TLP:GREEN  ·  States / Public Sector
FSB Formally Attributed. Cisco Exploitation Active. Supply Chain Compromised.

Three Threats Converge. The CISA Deadline Is July 16.

ELEVATED. The EU and UK formally attributed the December 2025 Poland power grid attack to Russia's FSB Center 16 — the same unit actively scanning U.S. government routers today. A CISA deadline of July 16 mandates emergency remediation of CVE-2008-4128, an 18-year-old Cisco IOS vulnerability now under active exploitation that grants full administrative control of network devices. Simultaneously, five legitimate npm packages were trojanized in a supply chain attack now stealing cloud credentials and Kubernetes secrets from development pipelines. State government networks sit at the intersection of all three threats.

I am a
My sector

DevelopmentDateWhy It Matters for State Government
EU/UK formally attribute Poland power grid attack to FSB Center 16; 33+ individuals/entities sanctioned2026-07-13Same FSB unit confirmed scanning U.S. government routers via SNMP/Smart Install. Formal attribution signals escalation risk.
CVE-2008-4128 (Cisco IOS CSRF) added to CISA KEV — active exploitation confirmed2026-07-13Legacy IOS 12.4 devices with web management enabled are being exploited NOW. Grants full admin (privilege level 15). Deadline: 16 July.
CISA Advisory AA26-194a — FSB Center 16 router scanning campaign2026-07-13/1412-nation advisory confirms active global scanning of government routers exploiting Cisco Smart Install and SNMPv1/v2.
AsyncAPI npm supply chain compromise (Miasma variant) — 5 packages trojanized via compromised publisher credentials2026-07-14Steals AWS/Azure/GCP credentials, Kubernetes secrets, and deployment tokens. ~1,500 downloads before detection. C2: 85[.]137[.]53[.]71:8080
U.S. Treasury sanctions ransomware enablers (1VPNS, cryptor developer Yegeniy Silayev)2026-07-14Municipal governments explicitly named as victims. Validates sustained ransomware pressure on state/local government.
St. Paul, MN issues breach notification — one year post-ransomware2026-07-14Demonstrates the long regulatory tail of government ransomware incidents. Minnesota National Guard cyber team was activated.
Five CISA ICS advisories (Schneider Electric, Siemens, OpenPLC)2026-07-14Directly relevant to state-managed water/energy SCADA systems.
VOID MANTICORE (Iranian IRGC) confirmed breach of California water utility2026-06-12Iranian state actors targeting U.S. critical infrastructure alongside Russian threat activity — dual nation-state pressure on state-managed utilities.

DateEventActor / CVEImpact
2025-12Destructive DynoWiper attack on Poland's power gridFSB Center 16 (Turla/Berserk Bear)Attempted disruption of renewable energy communications; formally attributed Jul 13 2026
2025-07-25St. Paul, MN ransomware attack (breach notification issued July 2026)Unattributed ransomware groupEmployee PII exfiltrated; data posted publicly; National Guard activated
2026-06-12Confirmed destructive breach of California water utilityVOID MANTICORE (Iranian IRGC)Critical infrastructure compromise by Iranian state actor
2026-07-07CVE-2026-48282 (Adobe ColdFusion, CVSS 10.0) added to KEV; exploited within 2 hoursMultiple actorsRCE on citizen-facing government portals
2026-07-12Deadlock ransomware group activity update — government sector targetingDeadlock RaaSActive ransomware pressure on government sector
2026-07-13EU/UK sanctions FSB Center 16; CISA advisory AA26-194a published (12-nation)FSB Center 16Formal attribution + confirmed active scanning of government routers globally
2026-07-13CVE-2008-4128 added to KEV — active exploitation confirmed; deadline July 16UnattributedLegacy Cisco IOS 12.4 web management interfaces under active attack; full admin access granted
2026-07-13Akira ransomware group activity update — government sectorAkira RaaSContinued government sector pressure
2026-07-14AsyncAPI npm packages trojanized via compromised publisher credentials (Miasma variant)UnattributedCloud credential theft via supply chain; ~1,500 downloads; C2 live
2026-07-14U.S. Treasury sanctions 1VPNS + cryptor developer Yegeniy SilayevN/A (law enforcement)Municipal governments named as victims; ransomware enabler infrastructure disrupted
2026-07-14PRIMITIVEBEAR (Gamaredon) fresh IOCs publishedFSB-linked (Ukraine-targeting)Situational awareness — FSB ecosystem activity confirms broad operational tempo

The formal EU/UK attribution of the December 2025 Poland power grid attack to FSB Center 16 transforms intelligence community assessment into established fact. This unit (aliases: Turla, Berserk Bear, Venomous Bear) is actively scanning U.S. government routers using SNMPv1/v2 exploitation and Cisco Smart Install abuse. The 12-nation CISA advisory AA26-194a confirms this is a global campaign, not a regional European problem. DynoWiper — the destructive malware deployed against Poland — demonstrates this unit's willingness to move beyond espionage to destruction.

Also active this cycle in the broader FSB/GRU ecosystem: PRIMITIVEBEAR (Gamaredon/Shuckworm) with fresh IOCs published July 14, and APT28/GRU Unit 26165 (Fancy Bear) conducting active espionage operations.

T1078T1557T1190T1048T1485

CVE-2008-4128 is a Cross-Site Request Forgery vulnerability in Cisco IOS 12.4's web management interface. Successful exploitation grants privilege level 15 — full administrative control of the network device. CISA confirmed active exploitation and set a July 16 remediation deadline. Despite its age, this vulnerability remains relevant because state government networks commonly retain legacy Cisco devices in branch offices, remote facilities, and utility SCADA networks.

The convergence of three simultaneous Cisco-targeting campaigns creates concentrated risk: FSB Center 16 scanning via Smart Install and SNMP, CVE-2008-4128 exploitation of IOS web management, and ongoing Cisco SD-WAN targeting.

T1190T1068

On July 14, five legitimate @asyncapi npm packages were trojanized using compromised publisher credentials, bypassing traditional typosquatting detection entirely. The Rust-based Miasma infostealer targets AWS, GCP, and Azure credentials; Kubernetes secrets and deployment tokens; browser session cookies; and AI coding tool configurations (Cursor, VS Code). Approximately 1,500 downloads occurred before detection.

Affected packages: @asyncapi/specs@6.11.2, @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1. The C2 server at 85[.]137[.]53[.]71:8080 is live. Persistence artifacts: ~/.config/.miasma/run/node.lock, miasma-monitor.service (systemd), HKCU\Run\miasma-monitor (Windows).

T1195.002T1555T1539T1547.001T1059.007

Four ransomware groups remain simultaneously active against the government sector: Deadlock, Akira, BITWISE SPIDER, and WARLOCK SPIDER (TA505). The U.S. Treasury's sanctioning of 1VPNS and cryptor developer Yegeniy Silayev confirms that municipal governments are explicitly named victims of ransomware operations enabled by these services.

The St. Paul, Minnesota breach notification — issued one year after the original attack — illustrates the extended lifecycle of government ransomware incidents: operational disruption, data exfiltration, public leak, National Guard activation, regulatory notification, and ongoing identity protection obligations.

T1486T1021.001T1567T1090

Five ICS advisories published this cycle affect systems commonly deployed in state-managed utilities: Schneider Electric Easergy MiCOM Px40 (protection relays), Schneider Electric PowerChute Serial Shutdown (UPS management), OpenPLC (open-source PLC platform), Hitachi PROMOD V (power system modeling), and Siemens SINEC OS (network management).

Combined with the FSB Center 16 attribution for the Poland power grid attack and the June 2026 VOID MANTICORE breach of a California water utility, state-managed critical infrastructure faces threats from both Russian and Iranian state actors simultaneously.

T0831T1190T1485

ScenarioProbabilityBasis
Additional Cisco IOS exploitation attempts against state networks as CVE-2008-4128 KEV listing draws attacker attentionHIGH (>70%)KEV listings historically trigger scanning spikes within 48–72 hours; deadline pressure increases attack surface visibility
FSB Center 16 scanning activity increases against U.S. state government routers following sanctions (retaliatory posture)MODERATE (40–60%)Historical pattern: sanctions trigger escalation in cyber operations rather than deterrence
Additional npm/supply chain compromises surface as Miasma campaign expands beyond @asyncapi packagesMODERATE (40–60%)Multiple packages compromised, rapid iteration, and IPFS-based staging suggest active ongoing campaign
China-nexus APT activity (Volt Typhoon/Salt Typhoon) emerges against state infrastructureMODERATE (40–60%)Absence of visible activity despite geopolitical tensions is anomalous; living-off-the-land techniques may be evading detection
Direct ransomware incident against a state government agency within 7 daysLOW-MODERATE (20–40%)Ecosystem pressure is high but no direct targeting indicators observed this cycle
Municipal government downstream compromise via state shared services connectionsMODERATE (40–60%)St. Paul and Bar Harbor incidents demonstrate active municipal targeting; shared service connections create lateral movement paths

Cisco Infrastructure Exploitation (CVE-2008-4128 + Smart Install + SNMP):

Monitor for HTTP/HTTPS connections TO Cisco device management interfaces from non-administrative workstations. Alert on requests to /level/15/exec/- and /level/15/exec/-/configure/http — these are the CSRF target paths for CVE-2008-4128 exploitation. Alert on inbound SNMP queries (UDP 161/162) from external sources. Monitor for Smart Install protocol traffic (TCP 4786) — this should never originate externally. Alert on any IOS device configuration changes not correlated with approved change windows. Hunt for TFTP transfers from network devices to unknown destinations.

AsyncAPI Miasma Supply Chain:

Alert immediately on network connections to 85[.]137[.]53[.]71:8080 from any internal host. Monitor for IPFS gateway connections from developer workstations (anomalous pattern). Endpoint: hunt for sync.js in NodeJS platform data directories; persistence artifacts ~/.config/.miasma/run/node.lock, miasma-monitor.service (systemd), HKCU\Run\miasma-monitor (Windows); build label string miasma-train-p1 in process memory or on disk. Block execution of sync.js from NodeJS data directories via application control.

Ransomware Precursor Activity:

Monitor for netscan.exe and netscanpack.exe execution (network discovery tools commonly used pre-encryption). Alert on mountvol.exe execution outside IT maintenance windows. Monitor for Raccine.exe — an anti-ransomware tool that attackers specifically attempt to disable. Detect mass file encryption patterns: high-volume file rename operations with new extensions. Enforce application allowlisting on servers; restrict RDP to jump servers only.

Nation-State Malware Families:

Priority watchlist for this cycle: DynoWiper (FSB Center 16, destructive ICS/energy wiper); STEALC / LUMMAC (infostealers targeting credentials); XWORM / ASYNCRAT (commodity RATs used against government). Deploy YARA/EDR rules for PRIMITIVEBEAR SHA-1 and MD5 indicators in the IOC table below.

ThreatATT&CK
Cisco IOS CSRF (CVE-2008-4128)T1190 T1068
FSB Center 16 SNMP / Smart Install scanningT1557 T1018 T1190
AsyncAPI Miasma supply chainT1195.002 T1555 T1539 T1547.001
Ransomware precursor activityT1486 T1021.001 T1567
Nation-state malware families (DynoWiper, Miasma)T1485 T1071 T1059.007
IOC Blocking Table:
85[.]137[.]53[.]71 fa7a9c86744c233efa9289e919ec1ebb66e1ee84 8096dfaa954113242011e0d7aaaebffd f873941d1907a97dc6c718fdecf59fd7d91f3f82... 9e214f38537e69bf51c7fa1ddd35ae495e9cb897...

85[.]137[.]53[.]71 (port 8080) — Miasma C2 server; block at all perimeter firewalls and proxy. SHA-1 fa7a9c86744c233efa9289e919ec1ebb66e1ee84 and MD5 8096dfaa954113242011e0d7aaaebffd — PRIMITIVEBEAR (Gamaredon/FSB). SHA-256 f873941d1907a97dc6c718fdecf59fd7d91f3f8212da2f7e5314b878b88bdc0b — Miasma supply chain (specs build). SHA-256 9e214f38537e69bf51c7fa1ddd35ae495e9cb897231ec010baf9e4f29407ee9a — Miasma supply chain (generator build). Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
Is an adversary exploiting CVE-2008-4128 against Cisco IOS web management interfaces?
Search web server logs on Cisco management hosts for requests to /level/15/exec/-. Hunt for admin-level configuration changes on IOS devices from non-management source IPs. Correlate with any user activity that could have triggered a CSRF lure (email click, web browse from admin workstation).
HUNT 02 · T1557
Is FSB Center 16 already inside a state network device via SNMP or Smart Install?
Search for TFTP transfers originating from routers/switches to external destinations. Hunt for SNMP authentication failures followed by successful auth from the same source (brute-force pattern). Check for unexpected configuration archive files on TFTP servers. Any device still on SNMPv1/v2 with default community strings should be treated as potentially compromised.
HUNT 03 · T1195.002
Is a developer workstation infected with Miasma, beaconing to C2 and exfiltrating cloud credentials?
Search for any historical or current DNS/network connections to 85[.]137[.]53[.]71. Hunt for sync.js in NodeJS platform directories on developer machines. Check cloud provider audit logs (AWS CloudTrail, Azure Activity Log, GCP Audit Logs) for anomalous API calls from developer machine IPs or unexpected geographic locations since July 14.
HUNT 04 · T1486
Is a ransomware operator conducting pre-encryption reconnaissance in state/municipal networks?
Search for netscan.exe or netscanpack.exe execution in the past 14 days. Hunt for mountvol.exe used outside of IT maintenance windows. Look for bulk shadow copy deletion (vssadmin delete shadows) or wbadmin delete catalog commands — these are immediate pre-encryption signals.

Financial Services
State Treasury, Revenue, Pension Systems
Primary threat
Miasma supply chain compromise stealing AWS/Azure credentials from development pipelines supporting treasury and revenue applications; 1VPNS-enabled ransomware explicitly naming financial sector victims
Secondary threat
Credential theft from developer workstations enabling access to cloud-hosted financial systems
Actions
  • Audit all development pipelines for @asyncapi package usage; isolate affected workstations and rotate all cloud credentials
  • Enforce hardware security keys for all cloud administrative access; review Azure Conditional Access policies for token theft indicators
  • Verify offline backups of financial databases are tested and current
Energy
State-Managed Utilities, Grid Coordination
Primary threats
FSB Center 16 demonstrated willingness to deploy destructive DynoWiper against power grid infrastructure; VOID MANTICORE (Iranian IRGC) breached a U.S. water utility in June 2026 — dual nation-state threat
Secondary threat
Five ICS advisories this cycle: Schneider Electric Easergy MiCOM Px40, PowerChute, OpenPLC, Hitachi PROMOD V, Siemens SINEC OS
Actions
  • Immediately audit all SCADA/ICS network segments for SNMPv1/v2 exposure and Cisco Smart Install presence
  • Review Schneider Electric and Siemens deployments against CISA ICS advisories; ensure OT networks are air-gapped or segmented with unidirectional gateways
  • Monitor for DynoWiper behavioral indicators — mass file deletion/overwrite patterns targeting OT configuration files
Healthcare
Health Agencies, Medicaid Systems
Primary threat
Ransomware groups Akira and Deadlock actively targeting healthcare; 1VPNS-enabled ransomware explicitly victimized U.S. hospitals
Secondary threat
Healthcare development teams using npm packages for patient portal development may be exposed to Miasma supply chain compromise
Actions
  • Verify Medicaid claims processing and EHR integrations have immutable backups with tested restoration procedures
  • Ensure medical device networks are segmented from administrative IT
  • Review IR plans for HIPAA breach notification timelines — compare to St. Paul's one-year notification delay as a cautionary precedent
Government
Executive Branch, Law Enforcement, Courts
Primary threat
Multi-vector: FSB Center 16 espionage via router compromise, ransomware via RDP/phishing, Miasma supply chain via developer tooling
Secondary threat
CJIS-connected systems at elevated risk given FSB interest in government networks; law enforcement databases require enhanced monitoring
Actions
  • Conduct emergency inventory of all Cisco IOS 12.4 devices across agency networks — many exist in branch offices and remote facilities forgotten by central IT
  • Enforce MFA on all VPN and remote access; brief agency heads on the St. Paul precedent
  • Audit CJIS terminal access logs for anomalous patterns; ensure law enforcement networks are segmented from general IT infrastructure
Aviation / Logistics
State DOT, Airport Authorities, Port Systems
Primary threat
Nation-state pre-positioning in transportation infrastructure for potential disruption during geopolitical escalation — Volt Typhoon pattern with living-off-the-land techniques evading standard detection
Secondary threat
Cisco networking equipment in DOT traffic management and airport/port OT networks exposed to FSB scanning campaigns
Actions
  • Audit all Cisco networking equipment in DOT traffic management systems and airport/port OT networks for Smart Install and SNMP exposure
  • Conduct proactive threat hunts for anomalous use of legitimate Windows utilities (PowerShell, WMI, certutil) in transportation OT environments
  • Focus detection on T1218 (System Binary Proxy Execution) and T1036 (Masquerading) in transportation network segments
No sector cards match the selected filters.

Disable HTTP/HTTPS management on ALL Cisco IOS 12.4 devices. CVE-2008-4128 is under active exploitation with a July 16 CISA deadline. If web management is operationally required, restrict access via ACL to a dedicated management subnet only.
Incident ResponderICS / OT
Disable SNMPv1 and SNMPv2 on all network devices. Migrate to SNMPv3 with authentication and encryption (authPriv). FSB Center 16 is actively scanning for these protocols per CISA AA26-194a.
Incident ResponderICS / OT
Disable Cisco Smart Install on all switches and routers (no vstack). Block TCP 4786 at all perimeter firewalls. This is a confirmed FSB Center 16 exploitation vector per the 12-nation advisory.
Incident ResponderICS / OT
Block C2 IP 85[.]137[.]53[.]71 at perimeter firewalls and proxy. Alert on any historical connections to this address from developer workstations. This is the live Miasma C2 server.
SOC Analyst
Audit all CI/CD pipelines for @asyncapi packages at versions 6.11.2, 3.3.1, 1.1.1, or 0.7.1. If found: isolate affected workstations, rotate ALL cloud credentials and deployment tokens accessible from those systems, and revoke active sessions immediately.
Incident ResponderIAM Analyst
No immediate actions for the selected roles.
Deploy all IOCs from the blocking table to EDR and network detection platforms. Implement hunting queries for Miasma persistence artifacts (miasma-monitor.service, node.lock, HKCU\Run\miasma-monitor) across all developer workstations.
SOC AnalystThreat Hunter
Complete full inventory of Cisco IOS device versions across all agency networks, including branch offices and remote facilities. Identify any remaining IOS 12.x devices for emergency upgrade or decommission.
Incident Responder
Brief agency leadership on FSB Center 16 attribution and sanctions context. State government network infrastructure is in the same target set as European critical infrastructure. Sanctions historically trigger escalation, not deterrence.
CISO / Exec
Implement npm package integrity verification: enforce package-lock.json, enable npm audit signatures, and pin critical dependencies to specific commit SHAs rather than version ranges in all development pipelines.
Incident ResponderIAM Analyst
Review and update incident response notification timelines. The St. Paul case demonstrates breach notification obligations extend 12+ months post-incident. Ensure compliance with your state's breach notification statute before the next incident.
Incident ResponderCISO / Exec
No 7-day actions for the selected roles.
Commission assessment of Cisco infrastructure concentration risk. Three active threat campaigns target Cisco products simultaneously — evaluate architectural diversity and vendor diversification for critical network segments.
CISO / Exec
Review ICS/SCADA patching posture for Schneider Electric Easergy MiCOM Px40, PowerChute Serial Shutdown, and Siemens SINEC OS per CISA ICS advisories published this cycle.
ICS / OTCISO / Exec
Develop a unified developer-workstation security policy addressing supply chain risk: mandatory endpoint detection, restricted outbound network access, credential isolation (no production cloud credentials on development machines), and package provenance verification.
CISO / ExecIAM Analyst
Assess security controls protecting municipal government tenants on state shared services. Both St. Paul, MN and Bar Harbor, ME incidents demonstrate that municipal governments connected to state infrastructure are actively targeted and represent lateral movement paths.
CISO / ExecIncident Responder
Evaluate National Guard cyber unit engagement protocols. Minnesota activated the 177th Cyber Protection Team for the St. Paul incident. Ensure your state has pre-established activation procedures and exercises with its cyber unit — do not negotiate this for the first time during an incident.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The intelligence picture this week is unambiguous: Russian state actors have been formally attributed for destructive attacks on allied power grids and are actively scanning U.S. government routers using those same techniques. An 18-year-old Cisco vulnerability is being exploited in the wild with a 48-hour CISA deadline. A supply chain attack is actively stealing cloud credentials from development environments right now. State government networks sit at the intersection of all three threats simultaneously — you run the Cisco infrastructure FSB is scanning, you maintain the legacy systems 18-year-old vulnerabilities can compromise, and your development teams use the npm packages that were trojanized today.

1
Disable HTTP/HTTPS web management on every Cisco IOS 12.4 device today. The CISA deadline is July 16 — not next week, not after the next change window.
2
Migrate all network devices from SNMPv1/v2 to SNMPv3 within 7 days. FSB Center 16 is scanning for you right now. Every device still on SNMPv1/v2 is an open invitation.
3
Isolate and credential-rotate any workstation that ran @asyncapi packages at compromised versions. Block 85[.]137[.]53[.]71 at the perimeter. The Miasma C2 is live.
No items found.