TLP:GREEN  ·  States / Public Sector
Oracle WebLogic CVSS 10.0 Mandated for 72-Hour Patch, Zimbra Mass Exploitation Confirmed:

AI-Powered Credential Theft Hits M365 — What State CISOs Must Do Now

ELEVATED. Elevated from prior GUARDED posture based on three converging high-severity events within a single 24-hour window: a CVSS 10.0 vulnerability with an unprecedented 3-day federal patching mandate, confirmed mass exploitation of 274 Zimbra email servers globally, and the emergence of an AI-powered Phishing-as-a-Service platform actively stealing Microsoft 365 sessions.

I am a
My sector

DateDevelopmentSignificance
2026-08-24CISA adds CVE-2026-21962 (Oracle WebLogic, CVSS 10.0) to KEV with 3-day patch deadlineFirst-ever 72-hour mandate; state agencies under BOD 22-01 must comply by ~Aug 27
2026-08-25Shadowserver confirms 274 Zimbra servers compromised via CVE-2026-73570Mass exploitation confirmed; any agency running ZCS < 10.1.20 is at immediate risk
2026-08-25Flare documents "EvilTokens" PhaaS — OAuth device code theft + AI mailbox analysis344 organizations hit in 16 days; AI automates BEC target selection post-compromise
2026-08-25ClickFix campaign uses Google Sites to impersonate OpenAI Codex, delivers AMOS stealerDeveloper workstations targeted via social engineering; macOS credential theft
2026-08-19 (ongoing)CISA Advisory AA26-231A — active threat to Siemens S7 PLCs across 7+ statesIran-linked ICS targeting continues; extends beyond Siemens to all PLC platforms
2026-08-18 (ongoing)MuddyWater (UNC5667) attributed to Siemens S7 PLC intrusionsMOIS-affiliated actors confirmed targeting U.S. water/wastewater infrastructure

DateActor / CampaignTargetImpact
2026-07-20—Zimbra users globallyCVE-2026-73570 patch released (ZCS 10.1.20)
2026-07-26IRGC-affiliated groupsU.S. wastewater facilities (12 states)ICS disruption operations begin
July 2026Iran-linked hackersUK power plant4-day shutdown (disclosed Aug 22)
2026-08-18MuddyWater / UNC5667Siemens S7 PLCs (7+ states)CISA AA26-231A attribution
2026-08-19CISAAll PLC operatorsFormal advisory: active threat to S7 series
2026-08-21CISAZimbra operatorsCVE-2026-73570 added to KEV
2026-08-24CISAOracle WebLogic operatorsCVE-2026-21962 added to KEV (3-day deadline)
2026-08-25EvilTokens PhaaSM365 organizations (344 confirmed)OAuth device code theft + AI-driven BEC
2026-08-25Unknown (criminal)macOS developersClickFix via Google Sites → AMOS stealer
2026-08-25ShadowserverZimbra servers globally274 confirmed compromises

This is a perfect-score vulnerability in the Oracle HTTP Server / WebLogic Server Proxy Plug-in affecting versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0. An unauthenticated remote attacker achieves full confidentiality and integrity compromise with scope change — meaning systems behind the proxy are also exposed.

Why this matters for state government: Oracle Fusion Middleware underpins many state ERP, procurement, HR, and financial systems. The proxy plug-in is the network entry point — not the application itself. Many agencies may not even have accurate inventory of which systems use this component.

Regulatory pressure: CISA's 3-day deadline is unprecedented. Standard state IT change management processes are not designed for 72-hour windows. Non-compliance with BOD 22-01 begins approximately August 27.

T1190T1071.001

The vulnerability resides in the zimbra-snmp package — improper sanitization during SNMP notification processing allows unauthenticated remote code execution via crafted SMTP requests. Patched in ZCS v10.1.20 (released July 20, 2026), but 274 servers are already confirmed compromised as of today.

Why this matters for state government: Zimbra is commonly deployed by smaller agencies, county offices, and legacy environments that have not migrated to M365. These are often the least-resourced IT shops with the slowest patch cadences.

T1190T1059.004T1505.003

EvilTokens is a criminal platform sold via Telegram since February 2026 that combines OAuth device code phishing with AI-driven post-compromise analysis. The attack flow: a victim receives a phishing message with a legitimate Microsoft device code login prompt; the victim authenticates normally and the attacker captures the session token; AI analyzes the compromised mailbox to identify payment approvers, map financial workflows, and generate tailored BEC messages; then automated fraud execution proceeds at scale.

344 organizations across 5 countries were compromised in a 16-day wave. The AI component lowers the skill barrier for sophisticated financial fraud — operators no longer need to manually triage victims.

Why this matters for state government: state employees process billions in payments (vendor contracts, benefits, payroll). AI-driven target selection means attackers will automatically identify the highest-value targets in a compromised mailbox — comptrollers, procurement officers, benefits administrators.

T1566.002T1528T1114.002

CISA Advisory AA26-231A (August 19) confirms an active threat to Siemens S7 Series PLCs, with MuddyWater (UNC5667, MOIS-affiliated) attributed to intrusions affecting 7+ states. The advisory explicitly notes targeting extends beyond Siemens to all PLC platforms. This follows IRGC-affiliated groups attacking wastewater facilities across 12 states beginning July 26 and the Iran-linked shutdown of a UK power plant disclosed August 22.

Why this matters for state government: state agencies operate water treatment, wastewater, transportation management, and building automation systems using PLCs. The DOJ indictment of 17 IRGC-affiliated hackers raises the probability of retaliatory operations.

T0831T0836T0855T0886

A campaign uses paid Google search ads to direct macOS users to Google Sites pages impersonating OpenAI Codex downloads. The "ClickFix" technique instructs victims to paste a Terminal command that delivers Atomic macOS Stealer (AMOS). Infrastructure includes bright-links[.]com, trekmesh15[.]com, and grove-12[.]com.

Why this matters for state government: developer and IT staff workstations running macOS are the primary targets. Credential theft from privileged IT accounts can enable lateral movement into enterprise systems.

T1204.002T1059.004T1027.010

ScenarioProbabilityTimeframeBasis
Exploitation attempts against Oracle WebLogic increase significantly as PoC circulates and 3-day deadline creates defender urgency>75% (HIGH)72 hoursHistorical Citrix/Oracle exploitation cadence; PoC already public
EvilTokens campaigns expand to target government sector specifically50–75% (MODERATE)7–14 daysAI-driven target selection + low barrier to entry; government payment workflows are high-value
Compromised Zimbra servers weaponized for lateral movement or data exfiltration50–75% (MODERATE)7 days274 servers already compromised; post-exploitation typically follows within days
Retaliatory Iranian ICS operations against U.S. critical infrastructure following DOJ indictments40–60% (MODERATE)30 daysHistorical pattern of Iranian retaliation post-indictment; active capability confirmed
State agency compromised via unpatched Oracle WebLogic before Aug 27 deadline30–50%72 hoursDepends on state Oracle Middleware footprint; many agencies unaware of proxy plug-in exposure

PriorityWhat to MonitorATT&CK IDDetection Logic
CRITICALOAuth device code authentication grants in Entra IDT1528Alert on grant_type=urn:ietf:params:oauth:grant-type:device_code + unfamiliar device ID + subsequent Graph API mailbox access within 60 minutes
CRITICALOracle WebLogic Proxy Plug-in exploitation attemptsT1190WAF/IDS signatures for malformed proxy requests to Oracle HTTP Server ports; monitor for unexpected child processes spawned by Oracle httpd
HIGHZimbra SNMP-based exploitationT1190, T1059.004Alert on crafted SMTP traffic to Zimbra instances containing SNMP notification payloads; monitor for shell execution by zimbra-snmp process
HIGHClickFix Terminal paste executionT1204.002, T1059.004EDR alert on curl piped to sh/bash on macOS; xattr -c on executables in /tmp/; outbound connections to IOC domains
MODERATEPLC access from IT network segmentsT0886Firewall logs showing any traffic from IT VLANs to OT/ICS subnets on Siemens S7 ports (TCP 102) or other PLC programming ports
IOC Blocking Table:
bright-links[.]comtrekmesh15[.]comgrove-12[.]com

ClickFix delivery/telemetry infrastructure — block at DNS and web proxy. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01
Hypothesis: OAuth device code tokens already issued to attacker-controlled devices.
Hunt in Entra ID sign-in logs for device code grants in the past 30 days where the device is not enrolled in Intune/MDM. Correlate with subsequent mailbox access patterns (bulk email read via Graph API).
HUNT 02
Hypothesis: Zimbra web shells deployed on state-managed instances.
If any agency runs Zimbra, hunt for new .jsp or .php files in web-accessible directories created after July 20 (patch date). Check for outbound connections from Zimbra servers to unfamiliar IPs.
HUNT 03
Hypothesis: Oracle WebLogic proxy plug-in exposed to internet.
Asset discovery scan for Oracle HTTP Server instances on ports 80/443 with proxy plug-in headers. Cross-reference with patch status from Oracle CPU January 2026.
HUNT 04
Hypothesis: Lateral movement from compromised developer macOS workstations.
Hunt for new SSH key additions, VPN connections from unusual geolocations, or Kerberos ticket requests from macOS endpoints that typically don't authenticate to AD.

Financial Services
State Treasury, Comptroller, Procurement
Primary threat
EvilTokens AI-powered BEC targeting payment approval workflows.
Secondary threat
Oracle WebLogic compromise of financial ERP systems.
Actions
  • Implement out-of-band verification for all payment changes >$10,000
  • Enable Conditional Access policies requiring compliant devices for Graph API access
  • Review Entra ID for device code grants in the past 30 days
  • Conduct an emergency inventory of Oracle Fusion Middleware versions in financial applications
Energy
State-Operated Utilities, Environmental Agencies
Primary threat
Iran-linked PLC targeting — MuddyWater/UNC5667 (MOIS-affiliated) confirmed in S7 intrusions; separate IRGC-affiliated groups conducting broader wastewater disruption operations.
Secondary threat
Supply chain compromise via engineering workstation.
Actions
  • Validate IT/OT network segmentation — no direct path from corporate network to PLC programming interfaces
  • Audit Siemens S7 firmware versions; enable logging on OT firewalls and forward to SOC
  • Restrict USB and removable media on OT engineering workstations
  • Conduct a tabletop exercise for an ICS disruption scenario within 30 days
Healthcare
State Health Agencies, Medicaid Systems, Public Health Labs
Primary threat
Ransomware (Qilin/REVENANT SPIDER historically targeting healthcare) and credential theft for PHI access.
Secondary threat
Zimbra exploitation at county health departments.
Actions
  • Verify offline backup integrity for Medicaid claims systems and EHR platforms
  • Ensure MFA is enforced on all remote access to health data systems
  • Survey county/local health agencies for Zimbra usage; provide patching guidance and a shared services migration path
Government
Executive Branch Agencies, Legislature, Courts
Primary threats
M365 credential theft (EvilTokens, iAuthFlow v2) leading to BEC or data exfiltration.
Secondary threat
Oracle WebLogic exploitation of shared services infrastructure.
Actions
  • Block OAuth device code flow via Conditional Access for all users except explicitly approved service accounts
  • Enable Continuous Access Evaluation (CAE) in Entra ID
  • Deploy phishing-resistant MFA (FIDO2 hardware keys) for executives and financial approvers
  • Coordinate centralized patch management across agencies; identify all Oracle HTTP Server instances in shared hosting environments
Aviation / Logistics
State DOT, Airport Authorities, Port Operations
Primary threat
ICS/SCADA targeting of transportation management systems and traffic control.
Secondary threat
Supply chain compromise via logistics software vendors.
Actions
  • Audit network segmentation between traffic management systems and corporate IT
  • Validate that SCADA HMI systems are not directly internet-accessible
  • Review remote access credentials for transportation control systems
  • Ensure vendor VPN accounts use MFA and are time-limited
No sector cards match the selected filters.

Patch Oracle WebLogic Proxy Plug-in (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) per the CISA BOD 22-01 mandate. If patching cannot be applied within 72 hours, disable the proxy plug-in or restrict network access to affected hosts. Non-compliance begins ~August 27.
Incident Responder
Audit all Zimbra instances across state agencies. Confirm ZCS version ≥ 10.1.20. If zimbra-snmp is installed with SNMP notifications enabled, disable notifications immediately pending upgrade.
Incident Responder
Block OAuth device code flow in Entra ID Conditional Access for all users. Create exceptions only for documented, approved service accounts. This neutralizes EvilTokens and similar OAuth phishing.
IAM Analyst
Deploy detection for device code authentication grants followed by Graph API mailbox access. Alert on this pattern for immediate investigation.
SOC Analyst
Report Oracle and Zimbra exposure within 24 hours to the central CISO office. Confirm versions, patch status, and internet accessibility.
CISO / Exec
No immediate actions for the selected roles.
Deploy endpoint detection for ClickFix indicators: base64-decoded curl piped to shell, xattr -c on executables in /tmp/, outbound connections to bright-links[.]com, trekmesh15[.]com, grove-12[.]com. Block these domains at DNS and web proxy.
SOC Analyst
Validate Siemens S7 PLC firmware versions and access controls per CISA AA26-231A. Confirm PLC programming ports are unreachable from the IT network. Audit IT/OT firewall rules.
ICS / OT
Enable Continuous Access Evaluation (CAE) in Entra ID to revoke sessions in near-real-time when risk signals are detected.
IAM Analyst
Authorize emergency procurement of an alternative OSINT intelligence feed (30-day trial minimum) to restore corroboration capability. The current 11-day gap in open-source collection is degrading analytical confidence.
CISO / Exec
No 7-day actions for the selected roles.
Develop an emergency patch SLA for CISA 3-day mandates. Current change management processes cannot meet 72-hour windows. Propose a pre-authorized emergency change category for CVSS 10.0 + KEV entries.
CISO / Exec
Commission a tabletop exercise for an ICS disruption scenario — simulate Iran-linked PLC manipulation at a state water treatment facility. Include OT operators, IT security, emergency management, and executive leadership.
CISO / ExecIncident Responder
Deploy phishing-resistant FIDO2 hardware security keys for all users with financial approval authority, executive leadership, and IT administrators. This eliminates the entire class of session theft attacks (EvilTokens, iAuthFlow, AiTM).
IAM Analyst
Conduct a full Oracle Middleware asset inventory including proxy plug-in versions across all agencies. Many instances are undocumented in CMDBs.
Incident Responder
Evaluate a Zimbra migration path for remaining agencies — consolidate to a managed M365 tenancy to eliminate the legacy email attack surface.
CISO / Exec
Brief the Governor's office on BOD 22-01 compliance risk — the 3-day mandate may not be achievable for all agencies; leadership needs to understand the compliance gap.
CISO / Exec
Pre-position an incident response retainer for Oracle WebLogic compromise — if exploitation occurs before patching, IR engagement must begin within hours, not days.
CISO / ExecIncident Responder
Review cyber insurance coverage for BEC/wire fraud — EvilTokens' AI-driven BEC creates elevated financial fraud risk for state payment systems.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Three simultaneous high-severity threats are converging on state government infrastructure today. The Oracle WebLogic CVSS 10.0 patch deadline is not negotiable — the 72-hour clock began August 24. Zimbra exploitation is already confirmed at scale, and any unpatched instance should be treated as potentially compromised. EvilTokens has demonstrated that AI-driven credential theft can industrialize financial fraud against exactly the payment workflows that state government operates. Blocking OAuth device code flow in Entra ID is a single policy change that eliminates this entire attack class. What makes this week's threat landscape particularly dangerous for state government is not any single vulnerability — it's the convergence. Adversaries are simultaneously targeting legacy middleware that runs financial systems, alternative email platforms used by resource-constrained agencies, cloud identity that connects the entire workforce, and industrial control systems that operate physical infrastructure. State government's attack surface spans all four categories, and the adversaries know it.

1
Act on the IMMEDIATE items today.
2
Brief your agency CIOs tomorrow.
3
The 72-hour clock is already running.
No items found.