| Development | Date | Why It Matters |
|---|---|---|
| CISA/NSA Joint Advisory AA26-204A — Russian state actors actively phishing Zimbra Collaboration Suite users | 2026-07-23 | Multiple state agencies still operate Zimbra — this is a direct, confirmed threat to state attack surface |
| CVE-2026-16232 (Check Point SmartConsole auth bypass, CVSS 9.1) confirmed actively exploited; added to KEV | 2026-07-22 | Attacker gains full admin privileges and can silently rewrite firewall policies |
| Storm-2603 (China-nexus) confirmed exploiting SharePoint with LockBit Black + Warlock dual ransomware via four CVEs | 2026-07-24 | State agencies running unpatched on-premises SharePoint are directly vulnerable to an active campaign |
| 7 ICS advisories published — Johnson Controls C-CURE 9000 RCE (ICSA-26-204-01) and Rockwell ThinManager file write (ICSA-26-204-05) | 2026-07-23 | C-CURE 9000 controls physical access to state buildings; Rockwell systems run water and transportation infrastructure |
| Hermes AI agent used for autonomous post-exploitation against Thailand Ministry of Finance — first confirmed government case | 2026-07-24 | Machine-speed post-exploitation compresses SOC detection windows from hours to minutes; tool is open-source with no kill switch |
| Golden Chickens MaaS resurfaces with ClickFix delivery and ChromEggscalator Chrome session hijacking | 2026-07-24 | Sector-agnostic credential theft; ChromEggscalator bypasses traditional phishing detection — no malicious link required |
| Date | Event | Actor / CVE | Impact |
|---|---|---|---|
| 2026-07-22 | CVE-2026-16232 added to CISA KEV catalog | Check Point / CISA | Unauthenticated firewall policy rewrite; CVSS 9.1 |
| 2026-07-22 | CVE-2026-41940 (cPanel/WHM auth bypass) added to KEV; ~6,100-node GitHub Actions botnet confirmed | CISA | Dual KEV additions in one day; botnet-scale exploitation confirmed |
| 2026-07-23 | CISA/NSA Joint Advisory AA26-204A — Russian state Zimbra phishing campaign | Russian state (likely GRU/FSB) | Direct targeting of government webmail; state agencies are in-scope |
| 2026-07-23 | 7 ICS advisories published (C-CURE 9000, ThinManager, Panduit IntraVUE, libIEC61850) | CISA / Vendor disclosures | RCE in building access control; file write in water/transportation SCADA |
| 2026-07-23 | ConnectWise/Action1 RMM phishing campaigns confirmed active | Criminal operators | Legitimate RMM tools weaponized as RATs against government targets |
| 2026-07-24 | Storm-2603 SharePoint dual ransomware (LockBit Black + Warlock) confirmed — ak47c2 C2 framework | Storm-2603 (China-nexus, CVE-2025-49704/49706/53770/53771) | Active exploitation of four SharePoint CVEs with BYOVD AV kill |
| 2026-07-24 | Golden Chickens resurfaces — TinyEgg, ChonkyChicken, ChromEggscalator | Golden Chickens / Venom Spider | ClickFix social engineering delivering Chrome DevTools session hijack |
| 2026-07-24 | Hermes AI agent autonomous post-exploitation against Thai Ministry of Finance confirmed | Chinese-speaking operator (Hong Kong IP 103.97.0[.]57) | First confirmed AI-autonomous offensive operation against government |
Actors: Russian state-supported, likely GRU or FSB, based on historical Zimbra campaign attribution. CISA/NSA published this advisory with DoD co-authorship — a signal of high confidence and urgency. Russian state actors have a documented history of targeting Zimbra since 2022–2023 (APT28/Fancy Bear).
What they're doing: Credential harvesting via spearphishing links leading to Zimbra webmail interface exploitation. Every day a Zimbra instance remains operational without MFA and current patches is accepted risk against a confirmed nation-state campaign. State agencies that still operate Zimbra for legacy mail are directly in the crosshairs.
Status: Actively exploited, CISA KEV. An unauthenticated remote attacker obtains an application login token, gains full administrative privileges, and can silently rewrite firewall security policies and configurations — opening paths for lateral movement, disabling inspection, or creating persistent backdoors in your perimeter security without triggering alerts from the firewall itself.
Check Point confirms exploitation affecting a small number of customers, but the KEV listing means federal agencies must patch within prescribed timelines. State agencies should treat this with equivalent urgency. Apply hotfix sk185169 if the Management Server is internet-exposed; if not, confirm Trusted Client restrictions are enforced.
Actors: Storm-2603, China-based (medium confidence), associated with Linen Typhoon (APT27) and Violet Typhoon (APT31). Exploiting CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 in SharePoint Server. Deploying LockBit Black and Warlock/x2anylock simultaneously via the ak47c2 framework with HTTP and DNS tunneling.
Three compounding risk factors: (1) Dual ransomware is a hedging strategy — if EDR catches one strain, the other may execute. (2) BYOVD driver (ServiceMouse.sys) kills AV processes before payload delivery. (3) China-nexus actors deploying ransomware blurs espionage and criminal boundaries — response must address both data theft and availability impact simultaneously. SharePoint Server is ubiquitous in state government. Unpatched instances are directly vulnerable; campaign currently confirmed in LATAM and APAC with high expansion probability.
Seven ICS advisories published 23 July 2026 include vulnerabilities with direct state government exposure:
- Johnson Controls C-CURE 9000 (ICSA-26-204-01): Remote code execution via network access. C-CURE 9000 controls physical access to state buildings — badge readers, door locks, visitor management. RCE enables unlocking doors, disabling alarms, or denying facility access.
- Rockwell Automation ThinManager (ICSA-26-204-05): Arbitrary file write (authenticated). ThinManager is deployed in state water treatment and transportation SCADA. File write enables implant deployment on thin client management infrastructure.
- Panduit IntraVUE (ICSA-26-204-04): IT-to-OT manipulation. If compromised, this network visibility tool becomes a pivot from IT networks into operational technology.
- MZ Automation libIEC61850 (ICSA-26-204-06): Unauthenticated crash of IEC 61850 services — the protocol underpinning substation automation.
A threat actor deployed the open-source Hermes AI agent in "YOLO mode" (all approval prompts disabled) for autonomous post-exploitation against Thailand's Ministry of Finance. The agent independently performed privilege escalation scanning, filesystem enumeration, and personnel record crawling — without human operator approval per action. Attribution indicators point to a Chinese-speaking operator (SSH from Hong Kong IP 103.97.0[.]57, FOFA API key, ShadowPad/VShell C2 history).
Why this changes the threat model for state government: Human attackers operate at human speed. An AI agent executes reconnaissance-to-exfiltration in minutes. There is no vendor kill switch — Hermes runs locally and cannot be account-banned. The operator's custom LinPEAS variant checks for CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, and CVE-2026-43503 automatically. State Linux servers with unpatched kernels are vulnerable to the same automated escalation chain. This is the first confirmed AI-autonomous offensive operation against a government target. It will not be the last.
Actors: Golden Chickens / Venom Spider / TAG-195 (developer); historical customers include Cobalt Group, Evilnum, and FIN6. New malware families: TinyEgg, ChonkyChicken, ChromEggscalator. Delivery via ClickFix social engineering — tricking users into running malicious commands themselves.
ChromEggscalator uses Chrome DevTools Protocol to hijack active browser sessions, including M365 web sessions. For state agencies using Microsoft 365 via browser, this represents a credential theft vector that bypasses traditional phishing detection — no malicious link or attachment is required. The user executes the payload themselves. State employees are susceptible to the social engineering lures used for initial delivery.
| Scenario | Probability | Basis |
|---|---|---|
| CISA issues Binding Operational Directive or Emergency Directive related to Zimbra | MODERATE (70%) within 30 days | Joint advisory publication pattern historically precedes BODs; DoD co-authorship signals elevated urgency |
| Storm-2603 SharePoint exploitation expands to U.S. government targets | MODERATE (60%) within 14 days | Campaign currently LATAM/APAC; SharePoint ubiquity in U.S. gov makes expansion likely; four CVEs actively weaponized |
| Additional CISA KEV entries for SharePoint CVEs (CVE-2025-49704/49706/53770/53771) | MODERATE (50%) within 14 days | Active exploitation confirmed; KEV listing typically follows within days of confirmed exploitation |
| AI-autonomous post-exploitation tools adopted by ransomware operators | MODERATE (55%) within 90 days | Hermes is open-source; ransomware operators historically adopt effective tools quickly after proof-of-concept demonstrations |
| Russian Zimbra campaign yields confirmed state/local government compromise | MODERATE (45%) within 30 days | Active confirmed campaign + state Zimbra instances + MFA gaps = sustained exploitation opportunity |
| ICS advisory vulnerabilities exploited in the wild (C-CURE 9000 or ThinManager) | LOW (30%) within 60 days | No exploitation evidence yet; RCE in building access control is high-value but requires more targeted effort |
Alert on Zimbra logins from new geolocations, impossible travel, or following email link clicks. Monitor for bulk mailbox access (T1114.002) post-authentication. Conduct Zimbra authentication log review for successful logins from non-U.S. IPs in the past 30 days. Audit for email forwarding rules (T1114.003) created recently forwarding to external addresses. Verify Zimbra admin accounts for unauthorized changes.
Audit SmartConsole logs for token generation from unexpected IPs. Alert on policy modifications outside change windows (T1562.001). Confirm Management Server is NOT internet-exposed without Trusted Client restrictions — if exposed, treat as potentially compromised pending hotfix application.
Monitor SharePoint ULS logs for exploitation signatures against CVE-2025-49704/49706/53770/53771. Alert on w3wp.exe spawning cmd.exe or powershell.exe. Alert on 7z.exe, MpCmdRun.exe, or clink_x86.exe loading DLLs from non-standard paths. Query for ServiceMouse.sys driver load events. Block and alert on DNS queries to updatemicfosoft[.]com and micfosoft[.]com; monitor high-entropy DNS TXT queries from internal hosts. Search for dnsclient.exe or bbb.msi on SharePoint servers.
Alert on mshta.exe or rundll32.exe loading .ocx files from %TEMP% or user Downloads directories. Monitor for WebSocket connections from non-browser processes (T1571). Monitor Windows certificate store for new Trusted Root CA additions outside GPO-managed deployments (T1553.004). Check Chrome extensions for unauthorized DevTools Protocol access.
Develop a behavioral baseline for command execution cadence. Alert on more than 10 sequential commands within 60 seconds without human typing patterns (no backspaces, consistent inter-command timing) — this is the signature of an AI agent operating in YOLO mode. Monitor for SSH connections from 103.97.0[.]57. Hunt for LinPEAS or custom privilege escalation scripts targeting CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, CVE-2026-43503 on Linux hosts.
| Threat | ATT&CK |
|---|---|
| Zimbra — Russian State Phishing (AA26-204A) | T1566.002 T1078 T1114.002 T1114.003 |
| Check Point CVE-2026-16232 Exploitation | T1190 T1078.004 T1562.001 |
| Storm-2603 SharePoint / ak47c2 / BYOVD | T1190 T1574.001 T1071.004 T1486 |
| Golden Chickens ClickFix / ChromEggscalator | T1204.002 T1059.001 T1185 T1571 |
| Hermes AI Agent Autonomous Post-Exploitation | T1059 T1068 T1083 |
Storm-2603 C2 infrastructure: block all four domains (and all subdomains) at DNS and firewall. 103.97.0[.]57 — Hermes AI agent operator SSH origin, Hong Kong. Block at perimeter; alert on historical connections. Driver: ServiceMouse.sys — BYOVD AV process killer; block driver load at endpoint. SHA-256: f711b14efb7792033b7ac954ebcfaec8141eb0abafef9c17e769ff96e8fecdf3 (Storm-2603 MSI installer, LockBit Black delivery). Monitor digicert[.]com for anomalous DNS resolution indicating AiTM — do not block (legitimate domain). Additional IOCs available via Anomali ThreatStream and partner feeds.
updatemicfosoft[.]com or micfosoft[.]com. Search proxy logs for HTTP POST requests with PDB path strings containing "ak47c2". Check for dnsclient.exe or bbb.msi on SharePoint servers. Query EDR for w3wp.exe spawning shells.ServiceMouse.sys driver load events. Check for gaps in EDR telemetry — hosts that stopped reporting to the console. Verify AV service status on all SharePoint servers, file servers, and DC-adjacent systems. Search for processes running as SYSTEM without corresponding service entries.mshta.exe executions with command-line arguments referencing .ocx files. Look for new WebSocket connections originating from non-browser processes in the past 72 hours. Check Chrome extension store for unauthorized DevTools Protocol access grants. Audit recently installed root certificates for additions outside GPO management.- Prioritize SharePoint patching for financial agencies — all four Storm-2603 CVEs
- Enforce hardware token MFA for all financial system access
- Segment financial SharePoint farms from general agency infrastructure
- Assess libIEC61850 and lib60870 exposure in substation environments
- Ensure OT network segmentation prevents IT-side compromise from reaching substation controllers
- Maintain out-of-band monitoring capability independent of IT network health
- Verify SharePoint patch status for all health-related agency instances
- Implement data loss prevention rules for Medicaid PII
- Ensure offline backup capability for vital records systems; validate backup restoration time
- Accelerate Zimbra migration timeline — patch and enforce MFA immediately for remaining instances
- Patch C-CURE 9000 and segment physical access control networks from general IT
- Brief executive staff on Zimbra phishing indicators; provide specific email subject/link patterns from AA26-204A
- Patch ThinManager instances; audit for unauthorized file creation in management directories
- Review Panduit IntraVUE deployments for unnecessary IT-OT connectivity
- Ensure transportation SCADA systems have independent safety instrumented systems not overrideable via network access
updatemicfosoft[.]com and micfosoft[.]com (all subdomains) at DNS and firewall. Also block 103.97.0[.]57 and alert on ServiceMouse.sys driver load events. Confirmed Storm-2603 C2 infrastructure and BYOVD AV killer.7z.exe, clink_x86.exe, and MpCmdRun.exe loading non-Microsoft DLLs from non-standard paths. Alert on ServiceMouse.sys driver load events and EDR telemetry gaps (hosts that stopped reporting).mshta.exe or rundll32.exe loading .ocx files from %TEMP% or user Downloads. Alert on WebSocket C2 traffic from non-browser processes. Monitor Windows certificate store for unauthorized Trusted Root CA additions.State government IT environments face simultaneous, active exploitation of three platform categories — Zimbra, Check Point firewall management, and SharePoint Server — by confirmed nation-state actors. The addition of AI-autonomous post-exploitation to the threat landscape means the window between initial compromise and data exfiltration is shrinking from days to minutes. Three questions determine your immediate risk posture today.