| Development | Date | Why It Matters for State Government |
|---|---|---|
| CVE-2026-25089 added to CISA KEV | 2026-07-16 | Third FortiSandbox critical RCE this quarter — unauthenticated, network-exploitable, confirmed in the wild. Agencies running FortiSandbox are exposed now. |
| Siemens ROX II zero-day chain published (CVE-2025-40947/40948/40949) | 2026-07-16 | Full details for chaining file disclosure → command injection → persistent root cron on OT switches. Any state-overseen utility running these devices faces elevated risk. |
| ACR Stealer ClickFix campaigns escalating | Apr–Jul 2026 | Steals M365 tokens, browser credentials and synced OneDrive/SharePoint files via steganographic JPEG payloads. Bypasses email gateways entirely — the user is the execution engine. |
| 5 Rockwell Automation ICS advisories in one day | 2026-07-16 | CompactLogix, ControlLogix, GuardLogix, Flex 5000, FactoryTalk DataMosaix — DoS and code execution across the PLC families common in state water/wastewater SCADA. |
| China election-data breach allegation | 2026-07-17 | Presidential-level attribution. Expect CISA emergency directives or BODs targeting state election infrastructure within 7–14 days. |
| Fresh APT28 malware samples identified | 2026-07-15/16 | GRU Unit 26165 actively targeting government entities with updated tooling — Russian military-intelligence operations against government networks are ongoing. |
| Ransomware landscape: 8 groups updated | Past 14 days | Akira, Deadlock, Krybit, Interlock, INC Ransom, Qilin, LockBit5 and BrainCipher all updated with active government targeting; Krybit added government entities on Jul 17. |
| NadMesh botnet targeting AI infrastructure | Early Jul 2026 | First "product-grade" autonomous botnet scanning for Ollama, ComfyUI, Docker and Kubernetes — relevant to any agency running AI pilots on exposed infrastructure. |
| Date | Event | Actor / CVE | Impact |
|---|---|---|---|
| 2026-07-13 | US/UK/EU sanction 24+ Russian cyber entities; FSB Center 16 attributed to DynoWiper attacks on Poland's power grid | FSB Center 16 / DynoWiper | Confirms state-level destructive capability against power infrastructure |
| 2026-07-14/16 | CISA adds 6 vulnerabilities to KEV in 48 hours, including Oracle EBS and SonicWall SMA1000 | CVE-2026-46817, CVE-2026-15409 | Unprecedented patch velocity required for agencies running these products |
| 2026-07-15/16 | Fresh APT28 malware samples identified targeting government entities | APT28 (GRU Unit 26165) | Active Russian military-intelligence operations against government networks |
| 2026-07-16 | CVE-2026-25089 (FortiSandbox, CVSS 9.8) added to CISA KEV | CVE-2026-25089 | Third FortiSandbox critical in one quarter — exploitation confirmed |
| 2026-07-16 | 10 ICS advisories published (Rockwell, Siemens, AutomationDirect, SALTO, NASA cFS) | N/A (vendor disclosure) | Largest single-day OT advisory volume this quarter |
| 2026-07-16 | Siemens ROX II chained zero-day exploitation details published by Unit 42 | CVE-2025-40947/40948/40949 | Full attack chain now public — weaponization timeline compressed |
| 2026-07-17 | President accuses China of massive U.S. election-data breach | China-nexus (alleged) | Political signal — expect compliance mandates for state election systems |
| 2026-06 | Confirmed destructive breach of a California water utility | VOID MANTICORE (Iran/IRGC) | Iran-nexus actors actively targeting U.S. state water infrastructure |
CVE-2026-25089 is an unauthenticated OS command-injection vulnerability affecting FortiSandbox 5.0.0–5.0.5, 4.4.0–4.4.8 and all 4.2.x releases, including Cloud/PaaS variants. It requires no credentials, is exploitable over the network with low complexity, and is now confirmed exploited in the wild.
This is the third critical FortiSandbox CVE added to CISA's KEV catalog this quarter, joining CVE-2026-39808 (CVSS 9.8, with public PoC on GitHub) and CVE-2026-25836 (CVSS 7.2) — a confirmed exploitation chain against a product designed to protect organizations from malware.
The irony is not lost: your malware-analysis sandbox may be the initial access vector into your network.
ACR Stealer campaigns from late April through mid-July 2026 use a social-engineering technique called "ClickFix". Instead of a malicious attachment or link the email gateway can scan, attackers instruct users to paste a command into the Windows Run dialog (Win+R). The user becomes the execution engine.
Two delivery chains are documented — disk-based (WebDAV + DLL sideloading) and fileless (mshta.exe → steganographic JPEG → reflective .NET execution in memory). Once executed, ACR Stealer harvests browser passwords and cookies, Microsoft 365 authentication tokens, synced OneDrive/SharePoint documents and credential-manager contents.
The campaign has used fake "Claude Code" installer pages (hosted at claude-desktop[.]gitlab[.]io) as lures; expect state-government lure themes to rotate toward tax compliance, benefits portals or IT-helpdesk impersonation.
Critical insight: this technique is now used as a hand-off to ransomware operators — ClickFix provides initial access and credential theft, which is then transferred to ransomware affiliates for deployment.
On July 16, CISA published 10 ICS advisories covering products directly relevant to state-overseen critical infrastructure:
| Vendor | Product | Impact | State Gov Relevance |
|---|---|---|---|
| Rockwell Automation | CompactLogix / ControlLogix / GuardLogix | Denial of Service | Water/wastewater SCADA PLCs |
| Rockwell Automation | 1756-EN2/EN3/ENBT Ethernet modules | Denial of Service | PLC communication modules |
| Rockwell Automation | Flex 5000 Adapter | Denial of Service | I/O expansion in SCADA |
| Rockwell Automation | FactoryTalk DataMosaix | XSS / Script Injection | Industrial data analytics |
| Rockwell Automation | Arena | Arbitrary Code Execution | Simulation / modeling |
| Siemens | ROX II OT Switches | Chained root exploitation | Network backbone for energy/water |
| Siemens | SICAM 8 | Multiple vulnerabilities | Energy distribution monitoring |
The Siemens ROX II chain (CVE-2025-40947/40948/40949, combined CVSS up to 9.1) is particularly dangerous because full exploitation details are now public: file disclosure → privilege escalation via command injection in feature-key validation → persistent root via cron. Firmware V2.17.1 patches all three.
Context: in June 2026, VOID MANTICORE (Iran/IRGC) conducted a confirmed destructive breach of a California water utility. Public OT exploitation techniques plus confirmed nation-state targeting of U.S. water infrastructure create material risk for state-overseen utilities.
Russia: fresh APT28 (GRU Unit 26165) malware samples were identified July 15–16 targeting government entities. Coordinated US/UK/EU sanctions on July 13 attributed FSB Center 16 to destructive DynoWiper attacks on Poland's power grid and GRU Unit 29155 to hybrid-warfare operations. MUSTANGPANDA IOCs were refreshed July 17.
China: the presidential accusation of Chinese election-data theft (July 17) is a political signal, not a technical finding — but it carries operational implications: expect increased scanning of state election infrastructure, potential new CISA directives, and budget/compliance pressure. Volt Typhoon and Salt Typhoon remain active, though no new indicators surfaced this cycle.
Iran: VOID MANTICORE's confirmed destructive breach of a California water utility in June 2026 shows Iranian actors are actively targeting U.S. state critical infrastructure — for destruction, not just espionage.
While no confirmed state/local government victim was reported on July 17, the following RaaS operations were updated in the past two weeks with active government targeting: Akira, Deadlock, Krybit, Interlock, INC Ransom, Qilin, LockBit5 and BrainCipher. Krybit specifically updated its targeting profile on July 17 to include government entities.
The ClickFix-to-ransomware hand-off pipeline means credential theft today becomes ransomware deployment tomorrow. The two threats are no longer separate — they are stages in the same kill chain.
| Scenario | Probability | Basis |
|---|---|---|
| Published exploitation details for CVE-2026-25089 (FortiSandbox) appear on exploit forums | HIGH (80%) | 7–14 days. PoC already exists for sister CVE-2026-39808; pattern of rapid weaponization for Fortinet vulns. |
| ClickFix campaigns rotate to state-government lure themes (tax portals, benefits, IT helpdesk) | HIGH (75%) | 14–30 days. Parallels observed Indian GST phishing pattern; state gov is a high-value target. |
| CISA issues an emergency directive or BOD for state election-system hardening | MODERATE-HIGH (65%) | 14–30 days. Presidential-level attribution of China election breach; political pressure. |
| Ransomware group claims a state/local government victim using ClickFix initial access | MODERATE (55%) | 30–60 days. Hand-off pipeline documented; 8 groups actively targeting government. |
| Exploitation of the Siemens ROX II chain against U.S. utility infrastructure | MODERATE (50%) | 30–90 days. Full chain public; VOID MANTICORE precedent for water-utility targeting. |
| NadMesh or similar botnet compromises state-agency AI pilot infrastructure | LOW-MODERATE (35%) | 60–90 days. Early-stage botnet; depends on agency exposure of Docker/Kubernetes. |
| ATT&CK | Detection Logic | Priority |
|---|---|---|
T1218.005 | Alert on mshta.exe spawning PowerShell or making outbound network connections | CRITICAL |
T1204.002 | Monitor for rundll32.exe loading DLLs from WebDAV paths (UNC paths with .google pattern) | CRITICAL |
T1027.003 | Flag processes downloading JPEG/PNG from ImgBB or similar hosting, followed by .NET Assembly.Load calls | HIGH |
T1053.005 | Detect new scheduled tasks named to mimic software-update services, created outside SCCM/Intune | HIGH |
T1555 | Alert on credential-store access by non-browser processes | HIGH |
| ATT&CK | Detection Logic | Priority |
|---|---|---|
T1190 | Monitor FortiSandbox management-interface logs for unexpected command execution or auth-bypass indicators | CRITICAL |
T1059.004 | Alert on outbound connections from FortiSandbox appliances to non-Fortinet IPs (potential post-exploitation C2) | CRITICAL |
| ATT&CK | Detection Logic | Priority |
|---|---|---|
T0816 | Alert on unexpected PLC restarts or communication drops on Rockwell CompactLogix/ControlLogix | HIGH |
T0831 | Monitor for unauthorized configuration changes to Siemens ROX II switches or SICAM 8 devices | HIGH |
T1053.003 | Where OT monitoring is available, flag new cron entries on Siemens ROX II devices | HIGH |
creativecommunityinfo[.]art — ACR Stealer payload hosting. enhanceblabber[.]cc — ACR Stealer C2. claude-desktop[.]gitlab[.]io — ClickFix lure page (fake Claude Code installer). 165.154.41[.]213 — associated threat infrastructure. Block at web proxy and DNS; sinkhole at the resolver level. Additional IOCs available via Anomali ThreatStream and partner feeds.
mshta.exe or conhost.exe spawned from explorer.exe (the Run dialog) with command-line arguments containing URLs or encoded PowerShell, followed by credential-store enumeration within 60 seconds.- Any
mshta.exeexecution with network activity → escalate immediately - FortiSandbox appliance making outbound connections to unknown IPs → isolate and investigate
- Scheduled-task creation outside change windows → correlate with ClickFix indicators
- M365 impossible-travel alerts coinciding with new device registrations → potential token theft from ACR Stealer
- Enable Conditional Access requiring compliant devices for Treasury SharePoint sites; implement token binding where supported
- Watch for ClickFix lures themed around tax compliance, payment processing or audit notifications
- Monitor for unusual bulk access to tax/revenue databases and credential stuffing against citizen-facing portals
- Inventory all Siemens ROX II switches and SICAM 8 devices; verify firmware V2.17.1 deployment
- Ensure OT network segmentation prevents lateral movement from a compromised switch
- Watch for unauthorized SSH to OT switches, new cron entries, and file-system modifications in feature-key directories
- Verify offline backup integrity for Medicaid enrollment and claims systems; ensure MFA on all EHR/claims portals
- Segment health-data networks from general state IT
- Watch for ClickFix lures themed around benefits enrollment, HIPAA compliance or health-portal access
- Audit election-system network segmentation; verify no shared credentials with general state IT
- Prepare for a potential CISA emergency directive on election hardening
- Watch for unusual queries against voter-registration databases, new Entra ID device enrollments from unexpected geolocations, and living-off-the-land activity
- Audit Rockwell CompactLogix/ControlLogix firmware in traffic-management systems
- Verify MSP access is scoped and monitored; ensure safety systems have independent fail-safes
- Watch for unexpected PLC restarts or communication drops and MSP credential usage outside normal hours
creativecommunityinfo[.]art, enhanceblabber[.]cc, claude-desktop[.]gitlab[.]io. Sinkhole at the resolver level.mshta.exe spawning PowerShell with network connections; rundll32.exe loading DLLs from WebDAV paths; conhost.exe spawned from explorer.exe with encoded arguments.mshta.exe via WDAC or AppLocker — this eliminates the ClickFix vector at the endpoint.The threat environment facing state government has shifted. Security appliances are being targeted as entry points, users are being tricked into becoming the malware execution engine, and OT infrastructure now has public exploitation blueprints available to any adversary. ClickFix represents a category change in social engineering — no attachment, no link, nothing your email gateway, sandbox or URL-reputation service can intercept — so the control point must shift from the network to the endpoint. Russian military intelligence, Chinese espionage, Iranian destructive operators and financially motivated ransomware groups are all active, all updated and all targeting government. The question is not whether agencies will be targeted, but whether they detect and respond before impact.