TLP:GREEN  ·  States / Public Sector
Four Minnesota Water Utilities Attacked Simultaneously:

Critical Zero-Days Demand Immediate State Government Action

ELEVATED. On July 27, 2026, four Minnesota municipalities simultaneously lost automated control of their water and wastewater systems in the most significant coordinated cyberattack on U.S. municipal water infrastructure since Aliquippa, Pennsylvania in 2023. The same day, CISA added a perfect CVSS 10.0 vulnerability in Arista VeloCloud Orchestrator to its KEV catalog. Compounding the risk: TheGentlemen ransomware group now deploys a self-propagating worm with a dedicated EDR-killing framework, and Qilin continues exploiting VPN zero-days for initial access.

I am a
My sector

DevelopmentDateWhy It Matters for State Government
Coordinated attack on 4+ Minnesota water systemsJul 27Demonstrates that municipal utilities under state oversight are being targeted simultaneously — likely via shared vendor/technology
CVE-2026-16812 — VeloCloud Orchestrator RCE (CVSS 10.0, KEV)Jul 27Any state agency using on-premises VeloCloud SD-WAN faces unauthenticated full compromise
CVE-2025-68686 — FortiOS symlink bypass (KEV)Jul 27Previously patched FortiGate appliances can be re-compromised; persistence survives patching
CVE-2026-63077 — TeamCity unauthenticated RCE (CVSS 9.8)Jul 28CI/CD pipelines used for state application deployment are at risk of supply chain injection
TheGentlemen ransomware gains worm + EDR-killer capabilityOngoingSelf-propagating ransomware that disables endpoint security before encrypting — catastrophic for flat networks
Q2 2026 ransomware: 2,666 incidents, 89 active groupsOngoingQilin (#1 globally), LockBit 5.0 resurfaced, encryption-less extortion now 22% of attacks
Salt Typhoon (Chinese MSS) confirmed in U.S. state agenciesJul 25Espionage-focused persistent access confirmed in multiple state agencies and at least one National Guard unit — prior remediation cannot be assumed complete
CVE-2026-16723 (Fastjson RCE, CVSS 9.0) — no patch availableOngoingActively exploited against government Java services with no vendor fix; state citizen-facing portals remain exposed indefinitely
Lazarus Group PolinRider supply chain campaign expands to 4,295 packagesOngoingBlockchain-based C2 evades traditional network detection; state developer toolchains at risk

DateEventSeverity
Jul 22CVE-2026-16232 (Check Point SmartConsole auth bypass, CVSS 9.1) added to CISA KEVCritical
Jul 23Joint Advisory AA26-204A: Russian GRU (UNC5792) and FSB (UNC4221) Zimbra credential harvesting + Signal/WhatsApp backup key theft; $10M bounty announcedHigh
Jul 25DHS confirms Salt Typhoon (Chinese MSS) persistent access in multiple U.S. state agencies and National Guard unitCritical
Jul 27Coordinated cyberattack on Maple Plain, Braham, Plymouth, and South St. Paul MN water/wastewater systemsCritical
Jul 27CVE-2026-16812 (VeloCloud Orchestrator CVSS 10.0) added to CISA KEV — active exploitation confirmedCritical
Jul 27CVE-2025-68686 (FortiOS symlink bypass) added to CISA KEV — persistence re-enablerHigh
Jul 28CVE-2026-63077 (TeamCity RCE CVSS 9.8) disclosed — no wild exploitation yet but imminent riskHigh
OngoingCVE-2026-16723 (Fastjson RCE CVSS 9.0) — actively exploited against government, no patch availableCritical
OngoingLazarus Group PolinRider supply chain campaign — 4,295 malicious packages with blockchain C2High

Four Minnesota municipalities — Maple Plain, Braham, Plymouth, and South St. Paul — reported simultaneous cyber incidents affecting automated water and wastewater controls on July 27. Braham confirmed its well and water treatment plant were shut down for approximately two hours. Plymouth lost cellular communications with water towers and lift stations. All facilities switched to manual operations; drinking water safety was maintained.

Why this is different: previous U.S. water system attacks (Oldsmar FL 2021, Aliquippa PA 2023) were single-municipality events. The simultaneity of four-plus attacks in one state suggests either a shared technology provider was compromised, or a threat actor pre-positioned across multiple targets and activated simultaneously. Federal agencies have previously warned about Iranian-affiliated actors targeting PLCs in U.S. water systems; attribution for the Minnesota incidents has not been officially confirmed.

State government implication: municipal water utilities typically fall under state environmental and public health oversight but operate IT/OT systems independently. A shared-vendor compromise could cascade across dozens of municipalities simultaneously.

T0831T0836T1133T0816

Arista disclosed a critical OS command injection vulnerability in VeloCloud Orchestrator (VCO) on-premises deployments. A remote, unauthenticated attacker can access privileged internal functionality, compromising the confidentiality, integrity, and availability of the SD-WAN orchestrator and all managed network data. This is actively exploited in the wild with three confirmed attacker IPs published by the vendor.

State government implication: VeloCloud SD-WAN is deployed across government and education networks for branch connectivity. Compromise of the orchestrator gives an attacker control over routing, traffic inspection, and configuration of every managed edge device — effectively owning the entire wide-area network. This is a "patch now or assume compromise" scenario.

T1190

This vulnerability allows attackers who previously compromised FortiGate appliances to regain access even after the original symlink persistence patch was applied. It is a "persistence re-enabler" — meaning state agencies that believed they remediated prior Fortinet compromises may still have active adversary access.

State government implication: Fortinet appliances are ubiquitous in state government perimeters. Given that Chinese (Volt Typhoon) and Russian actors have extensively targeted FortiGate devices, this bypass means prior remediation efforts cannot be assumed complete. Fresh audits are required.

T1505.003

All TeamCity On-Premises versions prior to 2025.11.7 and 2026.1.3 contain an authentication bypass via the agent polling protocol, allowing unauthenticated arbitrary OS command execution. While no wild exploitation has been confirmed yet, Russia's SVR (APT29) extensively exploited the previous TeamCity vulnerability (CVE-2023-42793) for supply chain access.

State government implication: state agencies increasingly use CI/CD pipelines for deploying citizen-facing applications. A compromised TeamCity server allows injection of malicious code into every application built through that pipeline — from DMV portals to benefits systems.

T1190

The Q2 2026 ransomware landscape represents a qualitative capability shift: Qilin (334 incidents, #1 globally for 3 consecutive quarters) exploited Check Point VPN zero-day CVE-2026-50751 for initial access. TheGentlemen (262 incidents) deploys a self-propagating worm module combined with "GentleKiller" — a dedicated EDR-killing framework using 8+ BYOVD drivers to terminate ~400 security processes. DragonForce (238 incidents) operates a "cartel" model absorbing smaller groups, using "Backdoor.Turn" which abuses Microsoft Teams TURN relay servers for C2. LockBit 5.0 (107 incidents) resurfaced post-Operation Cronos with cross-platform capability (Windows/Linux/ESXi). Encryption-less extortion now accounts for 22% of attacks, up from 2% in late 2024.

The critical combination: when attackers can bypass perimeters via VPN zero-days, propagate laterally without operator intervention via worm modules, AND disable endpoint security via BYOVD drivers, the traditional defense-in-depth model fails at every layer simultaneously. Network segmentation becomes the last reliable control.

T1068T1562.001T1210

From prior cycles, three threats remain active and unresolved: Salt Typhoon (Chinese MSS) confirmed persistent access in multiple U.S. state agencies and at least one National Guard unit (disclosed Jul 25) — no new indicators this cycle, but absence likely reflects improved adversary operational security, not reduced risk. CVE-2026-16723 (Fastjson RCE, CVSS 9.0) actively exploited against government Java-based services with no patch available; state citizen-facing portals running versions 1.2.68–1.2.83 remain vulnerable. Lazarus Group PolinRider supply chain campaign expanded to 4,295 malicious packages using blockchain-based C2, evading traditional network detection.

T1059.001T1053.005T1090.001

ScenarioProbabilityTimeframeBasis
CVE-2026-63077 (TeamCity) exploitation attempts begin>70%7 daysCVSS 9.8 + historical APT29 interest in TeamCity + public disclosure
CVE-2026-16812 (VeloCloud) exploitation expands to government targets>60%7 daysCVSS 10.0 + active exploitation + government SD-WAN prevalence
Minnesota water attack officially attributed to Iranian-affiliated actors40–60%14 daysFederal advisory correlation + investigation timeline
TheGentlemen or Qilin claims a U.S. government victim40–60%14 daysCurrent operational tempo (596 combined Q2 victims)
Additional U.S. water utilities report incidents linked to Minnesota campaign30–50%21 daysShared-vendor hypothesis + coordinated attack pattern

PriorityWhat to MonitorATT&CK IDDetection Logic
CRITICALVeloCloud Orchestrator access from attacker IPsT1190Alert on any connection to/from 8.19.75[.]217, 206.72.242[.]124, 206.72.242[.]162
CRITICALFortiGate symlink artifactsT1505.003Scan FortiGate filesystem for symbolic links in web-accessible directories; check for /migadmin/ or /vpn/ symlinks pointing to /
HIGHBYOVD driver loading (GentleKiller)T1068 T1562.001Alert on loading of known vulnerable signed drivers followed by termination of >3 security processes within 60 seconds
HIGHTeamCity agent polling protocol anomaliesT1190Monitor TeamCity servers for unauthenticated HTTP(S) requests to agent polling endpoints; baseline normal agent communication patterns
HIGHLateral movement via SMB/RPC (worm propagation)T1210Alert on rapid sequential SMB connections from a single host to multiple endpoints (>10 hosts in 5 minutes)
MEDIUMMicrosoft Teams TURN relay abuseT1071.001Monitor for anomalous outbound traffic to Microsoft Teams TURN relay infrastructure from non-Teams processes
MEDIUMFastjson deserialization attemptsT1190WAF rules for @type parameter in JSON POST bodies; monitor for com.sun.rowset.JdbcRowSetImpl class loading
IOC Blocking Table:
8.19.75[.]217206.72.242[.]124206.72.242[.]162

All three IPs — confirmed CVE-2026-16812 VeloCloud exploitation infrastructure. Block at all perimeter firewalls, proxies, and DNS. Additional IOCs for the campaigns discussed in this report — including indicators associated with PRIMITIVEBEAR, SAMBASPIDER, Salt Typhoon, and Lazarus Group PolinRider — are available through Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
VeloCloud Orchestrator compromise
Search network logs for any historical connections to 8.19.75[.]217, 206.72.242[.]124, or 206.72.242[.]162. If found, assume full SD-WAN compromise and initiate IR.
HUNT 02 · T1505.003
FortiGate re-compromise via symlink bypass
Even if the CVE-2025-68686 patch is applied, check for residual symlink artifacts from prior compromises. Attackers may have re-established persistence before patching.
HUNT 03 · T1133
Pre-positioned access in water utility SCADA
If your state oversees municipal water systems, query utility operators for internet-facing PLCs, cellular modem remote access to SCADA, and shared vendors with the affected Minnesota municipalities.
HUNT 04 · T1210
TheGentlemen worm propagation test
Search for lateral movement patterns consistent with automated propagation: sequential SMB authentication attempts, PsExec/WMI execution across multiple hosts in rapid succession, followed by security service termination.
HUNT 05 · T1059.001
Salt Typhoon persistence
Given confirmed access in U.S. state agencies, hunt for living-off-the-land indicators: unusual netsh port forwarding, ntdsutil credential dumping, scheduled tasks with encoded PowerShell, or traffic to known ORB network infrastructure.

Financial Services
State Treasury, Revenue, Benefits Systems
Primary threat
Qilin ransomware exploiting VPN zero-days (CVE-2026-50751) for initial access to financial processing systems
Secondary threat
Encryption-less extortion targeting PII databases (22% of attacks now data-theft-only)
Actions
  • Audit all Check Point VPN appliances for CVE-2026-50751 patching status; implement MFA on all VPN connections regardless of source IP; monitor for unusual after-hours VPN authentication patterns
  • Ensure DLP controls monitor for bulk database exports; validate that backup encryption keys are stored offline and separately from production systems
Energy
State-Regulated Utilities, Grid Operations
Primary threat
Coordinated ICS attacks following the Minnesota water system pattern — shared SCADA vendors create single points of failure across utilities
Secondary threat
VeloCloud Orchestrator compromise (CVE-2026-16812) affecting utility SD-WAN connectivity
Actions
  • Inventory all internet-facing OT/ICS systems; mandate VPN-only access for remote SCADA management; identify shared technology providers across state-regulated utilities
  • Confirm whether energy utilities use VeloCloud for operational network connectivity; if yes, treat as emergency patching priority
Healthcare
State Health Agencies, Medicaid Systems
Primary threat
TheGentlemen worm propagation through flat clinical/administrative networks combined with EDR neutralization
Secondary threat
Fastjson zero-day (CVE-2026-16723) affecting Java-based health information exchanges and patient portals
Actions
  • Validate network segmentation between clinical systems, administrative networks, and internet-facing portals; confirm EDR tamper protection is enabled and test against BYOVD scenarios
  • Inventory all Java applications using Alibaba Fastjson; implement WAF rules blocking malicious deserialization payloads as interim mitigation until patch is available
Government
State Agencies, Courts, Elections
Primary threat
Salt Typhoon confirmed persistent access in U.S. state agencies — espionage-focused pre-positioning for geopolitical leverage
Secondary threat
TeamCity RCE (CVE-2026-63077) enabling supply chain compromise of state application deployments; Russian GRU/FSB credential harvesting via Zimbra (AA26-204A) targeting government email
Actions
  • Conduct threat hunt focused on living-off-the-land techniques (T1059.001 PowerShell, T1053.005 Scheduled Tasks, T1090.001 Internal Proxy); review privileged account activity; audit Active Directory for unauthorized service accounts
  • Restrict TeamCity server access to VPN-only; upgrade immediately; audit recent builds for unauthorized code changes
  • If using Zimbra, apply all patches and monitor for credential harvesting indicators; brief staff on phishing campaigns targeting webmail credentials
Aviation / Logistics
State DOT, Ports, Transit Authorities
Primary threat
VeloCloud Orchestrator compromise (CVE-2026-16812) — transit and logistics networks frequently use SD-WAN for distributed site connectivity
Secondary threat
DragonForce ransomware using Microsoft Teams TURN relay for C2 — difficult to detect in environments that legitimately use Teams
Actions
  • Emergency audit of all VeloCloud on-premises deployments; patch or isolate immediately; review orchestrator logs for unauthorized configuration changes
  • Baseline Teams TURN relay traffic patterns; alert on TURN relay connections from non-Teams processes or from servers that should not generate Teams traffic
No sector cards match the selected filters.

Block attacker IPs 8.19.75[.]217, 206.72.242[.]124, 206.72.242[.]162 at all perimeter firewalls — confirmed VeloCloud exploitation infrastructure.
IAM Analyst
Determine VeloCloud presence — confirm within 24 hours whether any state agency operates Arista/VMware VeloCloud Orchestrator on-premises; if yes, apply Arista SA-0144 emergency patch and audit for compromise.
IAM Analyst
Audit all Fortinet FortiGate appliances for CVE-2025-68686 — apply FG-IR-25-934 patch; check for residual symlink artifacts even on previously patched devices.
IAM Analyst
Issue emergency advisory to state water/wastewater utilities — confirm SCADA/PLC remote access is disabled or VPN-only; verify no internet-facing PLCs; request shared vendor identification.
SOC AnalystCISO / Exec
Deploy IOC blocks and detection rules for VeloCloud attacker infrastructure and BYOVD/EDR-killer patterns.
SOC Analyst
No immediate actions for the selected roles.
Patch TeamCity across all state agencies — upgrade to 2025.11.7+ or 2026.1.3+; restrict HTTP(S) access via VPN only (CVE-2026-63077, CVSS 9.8).
SOC Analyst
Deploy TheGentlemen/GentleKiller detection — monitor for vulnerable driver loading followed by mass security process termination (T1068, T1562.001).
SOC Analyst
Validate inter-agency network segmentation — confirm firewall rules block SMB/RPC lateral movement between agency network segments; the worm capability makes flat networks catastrophically vulnerable.
IAM Analyst
Audit Java applications for Fastjson exposure — identify all services using Alibaba Fastjson 1.2.68–1.2.83; implement WAF deserialization blocking rules as interim mitigation (CVE-2026-16723, no patch available).
IAM Analyst
Initiate Salt Typhoon threat hunt — focus on living-off-the-land indicators in privileged infrastructure (domain controllers, VPN concentrators, email gateways).
SOC Analyst
No 7-day actions for the selected roles.
Commission shared-vendor assessment for state municipal water utilities — identify common SCADA vendors, remote monitoring platforms, and cellular providers to determine cascading compromise risk.
CISO / Exec
Evaluate EDR resilience against BYOVD — request vendor confirmation of tamper protection against GentleKiller-class driver-based termination; consider kernel-level integrity monitoring.
CISO / Exec
Establish state CI/CD security standard — TeamCity is the third critical CI/CD vulnerability in recent weeks; mandate pipeline security baselines across agencies.
CISO / Exec
Update incident response playbooks for coordinated ICS attack scenario (multiple utilities simultaneously) and worm-propagating ransomware scenario (cross-agency spread).
Incident Responder
Brief Governor's office / state emergency management on municipal water infrastructure cyber risk and potential for Iranian-attributed escalation requiring federal coordination.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The Minnesota water system attacks represent a threshold event. For the first time, we have documented evidence of coordinated, simultaneous cyberattacks against multiple municipal water utilities in a single U.S. state. Whether the attack vector proves to be a shared vendor compromise or pre-positioned nation-state access, the implication is the same: municipal utilities under state oversight represent an unmonitored attack surface with cascading failure potential. Simultaneously, the ransomware ecosystem has achieved a capability combination — VPN zero-day access, autonomous worm propagation, and EDR neutralization — that defeats traditional layered defense assumptions. Network segmentation is no longer a "nice to have." It is the last reliable control when every other layer can be bypassed.

1
Do you know if VeloCloud is in your environment? If you cannot answer within 24 hours, you cannot rule out active compromise via a CVSS 10.0 vulnerability.
2
Can your water utilities be attacked simultaneously? If you don't know their shared vendors, you cannot assess cascading risk.
3
Can ransomware propagate between your agencies? If inter-agency segmentation hasn't been validated recently, assume it's insufficient.
No items found.