| Development | Date | Why It Matters for State Government |
|---|---|---|
| Coordinated attack on 4+ Minnesota water systems | Jul 27 | Demonstrates that municipal utilities under state oversight are being targeted simultaneously — likely via shared vendor/technology |
| CVE-2026-16812 — VeloCloud Orchestrator RCE (CVSS 10.0, KEV) | Jul 27 | Any state agency using on-premises VeloCloud SD-WAN faces unauthenticated full compromise |
| CVE-2025-68686 — FortiOS symlink bypass (KEV) | Jul 27 | Previously patched FortiGate appliances can be re-compromised; persistence survives patching |
| CVE-2026-63077 — TeamCity unauthenticated RCE (CVSS 9.8) | Jul 28 | CI/CD pipelines used for state application deployment are at risk of supply chain injection |
| TheGentlemen ransomware gains worm + EDR-killer capability | Ongoing | Self-propagating ransomware that disables endpoint security before encrypting — catastrophic for flat networks |
| Q2 2026 ransomware: 2,666 incidents, 89 active groups | Ongoing | Qilin (#1 globally), LockBit 5.0 resurfaced, encryption-less extortion now 22% of attacks |
| Salt Typhoon (Chinese MSS) confirmed in U.S. state agencies | Jul 25 | Espionage-focused persistent access confirmed in multiple state agencies and at least one National Guard unit — prior remediation cannot be assumed complete |
| CVE-2026-16723 (Fastjson RCE, CVSS 9.0) — no patch available | Ongoing | Actively exploited against government Java services with no vendor fix; state citizen-facing portals remain exposed indefinitely |
| Lazarus Group PolinRider supply chain campaign expands to 4,295 packages | Ongoing | Blockchain-based C2 evades traditional network detection; state developer toolchains at risk |
| Date | Event | Severity |
|---|---|---|
| Jul 22 | CVE-2026-16232 (Check Point SmartConsole auth bypass, CVSS 9.1) added to CISA KEV | Critical |
| Jul 23 | Joint Advisory AA26-204A: Russian GRU (UNC5792) and FSB (UNC4221) Zimbra credential harvesting + Signal/WhatsApp backup key theft; $10M bounty announced | High |
| Jul 25 | DHS confirms Salt Typhoon (Chinese MSS) persistent access in multiple U.S. state agencies and National Guard unit | Critical |
| Jul 27 | Coordinated cyberattack on Maple Plain, Braham, Plymouth, and South St. Paul MN water/wastewater systems | Critical |
| Jul 27 | CVE-2026-16812 (VeloCloud Orchestrator CVSS 10.0) added to CISA KEV — active exploitation confirmed | Critical |
| Jul 27 | CVE-2025-68686 (FortiOS symlink bypass) added to CISA KEV — persistence re-enabler | High |
| Jul 28 | CVE-2026-63077 (TeamCity RCE CVSS 9.8) disclosed — no wild exploitation yet but imminent risk | High |
| Ongoing | CVE-2026-16723 (Fastjson RCE CVSS 9.0) — actively exploited against government, no patch available | Critical |
| Ongoing | Lazarus Group PolinRider supply chain campaign — 4,295 malicious packages with blockchain C2 | High |
Four Minnesota municipalities — Maple Plain, Braham, Plymouth, and South St. Paul — reported simultaneous cyber incidents affecting automated water and wastewater controls on July 27. Braham confirmed its well and water treatment plant were shut down for approximately two hours. Plymouth lost cellular communications with water towers and lift stations. All facilities switched to manual operations; drinking water safety was maintained.
Why this is different: previous U.S. water system attacks (Oldsmar FL 2021, Aliquippa PA 2023) were single-municipality events. The simultaneity of four-plus attacks in one state suggests either a shared technology provider was compromised, or a threat actor pre-positioned across multiple targets and activated simultaneously. Federal agencies have previously warned about Iranian-affiliated actors targeting PLCs in U.S. water systems; attribution for the Minnesota incidents has not been officially confirmed.
State government implication: municipal water utilities typically fall under state environmental and public health oversight but operate IT/OT systems independently. A shared-vendor compromise could cascade across dozens of municipalities simultaneously.
Arista disclosed a critical OS command injection vulnerability in VeloCloud Orchestrator (VCO) on-premises deployments. A remote, unauthenticated attacker can access privileged internal functionality, compromising the confidentiality, integrity, and availability of the SD-WAN orchestrator and all managed network data. This is actively exploited in the wild with three confirmed attacker IPs published by the vendor.
State government implication: VeloCloud SD-WAN is deployed across government and education networks for branch connectivity. Compromise of the orchestrator gives an attacker control over routing, traffic inspection, and configuration of every managed edge device — effectively owning the entire wide-area network. This is a "patch now or assume compromise" scenario.
This vulnerability allows attackers who previously compromised FortiGate appliances to regain access even after the original symlink persistence patch was applied. It is a "persistence re-enabler" — meaning state agencies that believed they remediated prior Fortinet compromises may still have active adversary access.
State government implication: Fortinet appliances are ubiquitous in state government perimeters. Given that Chinese (Volt Typhoon) and Russian actors have extensively targeted FortiGate devices, this bypass means prior remediation efforts cannot be assumed complete. Fresh audits are required.
All TeamCity On-Premises versions prior to 2025.11.7 and 2026.1.3 contain an authentication bypass via the agent polling protocol, allowing unauthenticated arbitrary OS command execution. While no wild exploitation has been confirmed yet, Russia's SVR (APT29) extensively exploited the previous TeamCity vulnerability (CVE-2023-42793) for supply chain access.
State government implication: state agencies increasingly use CI/CD pipelines for deploying citizen-facing applications. A compromised TeamCity server allows injection of malicious code into every application built through that pipeline — from DMV portals to benefits systems.
The Q2 2026 ransomware landscape represents a qualitative capability shift: Qilin (334 incidents, #1 globally for 3 consecutive quarters) exploited Check Point VPN zero-day CVE-2026-50751 for initial access. TheGentlemen (262 incidents) deploys a self-propagating worm module combined with "GentleKiller" — a dedicated EDR-killing framework using 8+ BYOVD drivers to terminate ~400 security processes. DragonForce (238 incidents) operates a "cartel" model absorbing smaller groups, using "Backdoor.Turn" which abuses Microsoft Teams TURN relay servers for C2. LockBit 5.0 (107 incidents) resurfaced post-Operation Cronos with cross-platform capability (Windows/Linux/ESXi). Encryption-less extortion now accounts for 22% of attacks, up from 2% in late 2024.
The critical combination: when attackers can bypass perimeters via VPN zero-days, propagate laterally without operator intervention via worm modules, AND disable endpoint security via BYOVD drivers, the traditional defense-in-depth model fails at every layer simultaneously. Network segmentation becomes the last reliable control.
From prior cycles, three threats remain active and unresolved: Salt Typhoon (Chinese MSS) confirmed persistent access in multiple U.S. state agencies and at least one National Guard unit (disclosed Jul 25) — no new indicators this cycle, but absence likely reflects improved adversary operational security, not reduced risk. CVE-2026-16723 (Fastjson RCE, CVSS 9.0) actively exploited against government Java-based services with no patch available; state citizen-facing portals running versions 1.2.68–1.2.83 remain vulnerable. Lazarus Group PolinRider supply chain campaign expanded to 4,295 malicious packages using blockchain-based C2, evading traditional network detection.
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| CVE-2026-63077 (TeamCity) exploitation attempts begin | >70% | 7 days | CVSS 9.8 + historical APT29 interest in TeamCity + public disclosure |
| CVE-2026-16812 (VeloCloud) exploitation expands to government targets | >60% | 7 days | CVSS 10.0 + active exploitation + government SD-WAN prevalence |
| Minnesota water attack officially attributed to Iranian-affiliated actors | 40–60% | 14 days | Federal advisory correlation + investigation timeline |
| TheGentlemen or Qilin claims a U.S. government victim | 40–60% | 14 days | Current operational tempo (596 combined Q2 victims) |
| Additional U.S. water utilities report incidents linked to Minnesota campaign | 30–50% | 21 days | Shared-vendor hypothesis + coordinated attack pattern |
| Priority | What to Monitor | ATT&CK ID | Detection Logic |
|---|---|---|---|
| CRITICAL | VeloCloud Orchestrator access from attacker IPs | T1190 | Alert on any connection to/from 8.19.75[.]217, 206.72.242[.]124, 206.72.242[.]162 |
| CRITICAL | FortiGate symlink artifacts | T1505.003 | Scan FortiGate filesystem for symbolic links in web-accessible directories; check for /migadmin/ or /vpn/ symlinks pointing to / |
| HIGH | BYOVD driver loading (GentleKiller) | T1068 T1562.001 | Alert on loading of known vulnerable signed drivers followed by termination of >3 security processes within 60 seconds |
| HIGH | TeamCity agent polling protocol anomalies | T1190 | Monitor TeamCity servers for unauthenticated HTTP(S) requests to agent polling endpoints; baseline normal agent communication patterns |
| HIGH | Lateral movement via SMB/RPC (worm propagation) | T1210 | Alert on rapid sequential SMB connections from a single host to multiple endpoints (>10 hosts in 5 minutes) |
| MEDIUM | Microsoft Teams TURN relay abuse | T1071.001 | Monitor for anomalous outbound traffic to Microsoft Teams TURN relay infrastructure from non-Teams processes |
| MEDIUM | Fastjson deserialization attempts | T1190 | WAF rules for @type parameter in JSON POST bodies; monitor for com.sun.rowset.JdbcRowSetImpl class loading |
All three IPs — confirmed CVE-2026-16812 VeloCloud exploitation infrastructure. Block at all perimeter firewalls, proxies, and DNS. Additional IOCs for the campaigns discussed in this report — including indicators associated with PRIMITIVEBEAR, SAMBASPIDER, Salt Typhoon, and Lazarus Group PolinRider — are available through Anomali ThreatStream Next-Gen and partner feeds.
8.19.75[.]217, 206.72.242[.]124, or 206.72.242[.]162. If found, assume full SD-WAN compromise and initiate IR.netsh port forwarding, ntdsutil credential dumping, scheduled tasks with encoded PowerShell, or traffic to known ORB network infrastructure.- Audit all Check Point VPN appliances for CVE-2026-50751 patching status; implement MFA on all VPN connections regardless of source IP; monitor for unusual after-hours VPN authentication patterns
- Ensure DLP controls monitor for bulk database exports; validate that backup encryption keys are stored offline and separately from production systems
- Inventory all internet-facing OT/ICS systems; mandate VPN-only access for remote SCADA management; identify shared technology providers across state-regulated utilities
- Confirm whether energy utilities use VeloCloud for operational network connectivity; if yes, treat as emergency patching priority
- Validate network segmentation between clinical systems, administrative networks, and internet-facing portals; confirm EDR tamper protection is enabled and test against BYOVD scenarios
- Inventory all Java applications using Alibaba Fastjson; implement WAF rules blocking malicious deserialization payloads as interim mitigation until patch is available
- Conduct threat hunt focused on living-off-the-land techniques (T1059.001 PowerShell, T1053.005 Scheduled Tasks, T1090.001 Internal Proxy); review privileged account activity; audit Active Directory for unauthorized service accounts
- Restrict TeamCity server access to VPN-only; upgrade immediately; audit recent builds for unauthorized code changes
- If using Zimbra, apply all patches and monitor for credential harvesting indicators; brief staff on phishing campaigns targeting webmail credentials
- Emergency audit of all VeloCloud on-premises deployments; patch or isolate immediately; review orchestrator logs for unauthorized configuration changes
- Baseline Teams TURN relay traffic patterns; alert on TURN relay connections from non-Teams processes or from servers that should not generate Teams traffic
8.19.75[.]217, 206.72.242[.]124, 206.72.242[.]162 at all perimeter firewalls — confirmed VeloCloud exploitation infrastructure.The Minnesota water system attacks represent a threshold event. For the first time, we have documented evidence of coordinated, simultaneous cyberattacks against multiple municipal water utilities in a single U.S. state. Whether the attack vector proves to be a shared vendor compromise or pre-positioned nation-state access, the implication is the same: municipal utilities under state oversight represent an unmonitored attack surface with cascading failure potential. Simultaneously, the ransomware ecosystem has achieved a capability combination — VPN zero-day access, autonomous worm propagation, and EDR neutralization — that defeats traditional layered defense assumptions. Network segmentation is no longer a "nice to have." It is the last reliable control when every other layer can be bypassed.