TLP:GREEN  ·  States / Public Sector
Sandworm Targets Government:

Cisco Email Gateway Under Active Exploitation as a New Chinese Actor Steals Source Code

ELEVATED. Raised from baseline. Three concurrent high-severity threats converged in a single 48-hour window: active Russian military intelligence phishing against government (APT44/Sandworm), a CISA-mandated emergency patch for email gateway infrastructure, and a newly discovered Chinese threat actor conducting source code and OT intelligence theft. Five of eight core intelligence priorities were hit simultaneously, and six distinct campaigns targeted government in 48 hours - well above baseline.

I am a
My sector

ChangeWhy It Matters
CVE-2026-76461 — Cisco Secure Email Gateway RCE...Unauthenticated root-level RCE via crafted inbound email. If your...
APT44 (Sandworm) — Active phishing campaign...Russia's GRU Unit 74455 — the group behind NotPetya and Industroyer —...
Red Heron — Newly documented China-nexus actor...Source code theft, credential harvesting, and a novel Linux rootkit...
Government-targeting campaign surge — Six distinct...UNC6553, UNC5692, UNC5224, UNC4108, UNC6527, and an unattributed...
New ICS/OT vulnerability disclosures — Secomea...Three advisories dropped in 48 hours covering OT remote access...

DateEventSeverity
8 SepCISA publishes AA26-251A: China AI distillation campaigns against...Strategic
9 SepCISA adds CVE-2025-25249 (Fortinet FortiOS) to KEV; linked to PivotC2...Critical
10 SepCISA ICS advisories: AVEVA Pipeline Integrity Monitor...High
11 SepCISA adds CVE-2026-85706 (GitLab CE/EE, CVSS 10.0) to KEV; BOD 26-04...Critical
12 SepRevolut confirms data breach via fraudulent legal process requests...High
14 SepCISA adds CVE-2026-76461 (Cisco Secure Email Gateway RCE, CVSS 9.8)...Critical
14 SepSecomea GateManager session fixation vulnerability (CVE-2026-1758...High
14–15 SepSix distinct campaigns targeting government detected...High
15 SepAPT44 (Sandworm) FEEDUPDATE phishing campaign against government...Critical
15 SepRed Heron Gitea exploitation campaign (CVE-2026-60004) publicly...Critical

CVE-2026-76461 is an unauthenticated RCE in Cisco AsyncOS - a specially crafted email with malicious SQL statements achieves root-level command execution. No user interaction required; the attack vector is the normal email flow itself. CISA added this to KEV Sep 14, confirming active exploitation.

For state government: if...

T1190T1059.004T1068

APT44/Sandworm is GRU Unit 74455 - responsible for NotPetya, Olympic Destroyer, and Industroyer. Intelligence confirms an active phishing campaign deploying VBS loaders that deliver FEEDUPDATE malware against government targets - a notable TTP evolution from Sandworm's historical destructive focus toward persistent espionage access.

T1566.002T1059.005T1105T1071.001

A previously undocumented Chinese actor, Red Heron, has exploited Gitea RCE (CVSS 9.8) across Canada, Argentina, Taiwan, the US, and Sri Lanka since July 29. Scale: 1,386 internet-exposed instances scanned, 477 in Taiwan alone. A Taiwanese industrial automation environment lost hundreds of repositories including SCADA/HMI tools...

T1190T1014T1136T1003
ActorMalware
UNC6553SURFCAKE (Node.js), Task Scheduler persistence
UNC5692PEAKLIGHT via ClickFix
UNC5224AsyncRAT via phishing
Unattributed

Secomea GateManager session fixation (CVSS 8.3) allows OT remote access session hijacking. AVEVA Pipeline Integrity Monitor and Orthanc DICOM advisories also dropped this cycle. CyberAv3ngers continues targeting water/wastewater SCADA.

Qilin remains the dominant ransomware operator...

T1133T1563T1486

ScenarioProbabilityBasis
Additional CISA KEV additions for Cisco SEG or Gitea as exploitation evidence mountsHIGH (70–80%)Both vulnerabilities are CVSS 9.8 with confirmed exploitation; KEV...
Red Heron campaign expands to additional Gitea instances; state...MODERATE (50–60%)Automated exploitation framework + 1,386 scanned instances = broad...
APT44 FEEDUPDATE phishing attempts reach .gov email addressesMODERATE (45–55%)Campaign is active and explicitly targets government; U.S. state...
Ransomware operators (Qilin, Rhysida) resume operations after weekend...MODERATE (40–50%)Historical pattern of weekend staging → weekday detonation; 146...
China-nexus actors escalate exploitation of CVE-2026-0257 (Palo Alto...MODERATE (40–50%)Confirmed campaign targeting government + energy; state VPN...
Red Heron or affiliated actors pivot from Gitea to GitLab...LOW-MODERATE (25–35%)Both are code repository platforms; actor demonstrated interest in...

Priority 1 — Cisco Secure Email Gateway Exploitation (CVE-2026-76461):

Hunt Hypothesis: Threat actors are sending crafted...

Priority 2 — APT44/Sandworm VBS Loader → FEEDUPDATE Chain:

Hunt Hypothesis: APT44 is delivering phishing emails...

Priority 3 — Red Heron Gitea Exploitation and SIXZUT Rootkit:

Hunt Hypothesis: Red Heron's automated framework is...

Priority 4 — SURFCAKE / Node.js Malware on Government Endpoints:

Hunt Hypothesis: UNC6553 is deploying SURFCAKE, a...

Priority 5 — ClickFix Social Engineering (PEAKLIGHT):

Hunt Hypothesis: UNC5692 is using ClickFix social...

Priority 6 — Secomea GateManager Session Hijacking (CVE-2026-1758):

Hunt Hypothesis: Attackers may exploit session...

ThreatATT&CK
Priority 1 — Cisco Secure Email Gateway Exploitation (CVE-2026-76461)T1190 T1059.004 T1068
Priority 2 — APT44/Sandworm VBS Loader → FEEDUPDATE ChainT1071.001 T1566.002 T1059.005...
Priority 3 — Red Heron Gitea Exploitation and SIXZUT RootkitT1136 T1003 T1190...
Priority 4 — SURFCAKE / Node.js Malware on Government EndpointsT1059.007 T1053.005
Priority 5 — ClickFix Social Engineering (PEAKLIGHT)T1204.002 T1059.001
Priority 6 — Secomea GateManager Session Hijacking (CVE-2026-1758)T1133 T1563
Indicators to Block:
82.192.72[.]4103.102.31[.]18

Persistence artifacts to hunt: unauthorized...

Hunting Hypotheses:
H1
Cisco SEG already exploited via SQL injection payload
Monitor anomalous SQL patterns in inbound email and unexpected SEG process spawning.
H2
APT44 VBS loader already delivered FEEDUPDATE
Monitor for wscript/cscript/mshta spawned by outlook.exe or browsers.
H3
Red Heron already registered a Gitea account to deploy JITTERLY/SIXZUT
Monitor new Gitea registrations, LD_PRELOAD modifications, and libglthread.so.2 anomalies.
H4
SURFCAKE already deployed via scheduled task
Monitor anomalous node.exe execution and schtasks.exe entries referencing Node.js.
H5
A user already executed a ClickFix PEAKLIGHT payload
Monitor clipboard-to-Run/PowerShell execution after suspicious web visits.

Financial Services
Treasury, Revenue, Benefits
Primary threats
Prime targets for ransomware (Qilin, BASTA) and credential harvesting. A compromised mail gateway...
Actions
  • Verify email gateways protecting financial systems are patched against CVE-2026-76461
Energy
Utilities, Pipeline Monitoring
Primary threat
Two-front threat: CyberAv3ngers targeting ICS/SCADA plus newly disclosed OT remote access and...
Actions
  • Upgrade Secomea GateManager to v11.6+ for CVE-2026-1758; restrict access until patched
Healthcare
Medicaid, Imaging Systems
Primary threat
State health infrastructure holds PHI for millions and runs increasingly network-connected medical...
Actions
  • Inventory and patch Orthanc DICOM instances per ICSMA-26-253-02
Government
Executive Agencies, Elections
Primary threat
Explicit target of at least six active campaigns this cycle plus APT44/Sandworm's FEEDUPDATE...
Actions
  • Deploy VBS loader detection; brief IT leads on ClickFix social engineering
Aviation / Logistics
DOT, Port Authorities
Primary threat
Transportation/logistics systems are increasingly digitized and connected to enterprise IT...
Actions
  • Verify GlobalProtect VPN patched against CVE-2026-0257 (confirmed China-nexus exploitation)
No sector cards match the selected filters.

Verify Cisco Secure Email Gateway in your mail stack; initiate...
SOC AnalystIncident Responder
Confirm Palo Alto GlobalProtect is patched against...
Incident Responder
Deploy VBS loader detection: alert on...
SOC Analyst
Inventory self-hosted Gitea instances within 48 hours; upgrade...
Incident Responder
No immediate actions for the selected roles.
Update Secomea GateManager to v11.6+; audit AVEVA and Orthanc...
ICS / OT
Add SURFCAKE detection signatures - monitor anomalous Node.js...
SOC Analyst
Update ClickFix detection rules for the PEAKLIGHT variant...
SOC Analyst
Review third-party/MSP VPN access given the BASTA campaign's...
CISO / Exec
No 7-day actions for the selected roles.
Brief leadership on China-nexus escalation - Red Heron...
CISO / Exec
Conduct a credential hygiene audit across agencies - SSH keys...
CISO / Exec
Evaluate segmentation between enterprise IT, OT/ICS, and...
CISO / Exec
Resolve the OSINT collection outage (Day 7) - evaluate...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The threat picture facing state government IT this week is not abstract. APT44/Sandworm - the unit that launched NotPetya - is actively phishing government targets. A critical Cisco email gateway vulnerability means every inbound email could be a root-level compromise. A new Chinese threat actor is stealing source code and OT intelligence from organizations that look exactly like state agencies. And six distinct campaigns targeting government were detected in a single 48-hour window. Three...

1
Is Cisco Secure Email Gateway in your mail stack? If yes, emergency patch now.
2
Is Palo Alto GlobalProtect your VPN? Verify CVE-2026-0257 patch status now.
3
Does any agency run self-hosted Gitea? Inventory and patch within 48 hours.
No items found.