TLP:GREEN  ·  States / Public Sector
Six Zero-Days in 48 Hours and Coordinated Sanctions Against Russia:

What State Government CISOs Must Do This Week

ELEVATED. Between July 14–16, CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog — including a CVSS 10.0 SonicWall SSRF that requires no authentication and a CVSS 9.8 Oracle E-Business Suite takeover with a three-day patch deadline (July 18). At the same time, the U.S., U.K., and E.U. imposed coordinated sanctions on 24+ Russian cyber entities — including FSB Center 16, formally attributed to destructive attacks on Poland's energy grid, and GRU Unit 29155 — sharply raising the probability of Russian retaliatory operations against government networks in the near term.

I am a
My sector

DateDevelopmentImpact
2026-07-13US/UK/EU sanction 24+ Russian cyber entities including FSB Center 16 and GRU Unit 29155Elevated Russian retaliatory risk; formal attribution of Poland energy-grid sabotage
2026-07-14CISA adds CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 to KEV — SonicWall SMA1000Unauthenticated SSRF in VPN appliances actively exploited
2026-07-14CISA issues urgent SharePoint hardening alertCVE-2026-32201, CVE-2026-45659, CVE-2026-45660Three-CVE exploitation chain confirmed active
2026-07-14OFAC sanctions First VPN Service (1VPNS) — ransomware infrastructure used against municipal governmentsDisruption of a ransomware enabler; signals continued targeting of local/state government
2026-07-14Four ICS-CERT advisories — ABB Ability Edgenius (CVE-2026-31431), Rockwell 1715-AENTROT/SCADA systems at risk; public exploit code available
2026-07-15CISA adds CVE-2026-46817 (CVSS 9.8) to KEV — Oracle E-Business SuiteUnauthenticated takeover of Oracle Payments; 3-day patch deadline (Jul 18)
2026-07-15FBI/CISA/NSA joint advisory on FSB Center 16 router exploitationActive scanning of U.S. government routers for default SNMP strings
2026-07-15/16Fresh APT28 malware samples surface targeting government-national entitiesOngoing Russian intelligence collection against government networks

TimeframeActor / CampaignActionTarget
Late Jun 2026UnknownWild exploitation of CVE-2026-46817 begins against Oracle EBS honeypotsFinancial systems
Jun 2026VOID MANTICORE (IRGC)Destructive breach of California water utility confirmedCritical infrastructure
2026-07-13Western governmentsCoordinated sanctions on FSB Center 16, GRU Unit 29155, Lumma Stealer operatorsRussian cyber apparatus
2026-07-14FSB Center 16Active scanning for routers with default SNMP community stringsU.S. government routers
2026-07-14Unknown (nation-state suspected)Active exploitation of SonicWall SMA1000 zero-daysVPN infrastructure
2026-07-14UnknownActive exploitation of SharePoint 3-CVE chainGovernment SharePoint
2026-07-14OFACSanctions on 1VPNS — ransomware VPN service used against municipal governmentRansomware infrastructure
2026-07-15UnknownMass exploitation of Oracle EBS CVE-2026-46817Oracle Payments (1,000+ exposed instances)
2026-07-15/16APT28 (GRU Unit 26165)Fresh malware samples deployed against government targetsGovernment-national

CVE-2026-46817 (CVSS 9.8) lets an unauthenticated attacker take over Oracle Payments via the File Transmission component — no credentials required. Versions 12.2.3 through 12.2.15 are affected. Threat intelligence firm Defused confirmed in-the-wild exploitation beginning late June 2026, and Shadowserver tracks over 1,000 internet-exposed Oracle EBS instances, predominantly in the United States.

Why it matters: CISA's remediation deadline is Saturday, July 18 — an unusually aggressive 3-day window that signals intelligence of imminent mass exploitation. Oracle E-Business Suite is the backbone of state financial operations (payroll, vendor payments, tax processing); an unauthenticated Payments takeover could enable fraudulent disbursements, exfiltration of taxpayer records, or destructive manipulation of financial data.

T1190T1068

The FBI, CISA, and NSA jointly published advisory aa26-194a detailing how FSB Center 16 actors are actively scanning globally for routers with default SNMP community strings, then exfiltrating full device configurations via SNMP Set-Requests to attacker-controlled infrastructure. They are exploiting CVE-2018-0171 (Cisco Smart Install RCE) and CVE-2008-4128 (Cisco IOS CSRF) — the latter with a CISA KEV remediation deadline of today, July 16.

This is the same unit formally attributed to the DynoWiper destructive attack on Poland's power grid, which triggered coordinated UK/EU sanctions on July 13. It has demonstrated both espionage capability and destructive intent.

Why it matters: state networks rely heavily on Cisco infrastructure. Any router still running IOS 12.x or using default/simple SNMP community strings is a confirmed target. Configuration exfiltration gives adversaries a blueprint of network topology, ACLs, and routing without ever touching an endpoint.

T1602.002T1595.002T1557

CISA confirmed active exploitation of a three-CVE chain targeting Microsoft SharePoint: CVE-2026-32201 (CVSS 6.5, improper input validation enabling spoofing — initial access), CVE-2026-45659 (CVSS 8.8, deserialization of untrusted data enabling RCE — execution), and CVE-2026-45660 (part of the chain, details pending). Combined, an attacker can move from unauthenticated access to remote code execution on the SharePoint server, typically deploying a web shell for persistent access.

Why it matters: SharePoint (on-premises and hybrid) is the document-management backbone for most state agencies. Compromise exposes policy documents, inter-agency communications, legal proceedings, and citizen PII held in document libraries.

T1505.003T1059.001T1190

CVE-2026-15409 received the maximum CVSS score of 10.0 — an unauthenticated Server-Side Request Forgery in the SMA1000 Work Place interface. Combined with CVE-2026-15410 (post-authentication code injection, CVSS 7.2), attackers can chain these for full appliance compromise. Both are now in CISA's KEV catalog, and Volexity's involvement in the discovery suggests nation-state exploitation.

Why it matters: SonicWall SMA appliances provide remote-access VPN for state employees and contractors. A compromised VPN concentrator gives an attacker authenticated network access to internal systems, bypassing perimeter defenses entirely.

T1190T1071.001

The coordinated sanctions against 24+ Russian entities across the U.S., U.K., and E.U. represent the most significant Western cyber-sanctions action in years. Sanctioned entities include FSB Center 16 (energy-grid sabotage, router exploitation), GRU Unit 29155 (hybrid warfare operations), Lumma Stealer operators (credential-theft infrastructure), and 1VPNS / First VPN Service (ransomware enablement against municipal government victims).

Why it matters: historically, major sanctions against Russian cyber entities are followed by retaliatory operations within 7–30 days. State critical infrastructure — water, energy, transportation — and government networks are within the target set.

Fresh APT28 (GRU Unit 26165) malware samples were identified on July 15–16, tagged as targeting government-national entities at confidence level 80. While no new command-and-control infrastructure was identified this cycle, the continued production of fresh samples confirms an ongoing operational tempo against government targets.

ScenarioProbabilityTimeframeBasis
Mass exploitation of Oracle EBS CVE-2026-46817 increases significantly70%7 days1,000+ exposed instances, active exploitation confirmed, CISA's aggressive 3-day deadline signals imminent escalation
Russian-linked destructive or disruptive cyber operation against Western critical infrastructure60%14 daysHistorical retaliation pattern post-sanctions; FSB Center 16 already pre-positioned on routers; DynoWiper precedent
SonicWall CVE-2026-15409 exploitation spreads to criminal actors50%7 daysCVSS 10.0 unauthenticated flaw details propagating; criminal groups historically adopt nation-state exploits within days
Ransomware group targets state/local government using the ClickFix technique45%14 daysActive campaign (ThreatStream ID 1604264) confirmed targeting government; multiple RaaS groups (Akira, LockBit5, Nightspire) updated Jul 13–15
Chinese pre-positioning actors (Volt Typhoon / Salt Typhoon) resume visible operations35%30 daysAbsence of activity during the Western focus on Russia may indicate an operational pause, not cessation

Oracle EBS Exploitation (CVE-2026-46817):

Monitor HTTP requests to Oracle EBS File Transmission endpoints from external IPs, unusual Oracle Payments service-account activity, and unexpected queries against payment tables. Alert on any unauthenticated HTTP POST to Oracle EBS /OA_HTML/ paths associated with the Payments module from non-whitelisted sources.

SharePoint Web Shell Detection (CVE-2026-45659 chain):

Watch for new .aspx files created in SharePoint web directories, unexpected serialized-object uploads, and the SharePoint application-pool account or w3wp.exe spawning cmd.exe or powershell.exe. Apply file-integrity monitoring to C:\inetpub\wwwroot\wss\VirtualDirectories\ and the SharePoint hive directories.

Router Configuration Exfiltration (FSB Center 16):

Alert on SNMP Set-Request packets to external destinations, SNMP traffic to non-management IPs, and configuration transfers via TFTP/FTP to unknown hosts. Flag any SNMP traffic leaving the management VLAN and any Cisco Smart Install activity (TCP/4786) from external sources.

SonicWall SMA1000 Exploitation (CVE-2026-15409):

Monitor the SMA1000 Work Place interface for SSRF indicators — internal RFC1918 addresses appearing in HTTP request parameters — and for the appliance initiating connections to internal hosts outside its normal baseline. Watch AMC console access from non-admin IPs.

Credential Phishing (koyeb[.]app infrastructure):

Block and alert on *.koyeb[.]app subdomains matching the known malicious set at the web proxy and DNS layer; add email-gateway rules for URLs containing koyeb[.]app.

ThreatATT&CK
Oracle EBS ExploitationT1190 T1068
SharePoint Web ShellT1505.003 T1059.001 T1190
Router Configuration ExfiltrationT1602.002 T1595.002 T1557
SonicWall SMA1000 ExploitationT1190 T1071.001
Credential PhishingT1566.002 T1078
IOC Blocking Table:
w1233estern.koyeb[.]app causbsa23w.koyeb[.]app asdwq-causbsa23w.koyeb[.]app

Phishing domains above target Government_and_Taxes credentials — block at web proxy and DNS. APT28 malware hashes (SHA-256), government-national targeting, confidence 80 — ingest to EDR/SIEM and alert on any match: 3277e72d938137018aac63d7d677fd567d67dadd7edf036f12f312c3fd35224e, 9699360e18815be0fa69e042a8ece472fd298aab34fa78f0c2fabf5ae7c3cd0a, 6eef8bf38ae45a1f686c3c9e2f3703f9880b453e037e7d8d1ed05c46667909dd. Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
Is an external attacker abusing Oracle Payments File Transmission?
Alert on unauthenticated POSTs to Oracle EBS /OA_HTML/ Payments paths; review Oracle Payments transaction logs for unauthorized disbursements or account changes since late June 2026, when exploitation began.
HUNT 02 · T1505.003
Has the SharePoint deserialization chain dropped a web shell?
Search for new .aspx files in SharePoint virtual directories, w3wp.exe spawning scripting interpreters, and unexpected serialized-object uploads to SharePoint endpoints.
HUNT 03 · T1602.002
Is FSB Center 16 exfiltrating router configs via SNMP?
Hunt for SNMP Set-Requests leaving the management VLAN, TFTP/FTP configuration transfers to unknown hosts, and Cisco Smart Install activity on TCP/4786 from external sources.
HUNT 04 · T1190
Is a nation-state pivoting inward through the SonicWall SSRF?
Review SMA1000 access logs for internal RFC1918 addresses in URL parameters and for the appliance initiating connections to internal hosts not in its normal baseline.
HUNT 05 · T1566.002
Are staff being phished via koyeb[.]app clones of government logins?
Search proxy and DNS logs for connections to the known koyeb[.]app subdomains and for credential-submission POSTs to those hosts from employee endpoints.

Financial Services
State Treasury, Comptroller, Revenue
Primary threat
CVE-2026-46817 — Oracle E-Business Suite Payments takeover
Actions
  • Verify Oracle EBS version (12.2.3–12.2.15 affected); if unpatched, isolate the Payments File Transmission component from internet access within 24 hours and apply the May 2026 Critical Patch Update
  • Confirm no internet-facing Oracle EBS instances via external attack-surface scan — Shadowserver reports 1,000+ exposed globally
  • Audit Oracle Payments transaction logs for unauthorized disbursements or account modifications since late June 2026
Energy
State-Regulated Utilities, PUC Oversight
Primary threat
FSB Center 16 pre-positioning + ICS vulnerabilities
Actions
  • Issue an advisory to all state-regulated utilities to audit SNMP configurations on all network infrastructure and mandate SNMPv3 migration or complex community strings
  • Patch ABB Ability Edgenius systems for CVE-2026-31431 (privilege escalation, public PoC); update Rockwell 1715-AENTR EtherNet/IP adapters to prevent I/O manipulation
  • Verify OT/IT segmentation — router configuration exfiltration gives adversaries the blueprint to cross segmentation boundaries
Healthcare
State HHS, Medicaid Systems, Public Health
Primary threat
Ransomware (Akira, LockBit5, Nightspire) + SharePoint exploitation
Actions
  • Patch SharePoint instances — health agencies store PHI in SharePoint document libraries, and the deserialization chain (CVE-2026-45659) enables RCE
  • Verify offline backup integrity for Medicaid claims systems; 1VPNS sanctions confirm ransomware groups target hospitals and government health systems
  • Block koyeb[.]app phishing domains agency-wide; audit authorized RMM tools and alert on unauthorized ConnectWise ScreenConnect or MSP360 installations
Government
Executive Agencies, Law Enforcement, Courts
Primary threat
APT28 espionage + credential theft + SharePoint compromise
Actions
  • Ingest APT28 hashes into all endpoint detection platforms — samples are tagged government-national with high confidence
  • Apply SharePoint patches and deploy web-shell detection (file-integrity monitoring on SharePoint directories); government agencies are the primary target of the chain
  • Enforce conditional-access policies requiring compliant devices, block legacy authentication, and prioritize SNMP audit on legacy law-enforcement and court networks
Aviation / Logistics
State DOT, Port Authorities, Airports
Primary threat
Supply-chain compromise via VPN/network appliances + Russian pre-positioning
Actions
  • Patch SonicWall SMA1000 appliances providing remote access to transportation management systems (CVE-2026-15409, CVSS 10.0) and restrict the Work Place interface to internal networks only
  • Prioritize SNMP hardening and Smart Install disablement (TCP/4786) across all DOT and port-authority routers spanning multiple sites with legacy Cisco equipment
  • Treat interconnections with federal systems and private carriers as lateral-movement risk; assess Rockwell EtherNet/IP adapter exposure (1715-AENTR) in OT environments
No sector cards match the selected filters.

Patch Oracle E-Business Suite to the May 2026 CPU level. CVE-2026-46817 (CVSS 9.8) is actively exploited; CISA deadline July 18. Verify Oracle Payments is not internet-exposed.
Incident Responder
Audit ALL Cisco routers for default SNMP community strings — change to complex strings or migrate to SNMPv3 and disable Smart Install (TCP/4786). CISA deadline for CVE-2008-4128: today, July 16.
Incident Responder
Apply the SonicWall SMA1000 firmware update per SNWLID-2026-0008. CVE-2026-15409 (CVSS 10.0) is an unauthenticated SSRF; restrict the Work Place interface to internal-only until patched.
Incident Responder
Deploy SharePoint web-shell detection — file-integrity monitoring on SharePoint web directories; alert on w3wp.exe spawning cmd.exe/powershell.exe; monitor for new .aspx files in virtual directories.
SOC Analyst
Block koyeb[.]app phishing domains at web proxy and DNS: w1233estern.koyeb[.]app, causbsa23w.koyeb[.]app, asdwq-causbsa23w.koyeb[.]app.
SOC Analyst
No immediate actions for the selected roles.
Ingest APT28 IOCs (3 SHA-256 hashes) into SIEM and EDR; configure high-priority escalation on any endpoint match.
SOC Analyst
Patch Linux servers (RHEL) for CVE-2026-31431 — kernel privilege escalation with public PoC. Prioritize servers in OT/SCADA management zones; apply RHSA errata.
Incident ResponderICS / OT
Apply SharePoint security patches (May/June 2026 cumulative updates) addressing CVE-2026-45659, CVE-2026-32201, CVE-2026-45660 across all on-premises and hybrid instances.
Incident Responder
Audit authorized RMM tools — create an allowlist of approved remote-management software; alert on ConnectWise ScreenConnect or MSP360 installations outside authorized deployments.
SOC Analyst
Enforce conditional-access policies blocking legacy authentication and requiring device compliance for all Azure AD/Entra ID sign-ins; review device-code authentication restrictions.
IAM Analyst
No 7-day actions for the selected roles.
Brief executive leadership on Russian retaliatory cyber risk. Coordinated US/UK/EU sanctions against 24+ entities historically precede retaliatory operations within 30 days; recommend an elevated monitoring posture for critical infrastructure.
CISO / Exec
Establish a pre-authorized emergency patching protocol. Six KEV additions in 48 hours with 3-day deadlines is unsustainable under current change management; propose standing authorization for CISA KEV patches on critical systems.
CISO / Exec
Commission an external assessment of OT/IT segmentation for state-regulated utilities. FSB Center 16's router configuration exfiltration provides the blueprint to cross network boundaries.
CISO / ExecICS / OT
Update incident-response playbooks for destructive-malware (wiper) scenarios. The DynoWiper precedent against Poland's grid confirms FSB Center 16's destructive capability; run a tabletop exercise within 30 days.
Incident Responder
Assess Volt Typhoon / Salt Typhoon exposure. Chinese pre-positioning actors have been quiet during the Western focus on Russia — proactively hunt for living-off-the-land techniques on SOHO routers and edge infrastructure.
CISO / ExecThreat Hunter
No 30-day actions for the selected roles.
The Bottom Line

The convergence of six actively exploited vulnerabilities, coordinated Western sanctions against Russian cyber units, and confirmed nation-state targeting of government infrastructure creates a threat environment that demands immediate executive attention and operational action. When Western governments impose coordinated cyber sanctions of this magnitude, retaliatory operations have historically followed — and state critical infrastructure is within the target set.

1
Patch or isolate Oracle EBS before Saturday — an unauthenticated attacker can take over your state's payment systems, and the CISA deadline reflects intelligence of imminent mass exploitation.
2
Audit every router for default SNMP strings by end of day — the FBI confirms FSB Center 16, the unit that destroyed Poland's grid, is actively scanning U.S. government networks for exactly this weakness.
3
Restrict external access to your SonicWall VPN appliances now — a CVSS 10.0 target that, if unpatched, is compromised or soon will be.
No items found.