TLP:GREEN  ·  States / Public Sector
FortiOS Persistence Bypass, APT28 Active C2, and Critical vBulletin RCE:

What State Government CISOs Must Act On Today

ELEVATED. Three converging developments demand immediate attention from state government IT leadership: a CISA-confirmed actively exploited FortiOS vulnerability that allows attackers to survive patching, fresh Russian military intelligence infrastructure targeting U.S. government networks, and a CVSS 9.8 pre-authentication remote code execution vulnerability in vBulletin with public exploit code available. Combined with an expanding ICS vulnerability surface and sustained nation-state espionage operations, state agencies face a threat environment requiring decisive action this week.

I am a
My sector

DevelopmentDateWhy It Matters
CVE-2025-68686 (FortiOS symbolic link bypass) added to CISA KEV, confirmed active exploitationJul 27Enables attackers who previously compromised FortiGate to maintain access even after patching — patches may not have removed the attacker
APT28 (Fancy Bear / GRU Unit 26165) infrastructure confirmed active against U.S. government targetsJul 2794% confidence — Russian military intelligence actively operating against government networks
CVE-2026-61511 (vBulletin pre-auth RCE, CVSS 9.8) published with public PoCJul 27Any public-facing vBulletin instance exploitable without any authentication
Sustained Russian state espionage — three distinct operational clusters (APT28, Secret Blizzard, FSB Center 16) active simultaneouslyOngoingCoordinated intelligence collection posture, not isolated campaigns
Salt Typhoon persistent access confirmed in multiple U.S. state agencies and National Guard unitsJul 25Chinese MSS pre-positioning for potential disruption
Coordinated cyberattacks on four Minnesota municipal water/wastewater SCADA systemsJul 27Most significant coordinated U.S. water infrastructure attack since Aliquippa, PA (2023)
Single-day surge of four Siemens ICS advisories and a MikroTik RouterOS brute force vulnerabilityJul 28Materially expands the OT/ICS attack surface for state critical infrastructure
Unattributed IIS rootkit campaign targeting public sector web infrastructure with kernel-mode persistenceOngoingSophistication level consistent with nation-state actors

DateEventSignificance
23 JulJoint Advisory AA26-204A: Russian GRU (UNC5792) and FSB (UNC4221) Zimbra credential harvestingActive Russian state credential theft campaigns against government
25 JulDHS confirms Salt Typhoon persistent access in multiple U.S. state agencies and National GuardChinese MSS pre-positioning for potential disruption
27 JulFour Minnesota municipalities suffer simultaneous cyberattacks on water/wastewater SCADAMost significant coordinated U.S. water infrastructure attack since Aliquippa, PA (2023)
27 JulCVE-2025-68686 (FortiOS symbolic link bypass) added to CISA KEV — active exploitation confirmedPreviously compromised FortiGate appliances retain attacker access despite patching
27 JulCVE-2026-61511 (vBulletin pre-auth RCE, CVSS 9.8) published with public PoCAny public-facing vBulletin instance exploitable without authentication
27 JulAPT28 C2 IP confirmed active targeting U.S. government (confidence 94%)Russian military intelligence actively operating against government networks
28 JulFour Siemens ICS advisories + MikroTik RouterOS brute force vulnerabilityExpanding OT/ICS attack surface for state critical infrastructure
28 JulCISA/ACSC joint CI Fortify guidance on isolating vital OT systemsDefensive framework for water, transportation, building management
28 JulFIN7 supply chain malware with government targeting identifiedTrojanized software delivery mechanism historically precedes ransomware

CVE-2025-68686 affects FortiOS versions 7.6.0–7.6.1, 7.4.0–7.4.6, and all 7.2/7.0/6.4 releases. The vulnerability exploits the symbolic link persistence mechanism — a technique where attackers create filesystem symbolic links that survive firmware updates. This is the third KEV entry in the FortiOS/FortiSandbox persistence family, indicating a systemic design-level weakness rather than an isolated bug.

What this means for state agencies: if any FortiGate appliance in your environment was compromised at any point in the past 18 months (even if subsequently patched), the attacker may still have access. Patching alone is insufficient — integrity verification is mandatory.

T1190T1505.003T1036

Russian military intelligence (GRU Unit 26165, tracked as APT28/Fancy Bear) is operating confirmed command-and-control infrastructure targeting U.S. government entities. The identified C2 node at 183.81.168[.]186 is hosted on ASN 206264 (Amarutu Technology), a known bulletproof hosting provider. This infrastructure supports initial access, data collection, and command-and-control operations.

This is not an isolated finding. Three distinct Russian state operational clusters are simultaneously active against government targets: APT28 (GRU) — active C2 infrastructure, credential harvesting; Secret Blizzard — adversary-in-the-middle (AiTM) session hijacking; FSB Center 16 — router scanning and network device exploitation. This represents a coordinated intelligence collection posture — not isolated campaigns.

T1190T1005T1571

CVE-2026-61511 is a critical (CVSS 9.8) unauthenticated remote code execution vulnerability in vBulletin 5.x through 6.x. The attack exploits eval injection in the template runtime using phpfuck-style encoding to bypass regex filters. Multiple security firms have confirmed the vulnerability, and detailed proof-of-concept code is publicly available.

State government relevance: agencies, boards, and commissions occasionally operate legacy forum software for constituent engagement or employee collaboration. Any instance of vBulletin exposed to the internet is exploitable without any authentication.

T1190T1059.001

FIN7 (Carbon Spider / Sangria Tempest) — a financially motivated group that historically enables ransomware operations — has been identified delivering trojanized software targeting government among 16+ industries. The malware includes the Expiro file infector and PowerShell-based implants delivered through compromised software supply chains.

Why this matters: FIN7's supply chain operations have historically preceded ransomware deployment by groups including BlackCat/ALPHV and BASTA. State agencies relying on third-party software without integrity verification are exposed.

T1195.002

A single day brought four Siemens advisories affecting systems commonly deployed in state government: Siemens Desigo CC (building automation) — OpenSSL stack buffer overflow; Siemens SIMATIC S7-1500 (industrial control) — multiple vulnerabilities in GNU/Linux subsystem; Siemens S7-PLCSIM Advanced — denial of service; Siemens Mendix Runtime — access rule bypass.

Additionally, MikroTik RouterOS (commonly deployed in state branch offices) received an advisory for a brute force vulnerability enabling unauthorized access. MikroTik devices are documented infrastructure for both Volt Typhoon and Russian state actors (Sandworm).

An unattributed campaign is compromising public sector systems through IIS web server exploitation followed by custom kernel-mode rootkits for persistence. The sophistication level (kernel-mode rootkits) is typically associated with nation-state actors. If targeting state government web portals, this could enable long-term data exfiltration or watering-hole attacks against state employees.

T1190T1014T1543.003

ScenarioProbabilityBasis
Mass scanning and exploitation attempts against FortiGate appliances following KEV listing70%KEV listings consistently trigger mass scanning within 48 hours; criminal and state actors both motivated
vBulletin CVE-2026-61511 exploitation in the wild50%Public PoC available, CVSS 9.8, no auth required — low barrier to exploitation
Attribution of Minnesota water attacks to nation-state actor40%Iranian-affiliated actors have documented interest in water PLCs; investigation ongoing
APT28 C2 infrastructure rotation to new IPs within 48–72 hours40%Disclosed infrastructure typically burned quickly; expect pivot to fresh nodes
Additional state/local government ransomware incident35%FIN7 supply chain activity historically precedes ransomware; Cactus/Qilin/Deadlock remain active
Escalation of IIS rootkit campaign to U.S. state government targets20%Currently unattributed and geographically uncertain; monitoring warranted

HypothesisATT&CK TechniqueDetection Approach
FortiGate appliances contain symbolic link persistence from prior compromiseT1505.003Run Fortinet symbolic link integrity check tool on all FortiGate devices; inspect /data/ filesystem for unexpected symlinks
APT28 is communicating with internal hosts via non-standard portsT1571Query netflow/firewall logs for any connection to 183.81.168[.]186 or ASN 206264 in past 90 days
FIN7 trojanized software executed on endpointsT1195.002Hunt for the two SHA-256 hashes across all endpoint telemetry; look for Expiro file infector behavioral signatures
Token theft/AiTM bypassing MFAT1539 T1557Review Entra ID sign-in logs for impossible travel, token replay from new device IDs, or sessions without corresponding MFA challenge
IIS servers hosting government web apps compromised with rootkitT1014 T1190Audit IIS servers for unexpected kernel drivers, unsigned modules, or anomalous w3wp.exe child processes
MikroTik routers compromised via brute forceT1110.001Review MikroTik management interface logs for failed authentication spikes; check for unauthorized user accounts
vBulletin exploitation attemptsT1190Monitor WAF logs for phpfuck-encoded payloads, unusual POST requests to template runtime endpoints
IOC Blocking Table:
183.81.168[.]186

183.81.168[.]186 — APT28 active C2, block at perimeter, alert on any historical connection in 90-day netflow. FIN7 supply chain malware SHA-256: f8e9556fc28c01ee2da8607dbde1329558a71250db7ef79c45ac57c42f514909, dd8695ab8fb5b7a70cd52d5e0c76ff35637c1d26d02b97e63ff90b3b35b5a51c — block in EDR/AV. Additional IOCs for the campaigns discussed in this report are available through Anomali ThreatStream Next-Gen and partner feeds.

SIEM Correlation Rules to Validate:

FortiGate integrity alert: any FortiGate syslog indicating filesystem modification outside maintenance windows. Bulletproof hosting communication: outbound connections to ASN 206264 (Amarutu Technology) from any internal host. Credential harvesting indicators: spike in Entra ID sign-in failures followed by successful auth from new IP/device. ICS anomaly: unexpected outbound connections from Siemens Desigo CC or S7-1500 network segments. Supply chain execution: new unsigned executables or PowerShell processes spawned from recently installed software.

Hunting Hypotheses:
HUNT 01 · T1505.003
FortiGate symbolic link persistence
Run the Fortinet symbolic link integrity check tool on all FortiGate devices, including previously patched ones. Inspect /data/ filesystem for unexpected symlinks.
HUNT 02 · T1571
APT28 C2 on non-standard ports
Query netflow/firewall logs for any historical connection to 183.81.168[.]186 or ASN 206264 (Amarutu Technology, bulletproof hosting).
HUNT 03 · T1195.002
FIN7 trojanized software execution
Hunt for the two FIN7 SHA-256 hashes across all endpoint telemetry; look for Expiro file infector behavioral signatures.
HUNT 04 · T1557
Token theft / AiTM bypassing MFA
Review Entra ID sign-in logs for impossible travel, token replay from new device IDs, or sessions without a corresponding MFA challenge.
HUNT 05 · T1014
IIS rootkit compromise
Audit IIS servers hosting government web apps for unexpected kernel drivers, unsigned modules, or anomalous w3wp.exe child processes.

Financial Services
State Treasury, Revenue, Benefits Systems
Primary threat
FIN7 supply chain compromise leading to ransomware deployment against financial processing systems
Secondary threat
Token theft — benefits portals and tax systems using M365 authentication are prime targets for AiTM attacks
Actions
  • Audit all third-party software installations on systems processing financial transactions; verify software integrity via vendor-published hashes before deployment
  • Enforce Continuous Access Evaluation (CAE) and compliant device requirements for M365 authentication
Energy
State-Regulated Utilities, Grid Operations
Primary threat
ICS vulnerability accumulation (Siemens S7-1500, lib60870 IEC 60870-5-104 protocol library) combined with Volt Typhoon pre-positioning
Secondary threat
MikroTik risk — branch office routers connecting to utility substations vulnerable to brute force
Actions
  • Implement CISA CI Fortify isolation guidance for energy SCADA networks; verify no IT-to-OT lateral movement paths exist; audit S7-1500 firmware versions against ICSA-26-209-04
  • Harden MikroTik devices against brute force: rate limiting, complex credentials, management interface ACLs
Healthcare
State Health Agencies, Medicaid Systems
Primary threat
Ransomware via supply chain (FIN7 → ransomware handoff) targeting systems with high service continuity pressure
Secondary threat
Credential theft — health information exchanges using federated identity are vulnerable to token theft
Actions
  • Validate offline backup integrity for Medicaid processing systems; ensure EDR coverage includes all clinical and administrative endpoints; block FIN7 hashes immediately
  • Review session lifetime policies for federated identity systems
Government
Executive Agencies, Legislative, Courts
Primary threat
APT28 espionage targeting government networks; IIS rootkit campaign against public sector web infrastructure
Secondary threat
vBulletin risk — any agency-operated forum must be inventoried and patched to 6.2.2 or taken offline within 7 days
Actions
  • Block APT28 C2 infrastructure immediately; audit all IIS-hosted government web applications for unexpected kernel drivers or web shells
  • Review Zimbra deployments for credential harvesting indicators per Joint Advisory AA26-204A
Aviation / Logistics
State DOT, Airport Authorities, Port Systems
Primary threat
Volt Typhoon / Salt Typhoon pre-positioning in transportation control systems for potential disruption during geopolitical escalation
Secondary threat
Supply chain — logistics management software should be audited for integrity given FIN7's broad industry targeting
Actions
  • Segment transportation SCADA from enterprise IT; apply Siemens Desigo CC patches for building automation in terminals and facilities
  • Verify MikroTik devices in remote transportation sites are not using default credentials
No sector cards match the selected filters.

Run Fortinet symbolic link integrity check tool on ALL FortiGate appliances statewide. Verify patches for CVE-2025-68686 are applied (FortiOS ≥7.6.2, ≥7.4.7). Any device showing symlink anomalies must be forensically imaged and rebuilt — not just re-patched.
IAM Analyst
Block APT28 C2 IP 183.81.168[.]186 at perimeter firewalls and add to SIEM watchlist. Run 90-day retrospective query across all netflow data for any historical connection to this IP or ASN 206264.
SOC Analyst
Deploy FIN7 SHA-256 hashes to EDR blocklists and run retroactive scan across all managed endpoints. Alert on Expiro file infector behavioral signatures.
SOC Analyst
Brief agency heads that FortiGate integrity verification is underway and may require maintenance windows for device rebuilds if compromise is confirmed.
CISO / Exec
No immediate actions for the selected roles.
Conduct full asset inventory for vBulletin installations across all agency web properties. Any instance of vBulletin 5.x–6.x must be patched to 6.2.2 or isolated from the internet immediately. CVE-2026-61511 is pre-auth RCE with public exploit code.
IAM Analyst
Inventory all MikroTik RouterOS devices in state networks. Apply rate-limiting on management interfaces, enforce complex credentials, verify no default credentials remain. Prioritize devices in OT-adjacent locations.
IAM Analyst
Review Siemens Desigo CC building automation systems for OpenSSL patch status. Coordinate with facilities management for S7-1500 firmware assessment per ICSA-26-209-04.
ICS / OT
Validate Entra ID Conditional Access policies enforce token binding and Continuous Access Evaluation (CAE). Reduce refresh token lifetimes to 24-hour maximum. Review for gaps in device compliance requirements.
IAM Analyst
Audit all IIS-hosted government web applications for unexpected kernel-mode drivers, unsigned modules, or anomalous service installations. Baseline known-good configurations.
SOC Analyst
No 7-day actions for the selected roles.
Implement CISA CI Fortify isolation guidance for state water/wastewater SCADA networks. Commission formal segmentation assessment with qualified OT security vendor.
CISO / ExecICS / OT
Initiate architectural review of Fortinet as primary perimeter vendor. Three KEV entries in the same persistence mechanism family indicates a systemic design weakness. Evaluate diversification options.
CISO / Exec
Evaluate creation of an election infrastructure threat monitoring program given approaching election cycles and current absence of collection in this area.
CISO / Exec
Conduct tabletop exercise simulating simultaneous FortiGate compromise discovery + ransomware deployment via supply chain — test coordination between SOC, IT Ops, and agency leadership.
Incident Responder
Assess need for redundant OSINT intelligence source to address single-point-of-failure in threat visibility architecture. Current degradation reduces detection capacity to approximately 70%.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

State government networks are facing a convergence of threats that individually would warrant attention and collectively demand urgent action. The FortiOS persistence bypass is particularly insidious — it means that agencies which believed they had remediated prior compromises may still be hosting adversaries. This is not theoretical; CISA confirms active exploitation. The Russian intelligence apparatus is operating three simultaneous collection campaigns against government targets. Salt Typhoon maintains confirmed persistent access in state agencies. FIN7 is staging supply chain malware that historically precedes ransomware. And a CVSS 9.8 vulnerability with public exploit code threatens any state-operated forum.

1
Verify the integrity of every FortiGate appliance in your environment. Patching is necessary but no longer sufficient — if symbolic link persistence is detected, assume the device and potentially the network behind it are compromised.
2
Have you blocked the APT28 C2 node? Three simultaneous Russian collection clusters (APT28, Secret Blizzard, FSB Center 16) represent a coordinated intelligence posture, not isolated campaigns.
3
Is your public-facing vBulletin patched? CVE-2026-61511 requires no credentials and has public exploit code — the organizations that act within 24 hours will be materially safer than those that wait for the next patch cycle.
No items found.