| Development | Significance |
|---|---|
| APT44/Sandworm released an updated... | Any Linux-based network appliance is now a... |
| APT44/Sandworm FEEDUPDATE phishing... | Direct Russian military intelligence targeting of... |
| ConnectWise ScreenConnect CVE-2026-84869... | Ransomware and Kimsuky have historically... |
| Cisco Secure Email Gateway CVE-2026-76461... | Every state agency receiving email is exposed |
| CISA published seven ICS... | Products deployed in state water treatment... |
| CISA and NIST jointly published IR... | Signals session hijacking and token theft as... |
| Anthropic published a threat... | Spans government, education, healthcare, and... |
| Date | Event | Severity | Relevance to State Gov |
|---|---|---|---|
| Sep 9 | Cisco Talos publishes analysis of Cyclops Blink... | HIGH | Cisco FMC widely deployed in state network... |
| Sep 11 | CISA adds CVE-2026-84869 (ScreenConnect) to KEV... | CRITICAL | MSP remote access tool used across state vendor... |
| Sep 11 | Sophos CTU publishes detailed Cyclops Blink 2026... | HIGH | Nation-state implant on network management... |
| Sep 14 | CISA adds CVE-2026-76461 (Cisco Secure Email... | CRITICAL | Email gateways are universal in state government |
| Sep 15 | APT44/Sandworm FEEDUPDATE phishing campaign... | HIGH | Direct government targeting by Russian military... |
| Sep 15 | CISA publishes 7 ICS advisories (mySCADA... | HIGH | OT/ICS products deployed in state water, utility... |
| Sep 15 | CISA/NIST publish IR 8587 — Token and Assertion... | MEDIUM | Directly addresses M365/Azure AD token theft risks |
| Sep 15 | Sophos confirms active exploitation of... | CRITICAL | Exploitation confirmed in the wild |
| Sep 16 | Anthropic threat report documents AI-enabled... | MEDIUM | China-nexus group targeted government, education... |
APT44/Sandworm is GRU Unit 74455, responsible for NotPetya, the Ukrainian power grid attacks, and Olympic Destroyer. The 2026 Cyclops Blink variant (timezone_check) uses generic SysV init persistence - deliberately broadening from the 2022 WatchGuard-specific version to any Linux-based network appliance. It...
CVE-2026-84869 allows attackers with basic session privileges to transfer and execute files on managed endpoints without authorization. Over 1,000 instances remain unpatched globally, 758 in North America. This is the fourth ScreenConnect CVE on KEV since 2024 - each previous flaw was rapidly weaponized by nation-state actors...
Allows unauthenticated remote command execution with root privileges via a crafted email containing malicious SQL statements - no credentials or user interaction required. CISA KEV Sep 14; Sophos confirmed active exploitation Sep 15.
Patching requires maintenance windows that disrupt mail flow, but leaving unpatched means every inbound...
| Product | Impact |
|---|---|
| mySCADA myPRO Manager | Privileged access, arbitrary SQL execution |
| Schneider SCADAPack x70 | SCADA system vulnerability |
| Digital Watchdog VMAX | Full admin control of... |
NIST IR 8587 addresses AiTM phishing, OAuth token abuse, and SAML assertion forgery - active campaigns (Storm-3121/3032 passkey vishing) already target M365 with these techniques.
AI escalation: Anthropic's report documents GTG-10007 (China-nexus) targeting ~50 organizations with autonomous vulnerability...
| Scenario | Probability | Basis |
|---|---|---|
| Ransomware operators weaponize ScreenConnect... | HIGH (>70%) | Historical pattern: CVE-2024-1709 was weaponized... |
| Cyclops Blink variant discovered on non-Cisco... | MODERATE (40–60%) | The 2026 variant deliberately uses generic SysV... |
| AI-enabled credential harvesting campaigns target... | MODERATE (40–60%) | Anthropic report documents operational AI-enabled... |
| Rhysida or Qilin ransomware targets a U.S. state... | LOW-MODERATE (20–40%) | Based on historical cadence and current... |
| Exploitation of mySCADA or SCADAPack... | LOW-MODERATE (20–40%) | CISA advisory publication often precedes... |
Hunt hypothesis: APT44 has...
Hunt hypothesis: An attacker has...
Hunt hypothesis: An attacker has...
Hunt hypothesis: An adversary is...
Hunt hypothesis: An attacker is...
| Threat | ATT&CK |
|---|---|
| 1. Cyclops Blink / APT44 Indicators on Network... | T1036 T1543.003... |
| 2. ScreenConnect Exploitation and Abuse | T1219 T1068... |
| 3. Cisco Secure Email Gateway Exploitation | T1059 T1190... |
| 4. Token Theft and Session Hijacking in... | T1528 T1550.001... |
| 5. OT/ICS Anomaly Monitoring | T0890 T0836... |
Cyclops Blink 2026 behavioral indicators: implant filename timezone_check; process masquerade [kworker/0:1]; C2 TCP ports 43856 and 49172; persistence path /etc/init.d/. File hashes and network IOCs for all campaigns discussed in this report - including Cyclops Blink, CVE-2026-84869, CVE-2026-76461, and Red Heron JITTERLY/SIXZUT - are available via Anomali ThreatStream Next-Gen.
- Inventory/patch all MSP RMM tools; validate CVE-2026-76461 patch status on revenue-facing email gateways
- Emergency inventory of mySCADA and SCADAPack x70; hunt Cyclops Blink indicators on OT network appliances
- Prioritize ScreenConnect patching; implement FIDO2/passkey MFA for Medicaid database access
- Treat Cisco FMC integrity check as emergency; implement NIST IR 8587 for high-privilege M365/Azure AD accounts
- Inventory SCADAPack deployments in traffic control; monitor for Cyclops Blink on transportation network segments
Three themes define this week's threat landscape. The perimeter is the target: Sandworm is implanting Cisco firewall management infrastructure, email gateways are being rooted via inbound mail, and ScreenConnect is being exploited to bypass endpoint controls entirely. Supply chain trust is eroding: the fourth ScreenConnect KEV in two years is a vendor governance problem, not just a patching problem. Silence is not safety: Volt Typhoon, Salt Typhoon, and Rhysida have all gone quiet, and the...