TLP:GREEN  ·  States / Public Sector
Sandworm Returns:

ScreenConnect Under Siege and the Widening Gap in State Government Cyber Defense

ELEVATED. Upgraded from prior cycle's ELEVATED-with-upward-pressure. Russia's APT44/Sandworm deployed an updated Cyclops Blink implant on Cisco Firewall Management Center devices, broadening beyond WatchGuard-only targeting. A CVSS 9.9 ConnectWise ScreenConnect flaw is under active exploitation with 1,000+ unpatched instances, and a CVSS 9.8 Cisco Secure Email Gateway RCE means attackers can compromise your email infrastructure by simply sending a crafted message.

I am a
My sector

DevelopmentSignificance
APT44/Sandworm released an updated...Any Linux-based network appliance is now a...
APT44/Sandworm FEEDUPDATE phishing...Direct Russian military intelligence targeting of...
ConnectWise ScreenConnect CVE-2026-84869...Ransomware and Kimsuky have historically...
Cisco Secure Email Gateway CVE-2026-76461...Every state agency receiving email is exposed
CISA published seven ICS...Products deployed in state water treatment...
CISA and NIST jointly published IR...Signals session hijacking and token theft as...
Anthropic published a threat...Spans government, education, healthcare, and...

DateEventSeverityRelevance to State Gov
Sep 9Cisco Talos publishes analysis of Cyclops Blink...HIGHCisco FMC widely deployed in state network...
Sep 11CISA adds CVE-2026-84869 (ScreenConnect) to KEV...CRITICALMSP remote access tool used across state vendor...
Sep 11Sophos CTU publishes detailed Cyclops Blink 2026...HIGHNation-state implant on network management...
Sep 14CISA adds CVE-2026-76461 (Cisco Secure Email...CRITICALEmail gateways are universal in state government
Sep 15APT44/Sandworm FEEDUPDATE phishing campaign...HIGHDirect government targeting by Russian military...
Sep 15CISA publishes 7 ICS advisories (mySCADA...HIGHOT/ICS products deployed in state water, utility...
Sep 15CISA/NIST publish IR 8587 — Token and Assertion...MEDIUMDirectly addresses M365/Azure AD token theft risks
Sep 15Sophos confirms active exploitation of...CRITICALExploitation confirmed in the wild
Sep 16Anthropic threat report documents AI-enabled...MEDIUMChina-nexus group targeted government, education...

APT44/Sandworm is GRU Unit 74455, responsible for NotPetya, the Ukrainian power grid attacks, and Olympic Destroyer. The 2026 Cyclops Blink variant (timezone_check) uses generic SysV init persistence - deliberately broadening from the 2022 WatchGuard-specific version to any Linux-based network appliance. It...

T1543.003T1036T1046T1573

CVE-2026-84869 allows attackers with basic session privileges to transfer and execute files on managed endpoints without authorization. Over 1,000 instances remain unpatched globally, 758 in North America. This is the fourth ScreenConnect CVE on KEV since 2024 - each previous flaw was rapidly weaponized by nation-state actors...

T1068T1219T1021.001

Allows unauthenticated remote command execution with root privileges via a crafted email containing malicious SQL statements - no credentials or user interaction required. CISA KEV Sep 14; Sophos confirmed active exploitation Sep 15.

Patching requires maintenance windows that disrupt mail flow, but leaving unpatched means every inbound...

T1190T1059
ProductImpact
mySCADA myPRO ManagerPrivileged access, arbitrary SQL execution
Schneider SCADAPack x70SCADA system vulnerability
Digital Watchdog VMAXFull admin control of...
T0831T0836T0890

NIST IR 8587 addresses AiTM phishing, OAuth token abuse, and SAML assertion forgery - active campaigns (Storm-3121/3032 passkey vishing) already target M365 with these techniques.

AI escalation: Anthropic's report documents GTG-10007 (China-nexus) targeting ~50 organizations with autonomous vulnerability...

T1528T1539T1550.001T1606.002

ScenarioProbabilityBasis
Ransomware operators weaponize ScreenConnect...HIGH (>70%)Historical pattern: CVE-2024-1709 was weaponized...
Cyclops Blink variant discovered on non-Cisco...MODERATE (40–60%)The 2026 variant deliberately uses generic SysV...
AI-enabled credential harvesting campaigns target...MODERATE (40–60%)Anthropic report documents operational AI-enabled...
Rhysida or Qilin ransomware targets a U.S. state...LOW-MODERATE (20–40%)Based on historical cadence and current...
Exploitation of mySCADA or SCADAPack...LOW-MODERATE (20–40%)CISA advisory publication often precedes...

1. Cyclops Blink / APT44 Indicators on Network Appliances:

Hunt hypothesis: APT44 has...

2. ScreenConnect Exploitation and Abuse:

Hunt hypothesis: An attacker has...

3. Cisco Secure Email Gateway Exploitation:

Hunt hypothesis: An attacker has...

4. Token Theft and Session Hijacking in M365/Azure AD:

Hunt hypothesis: An adversary is...

5. OT/ICS Anomaly Monitoring:

Hunt hypothesis: An attacker is...

ThreatATT&CK
1. Cyclops Blink / APT44 Indicators on Network...T1036 T1543.003...
2. ScreenConnect Exploitation and AbuseT1219 T1068...
3. Cisco Secure Email Gateway ExploitationT1059 T1190...
4. Token Theft and Session Hijacking in...T1528 T1550.001...
5. OT/ICS Anomaly MonitoringT0890 T0836...
IOC Blocking Table:

Cyclops Blink 2026 behavioral indicators: implant filename timezone_check; process masquerade [kworker/0:1]; C2 TCP ports 43856 and 49172; persistence path /etc/init.d/. File hashes and network IOCs for all campaigns discussed in this report - including Cyclops Blink, CVE-2026-84869, CVE-2026-76461, and Red Heron JITTERLY/SIXZUT - are available via Anomali ThreatStream Next-Gen.

Hunting Hypotheses:
HUNT 01
1. Cyclops Blink / APT44 Indicators on Network Appliances
APT44 has compromised one or more Linux-based network appliances (Cisco FMC, firewalls, VPN concentrators) in the state environment and established SysV init persistence.
HUNT 02
2. ScreenConnect Exploitation and Abuse
An attacker has exploited CVE-2026-84869 to transfer and execute malicious payloads via a ScreenConnect session without host authorization.
HUNT 03
3. Cisco Secure Email Gateway Exploitation
An attacker has sent crafted email containing SQL injection payloads to exploit CVE-2026-76461 and achieve root-level command execution on the email gateway.
HUNT 04
4. Token Theft and Session Hijacking in M365/Azure AD
An adversary is using AiTM phishing or token theft techniques to bypass MFA and access state employee M365 mailboxes and SharePoint.
HUNT 05
5. OT/ICS Anomaly Monitoring
An attacker is exploiting newly disclosed vulnerabilities in mySCADA, SCADAPack, or Digital Watchdog products deployed in state utility or building management environments.

Financial Services
Treasury, Revenue, Tax Systems
Primary threat
High-value ransomware targets processing sensitive financial data via MSP-managed remote access...
Actions
  • Inventory/patch all MSP RMM tools; validate CVE-2026-76461 patch status on revenue-facing email gateways
Energy
Water, Power, Transportation
Primary threat
Directly affected by this cycle's ICS advisories and ongoing nation-state interest in critical...
Actions
  • Emergency inventory of mySCADA and SCADAPack x70; hunt Cyclops Blink indicators on OT network appliances
Healthcare
Medicaid, Public Health
Primary threat
Identified as a China-nexus AI-enabled operations target; high-pressure ransomware target.
Actions
  • Prioritize ScreenConnect patching; implement FIDO2/passkey MFA for Medicaid database access
Government
Executive Agencies, Courts
Primary threats
Primary target of nation-state espionage (APT44, Kimsuky, Red Heron) and ransomware seeking maximum...
Actions
  • Treat Cisco FMC integrity check as emergency; implement NIST IR 8587 for high-privilege M365/Azure AD accounts
Aviation / Logistics
DOT, Airports, Ports
Primary threat
Operates IT and OT environments with high availability requirements shared with transportation...
Actions
  • Inventory SCADAPack deployments in traffic control; monitor for Cyclops Blink on transportation network segments
No sector cards match the selected filters.

Verify ALL ScreenConnect instances updated to 26.6.5+; disable...
Incident Responder
Deploy Cyclops Blink detection on ALL Cisco FMC devices: hunt...
SOC Analyst
Apply Cisco AsyncOS patches for CVE-2026-76461; implement SQL...
Incident Responder
Brief agency CISOs on the three active critical threats...
CISO / Exec
No immediate actions for the selected roles.
Inventory all OT/ICS systems against the 7 CISA advisories...
ICS / OT
Review NIST IR 8587 guidance; prioritize token binding for...
IAM Analyst
Conduct an enterprise-wide RMM tool inventory; establish an...
Incident Responder
Expand appliance integrity monitoring beyond Cisco FMC to...
SOC Analyst
No 7-day actions for the selected roles.
Commission a strategic MSP/vendor remote access review - the...
CISO / Exec
Assess AI agent deployment risks across state IT automation...
CISO / Exec
Address the 14-day OSINT collection gap; evaluate emergency...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Three themes define this week's threat landscape. The perimeter is the target: Sandworm is implanting Cisco firewall management infrastructure, email gateways are being rooted via inbound mail, and ScreenConnect is being exploited to bypass endpoint controls entirely. Supply chain trust is eroding: the fourth ScreenConnect KEV in two years is a vendor governance problem, not just a patching problem. Silence is not safety: Volt Typhoon, Salt Typhoon, and Rhysida have all gone quiet, and the...

1
Patch ScreenConnect and verify Cisco FMC integrity today.
2
Apply Cisco Secure Email Gateway patches today.
3
The window for proactive action is measured in days, not weeks.
No items found.