TLP:GREEN  ·  States / Public Sector
Silent Sabotage:

Defender-Busting PoCs, DPRK Supply Chain Attacks, and Unpatched Linux Servers Converge

ELEVATED. Sustained from prior cycle. A newly published proof-of-concept silently degrades Windows Defender signature updates without triggering alerts, DPRK's TraderTraitor group expanded beyond cryptocurrency into state DevOps tooling via weaponized Terraform files, and CVSS 9.8 Linux kernel and cPanel vulnerabilities are under active exploitation. A rare criminal-on-criminal breach - ShinyHunters against Clop's leak site - introduces unpredictable secondary exposure risks.

I am a
My sector

DateDevelopmentWhy It Matters for State Government
21 Sep 2026CrowdSec confirms ~300 repositories (170 private)...Any state agency or contractor using npm packages...
21 Sep 2026"BigDiskBuster" proof-of-concept published on...State agencies relying on Defender as their sole...
21 Sep 2026SentinelOne reports DPRK's TraderTraitor group...State IT modernization projects using Terraform...
19–21 Sep 2026ShinyHunters breaches and defaces Clop ransomware...Potential secondary exposure for any government...
18 Sep 2026CISA adds CVE-2025-39682 (CVSS 9.8)...Every Linux server terminating TLS connections in...
17 Sep 2026CISA publishes 8 ICS advisories covering ABB...State agencies managing water/wastewater SCADA...
17 Sep 2026Cisco ISE CVE-2026-76460 (CVSS 10.0) confirmed...State agencies using Cisco ISE that have not yet...
OngoingCVE-2026-41940 (CVSS 9.8) — cPanel/WHM...State contractors and MSPs hosting state-adjacent...

DateEventThreat Category
Sep 2025 (disclosed Sep 2026)Cisco Secure Email Gateway CVE-2026-76461...Vulnerability Exploitation
May 2026TanStack npm supply chain compromise occurs...Supply Chain
15 Sep 2026Cisco Secure Email Gateway CVE-2026-76461 (CVSS...Vulnerability Exploitation
17 Sep 2026Cisco ISE CVE-2026-76460 (CVSS 10.0) confirmed...Vulnerability Exploitation
17 Sep 2026CISA publishes 8 ICS advisories (ABB, Schneider...Critical Infrastructure
18 Sep 2026CISA adds 3 Linux kernel CVEs to KEV catalog with...Vulnerability Exploitation
19–21 Sep 2026ShinyHunters breaches Clop's dark web leak site...Criminal Ecosystem Disruption
21 Sep 2026CrowdSec publicly confirms 300-repo theft via...Supply Chain
21 Sep 2026BigDiskBuster PoC published — Defender signature...Defense Evasion
21 Sep 2026SentinelOne reports TraderTraitor Terraform lock...Nation-State / Supply Chain

TraderTraitor (Lazarus subgroup) is weaponizing Terraform .terraform.lock.hcl files in fake job-interview GitHub repos. When a developer clones the repo and runs terraform init, the lock file redirects provider downloads to typosquatted registries delivering FLATROOF and ROOFDECK macOS backdoors. A confirmed victim is...

T1566.003T1204.002T1553.001T1102

BigDiskBuster prevents Microsoft Defender from completing signature updates - it does not disable Defender, so most monitoring solutions that alert on "Defender disabled" miss it entirely. Signature databases become progressively stale, creating an invisible detection blind spot. The PoC has 130+ GitHub stars and 20+ forks, indicating rapid...

T1562.001

CVE-2025-39682 (CVSS 9.8): Linux kernel TLS zero-length record handling flaw enabling RCE on any server terminating TLS - web servers, API gateways, load balancers. Added to KEV Sep 18 with an aggressive remediation timeline.

CVE-2026-41940 (CVSS 9.8): cPanel/WHM auth bypass actively exploited for Mirai...

T1068T1190T1078

CrowdSec confirmed ~300 repositories (170 private) were exfiltrated in May 2026 through a compromised API key from a TanStack package dependency - undetected for four months. TanStack's broad npm adoption means additional victim disclosures are expected. Any organization consuming TanStack packages between May-September may have been...

T1195.002T1528

ShinyHunters breached and defaced Clop's dark web leak site via a Grav CMS vulnerability, claiming control of Clop's onion private keys and threatening to release ransom payment data - creating potential exposure for any entity that previously paid Clop. Separately, 8 CISA ICS advisories (Sep 17) cover ABB, Schneider, Hitachi Energy...

ScenarioProbabilityTimeframeBasis
Additional TanStack supply chain victim...HIGH (70%)1–3 weeksTanStack's broad npm adoption means CrowdSec is...
BigDiskBuster technique incorporated into...MODERATE (50%)2–4 weeksPublic PoC with 130+ stars; low complexity to...
Clop retaliates against ShinyHunters or...MODERATE (40%)1–2 weeksCriminal groups historically respond to public...
DPRK TraderTraitor targets U.S. government...MODERATE (40%)1–2 monthsConfirmed expansion beyond crypto; IT services...
APT44/Sandworm resumes Western government...LOW-MODERATE (20–30%)2–4 weeksHistorical pattern shows post-election...
"Sorry" ransomware campaign via cPanel...LOW-MODERATE (25%)1–2 weeksMass exploitation is confirmed; state contractor...

1. Windows Defender Signature Staleness (BigDiskBuster):

Hunting hypothesis: An attacker...

2. DPRK TraderTraitor Infrastructure (Terraform/Fake Interview Campaign):

Hunting hypothesis: A developer...

3. TerminalFix PNG Steganography Campaign:

Hunting hypothesis: Threat...

4. Linux Kernel Exploitation (CISA KEV):

What to monitor: - Unexpected...

5. cPanel/WHM Exploitation:

What to monitor: - Any...

ThreatATT&CK
1. Windows Defender Signature Staleness...T1562.001
2. DPRK TraderTraitor Infrastructure...T1566.003 T1204.002...
3. TerminalFix PNG Steganography CampaignT1027.003 T1574.002...
4. Linux Kernel Exploitation (CISA KEV)T1068 T1190
5. cPanel/WHM ExploitationT1190 T1078
IOC Blocking Table:
hashicorp-aws[.]comhashicorp-aws[.]iohashicorp-terraform[.]iogrenight[.]comsytes[.]nethubpage[.]cloud

Block the above at perimeter firewalls, proxies...

Hunting Hypotheses:
HUNT 01
1. Windows Defender Signature Staleness (BigDiskBuster)
An attacker with local access deploys BigDiskBuster or a variant to prevent Defender signature updates, creating a detection blind spot for subsequent malware deployment.
HUNT 02
2. DPRK TraderTraitor Infrastructure (Terraform/Fake Interview Campaign)
A developer or DevOps engineer clones a malicious GitHub repository containing a weaponized .terraform.lock.hcl file, which redirects Terraform provider downloads to attacker-controlled registries delivering FLATROOF or ROOFDECK backdoors.
HUNT 03
3. TerminalFix PNG Steganography Campaign
Threat actors deliver malicious payloads embedded in PNG images via email or web download. The legitimate Microsoft binary LockScreenContentServer.exe is used for DLL sideloading.

Financial Services
Treasury, Revenue, Benefits
Primary threat
TanStack dependency exposure risk for third-party npm integrations; DPRK actors stealing API...
Actions
  • Audit TanStack dependency exposure; prepare for potential Clop ransom payment disclosure
Energy
SCADA, OT Linux Systems
Primary threats
8 CISA ICS advisories cover Schneider, Hitachi, and ABB equipment common in energy/water...
Actions
  • Cross-reference ICS advisories against OT inventory; coordinate Linux patching with OT teams
Healthcare
Medicaid, Clinical Systems
Primary threats
High-value target for bulk PII; clinical workstations frequently rely solely on Defender, elevating...
Actions
  • Assess Defender dependency in clinical settings; audit TanStack exposure in health IT web frameworks
Government
Endpoint Protection, DevOps
Primary threats
Highest risk this cycle: Defender signature degradation, Linux kernel exploitation, and DPRK supply...
Actions
  • Implement Defender signature freshness monitoring; prioritize CVE-2025-39682 on internet-facing Linux servers
Aviation / Logistics
Transportation ICS
Primary threat
Mitsubishi CC-Link/GX Works3 advisories relevant to traffic management and rail signaling...
Actions
  • Verify no contractor-managed infrastructure uses vulnerable cPanel; patch Linux NTP servers against current KEVs
No sector cards match the selected filters.

Patch all Linux servers against CVE-2025-39682 and...
Incident Responder
Deploy Defender signature freshness alerting - alert when any...
SOC Analyst
Block DPRK TraderTraitor domains at DNS/proxy; add...
SOC Analyst
Deploy TerminalFix steganography detection; verify Cisco ISE...
SOC AnalystIncident Responder
No immediate actions for the selected roles.
Audit all Terraform projects; pin providers to...
Incident Responder
Inventory and remediate cPanel/WHM instances; patch...
Incident Responder
Patch SolarWinds Access Rights Manager to 2026.2.1 for...
Incident Responder
Brief recruiting/hiring teams on DPRK fake-interview TTPs.
CISO / Exec
No 7-day actions for the selected roles.
Review endpoint protection strategy - evaluate supplemental...
CISO / Exec
Brief leadership on DPRK supply chain expansion; inform...
CISO / Exec
Develop a supply chain security policy requiring SBOMs and...
CISO / Exec
Resolve the OSINT collection gap - 5 consecutive days of...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

This week's intelligence paints a picture of compounding risk for state government IT. Your Defender-only endpoints have a new adversary - BigDiskBuster is public and will be weaponized. Your developers are being targeted by a nation-state - DPRK's TraderTraitor has moved beyond cryptocurrency into Terraform and GitHub. Your Linux servers are under active exploitation with a CVSS 9.8 confirmed KEV listing. The supply chain attack surface is expanding faster than your monitoring - TanStack...

1
Patch Linux servers against CVE-2025-39682 this week.
2
Deploy Defender signature freshness monitoring today.
3
Brief your developers on DPRK fake-interview TTPs.
No items found.