| Change | Why It Matters |
|---|---|
| CVE-2026-76461 — Cisco Secure Email Gateway RCE... | Unauthenticated root-level RCE via crafted inbound email. If your... |
| APT44 (Sandworm) — Active phishing campaign... | Russia's GRU Unit 74455 — the group behind NotPetya and Industroyer —... |
| Red Heron — Newly documented China-nexus actor... | Source code theft, credential harvesting, and a novel Linux rootkit... |
| Government-targeting campaign surge — Six distinct... | UNC6553, UNC5692, UNC5224, UNC4108, UNC6527, and an unattributed... |
| New ICS/OT vulnerability disclosures — Secomea... | Three advisories dropped in 48 hours covering OT remote access... |
| Date | Event | Severity |
|---|---|---|
| 8 Sep | CISA publishes AA26-251A: China AI distillation campaigns against... | Strategic |
| 9 Sep | CISA adds CVE-2025-25249 (Fortinet FortiOS) to KEV; linked to PivotC2... | Critical |
| 10 Sep | CISA ICS advisories: AVEVA Pipeline Integrity Monitor... | High |
| 11 Sep | CISA adds CVE-2026-85706 (GitLab CE/EE, CVSS 10.0) to KEV; BOD 26-04... | Critical |
| 12 Sep | Revolut confirms data breach via fraudulent legal process requests... | High |
| 14 Sep | CISA adds CVE-2026-76461 (Cisco Secure Email Gateway RCE, CVSS 9.8)... | Critical |
| 14 Sep | Secomea GateManager session fixation vulnerability (CVE-2026-1758... | High |
| 14–15 Sep | Six distinct campaigns targeting government detected... | High |
| 15 Sep | APT44 (Sandworm) FEEDUPDATE phishing campaign against government... | Critical |
| 15 Sep | Red Heron Gitea exploitation campaign (CVE-2026-60004) publicly... | Critical |
CVE-2026-76461 is an unauthenticated RCE in Cisco AsyncOS - a specially crafted email with malicious SQL statements achieves root-level command execution. No user interaction required; the attack vector is the normal email flow itself. CISA added this to KEV Sep 14, confirming active exploitation.
For state government: if...
APT44/Sandworm is GRU Unit 74455 - responsible for NotPetya, Olympic Destroyer, and Industroyer. Intelligence confirms an active phishing campaign deploying VBS loaders that deliver FEEDUPDATE malware against government targets - a notable TTP evolution from Sandworm's historical destructive focus toward persistent espionage access.
A previously undocumented Chinese actor, Red Heron, has exploited Gitea RCE (CVSS 9.8) across Canada, Argentina, Taiwan, the US, and Sri Lanka since July 29. Scale: 1,386 internet-exposed instances scanned, 477 in Taiwan alone. A Taiwanese industrial automation environment lost hundreds of repositories including SCADA/HMI tools...
| Actor | Malware |
|---|---|
| UNC6553 | SURFCAKE (Node.js), Task Scheduler persistence |
| UNC5692 | PEAKLIGHT via ClickFix |
| UNC5224 | AsyncRAT via phishing |
| Unattributed |
Secomea GateManager session fixation (CVSS 8.3) allows OT remote access session hijacking. AVEVA Pipeline Integrity Monitor and Orthanc DICOM advisories also dropped this cycle. CyberAv3ngers continues targeting water/wastewater SCADA.
Qilin remains the dominant ransomware operator...
| Scenario | Probability | Basis |
|---|---|---|
| Additional CISA KEV additions for Cisco SEG or Gitea as exploitation evidence mounts | HIGH (70–80%) | Both vulnerabilities are CVSS 9.8 with confirmed exploitation; KEV... |
| Red Heron campaign expands to additional Gitea instances; state... | MODERATE (50–60%) | Automated exploitation framework + 1,386 scanned instances = broad... |
| APT44 FEEDUPDATE phishing attempts reach .gov email addresses | MODERATE (45–55%) | Campaign is active and explicitly targets government; U.S. state... |
| Ransomware operators (Qilin, Rhysida) resume operations after weekend... | MODERATE (40–50%) | Historical pattern of weekend staging → weekday detonation; 146... |
| China-nexus actors escalate exploitation of CVE-2026-0257 (Palo Alto... | MODERATE (40–50%) | Confirmed campaign targeting government + energy; state VPN... |
| Red Heron or affiliated actors pivot from Gitea to GitLab... | LOW-MODERATE (25–35%) | Both are code repository platforms; actor demonstrated interest in... |
Hunt Hypothesis: Threat actors are sending crafted...
Hunt Hypothesis: APT44 is delivering phishing emails...
Hunt Hypothesis: Red Heron's automated framework is...
Hunt Hypothesis: UNC6553 is deploying SURFCAKE, a...
Hunt Hypothesis: UNC5692 is using ClickFix social...
Hunt Hypothesis: Attackers may exploit session...
| Threat | ATT&CK |
|---|---|
| Priority 1 — Cisco Secure Email Gateway Exploitation (CVE-2026-76461) | T1190 T1059.004 T1068 |
| Priority 2 — APT44/Sandworm VBS Loader → FEEDUPDATE Chain | T1071.001 T1566.002 T1059.005... |
| Priority 3 — Red Heron Gitea Exploitation and SIXZUT Rootkit | T1136 T1003 T1190... |
| Priority 4 — SURFCAKE / Node.js Malware on Government Endpoints | T1059.007 T1053.005 |
| Priority 5 — ClickFix Social Engineering (PEAKLIGHT) | T1204.002 T1059.001 |
| Priority 6 — Secomea GateManager Session Hijacking (CVE-2026-1758) | T1133 T1563 |
Persistence artifacts to hunt: unauthorized...
- Verify email gateways protecting financial systems are patched against CVE-2026-76461
- Upgrade Secomea GateManager to v11.6+ for CVE-2026-1758; restrict access until patched
- Inventory and patch Orthanc DICOM instances per ICSMA-26-253-02
- Deploy VBS loader detection; brief IT leads on ClickFix social engineering
- Verify GlobalProtect VPN patched against CVE-2026-0257 (confirmed China-nexus exploitation)
The threat picture facing state government IT this week is not abstract. APT44/Sandworm - the unit that launched NotPetya - is actively phishing government targets. A critical Cisco email gateway vulnerability means every inbound email could be a root-level compromise. A new Chinese threat actor is stealing source code and OT intelligence from organizations that look exactly like state agencies. And six distinct campaigns targeting government were detected in a single 48-hour window. Three...