targeted as entry points, users are being tricked into becoming the malware execution engine, and OT infrastructure now has public exploitation blueprints available to any adversary. ClickFix represents a category change in social engineering — no attachment, no link, nothing your email gateway, sandbox or URL-reputation service can intercept — so the control point must shift from the network to the endpoint. Russian military intelligence, Chinese espionage, Iranian destructive operators and financially motivated ransomware groups are all active, all updated and all targeting government. The question is not whether agencies will be targeted, but whether they detect and respond before impact.

1
Patch FortiSandbox today — CVSS 9.8, unauthenticated, confirmed exploited, no workaround.
2
Shift ClickFix defense to the endpoint: block mshta.exe and WebDAV rundll32, disable the Run dialog, and train staff to treat paste-and-run as the new phishing.
3
Build the OT asset inventory — without it, yesterday's 10 ICS advisories can't be acted on. It's the most urgent 30-day deliverable.
No items found.