| Development | Date | Why It Matters |
|---|---|---|
SonicWall confirms active exploitation of CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) in SMA 1000 appliances; CISA adds to KEV | 2026-07-14 | Any state agency using SMA 1000 for VPN is potentially compromised |
CISA issues urgent SharePoint hardening advisory citing active exploitation of CVE-2026-32201, CVE-2026-45659, CVE-2026-20963 | 2026-07-14 | SharePoint hybrid environments (common in state gov) face unauthenticated RCE |
| Microsoft releases record 570-patch Patch Tuesday with 3 confirmed exploited zero-days | 2026-07-14 | Massive remediation backlog; prioritization is critical |
CISA publishes 4 ICS advisories: ABB Ability Edgenius (CVE-2026-31431), ABB Advant Master, ABB T-MAC Plus, Rockwell 1715-AENTR | 2026-07-14 | Water/wastewater SCADA partnerships at risk; PoC available for the kernel vuln |
| Miasma npm supply-chain campaign identified: AsyncAPI packages trojanized, ~1,500 downloads, cloud credential theft | 2026-07-14 | Developer and logistics/cloud toolchains at risk; supply-chain vector active |
| Cofense identifies dual phishing campaigns weaponizing ConnectWise ScreenConnect and MSP360 RMM tools | 2026-07-15 | Legitimate MSP tools used as payloads bypass EDR and application whitelists |
| White House announces “Gold Eagle” AI cyber-defense coordination platform | 2026-07-15 | Policy signal: state CI operators may face new participation requirements by August |
| Date | Event | Actor / CVE | Impact |
|---|---|---|---|
| 2025-12 | Destructive ICS attack (DynoWiper) on Poland power grid | FSB Center 16 (Russia) | Formally attributed 2026-07-13; same unit scanning U.S. gov routers |
| 2026-06 | Destructive breach of California water utility | VOID MANTICORE (Iran/IRGC) | Confirmed; demonstrates state-level CI targeting |
| 2026-07-13 | EU/UK sanctions against FSB Center 16 (33+ entities) | FSB Center 16 | Escalation risk: sanctioned actors may intensify operations |
| 2026-07-14 | SonicWall SMA dual zero-day exploitation begins | Unattributed (Volexity investigating) | Active exploitation confirmed |
| 2026-07-14 | SharePoint 3-CVE chain exploitation | Unattributed | Active exploitation confirmed; CISA KEV |
| 2026-07-14 | Miasma npm supply-chain campaign (AsyncAPI trojanized) | Unattributed | ~1,500 downloads; cloud credential theft |
| 2026-07-15 | RMM tool phishing campaigns (ConnectWise + MSP360) | Unattributed | Active campaigns with fresh IOCs |
Why it matters for state government: SonicWall SMA appliances are widely deployed across state agencies for remote-workforce VPN access. The chain requires no authentication — an unauthenticated attacker exploits CVE-2026-15409 (SSRF, CVSS 10.0) for initial access, then chains CVE-2026-15410 (post-auth OS command injection, CVSS 7.2) for full system compromise.
Affected: SMA 1000 models 6210, 7210, 8200v running 12.4.3-03245–12.4.3-03434 and 12.5.0-02283–12.5.0-02800. Fixed: 12.4.3-03453+ or 12.5.0-02835+.
Attribution: currently unattributed. Volexity’s involvement is a strong indicator of nation-state activity; attribution may emerge within 72 hours. IOCs: unusual login/logout API requests, suspicious WebSocket proxy connections, hotfix rollback via path traversal, unauthorized API routes.
Why it matters for state government: most state agencies run SharePoint in hybrid configurations (on-premises servers federated with SharePoint Online). The exploitation chain combines three vulnerabilities:
| CVE | Type | CVSS | Auth Required | KEV Status |
|---|---|---|---|---|
| CVE-2026-20963 | Deserialization RCE | 9.8 | No | In KEV |
| CVE-2026-45659 | Deserialization RCE | 8.8 | Yes | In KEV |
| CVE-2026-32201 | Input validation / spoofing | 6.5 | Yes | In KEV |
The critical concern is CVE-2026-20963: unauthenticated RCE on internet-facing SharePoint, exploitable without credentials. Post-exploitation typically involves PowerShell execution and web-shell deployment for persistence. Cross-domain risk: a compromised on-prem SharePoint server in a hybrid environment becomes a pivot into the Azure/M365 tenant — lateral movement to cloud resources, email, and potential ransomware deployment.
Why it matters for state government: state agencies routinely authorize MSP partners to use remote-management tools. When attackers deploy the same tools as their payload, malicious traffic is indistinguishable from legitimate MSP activity, and EDR often whitelists these signed binaries.
Campaign 1 — ConnectWise ScreenConnect: French-language phishing → OAuth redirect via Google → VBS dropper → ScreenConnect MSI install; C2 at houndsregimeskid[.]com (port 8041). Campaign 2 — MSP360: “Warm Invitation” PDF → fake Adobe update → MSP360 agent install; C2 at client[.]rmm[.]mspbackups[.]com, rm[.]mspbackups[.]com.
Critical question for state CISOs: do you have a complete inventory of which RMM tools are authorized, which hosts should reach their relay servers, and alerting for unauthorized RMM installations?
Four ICS advisories in a single day affect equipment common in municipal water/wastewater systems that state agencies oversee or partner with: ABB Ability Edgenius (CVE-2026-31431, Linux kernel privilege escalation, CVSS 7.8, public PoC), ABB Advant Master, ABB T-MAC Plus, and Rockwell 1715-AENTR (EtherNet/IP adapter allowing file read/delete, memory modification, and I/O manipulation).
Combined with the confirmed VOID MANTICORE breach of a California water utility (June 2026) and FSB Center 16’s demonstrated willingness to conduct destructive attacks on power infrastructure (DynoWiper, December 2025), the ICS threat to state-partnered utilities is concrete and current.
| Actor | Attribution | Current Status | Concern |
|---|---|---|---|
| FSB Center 16 | Russian FSB | Scanning U.S. gov routers; sanctioned Jul 13 | Destructive capability proven (DynoWiper) |
| VOID MANTICORE | Iranian IRGC | Confirmed CA water utility breach Jun 2026 | Destructive intent against U.S. CI |
| Volt Typhoon | Chinese PLA | Silent — multiple cycles | Pre-positioning may be complete; LOTL evades detection |
| Salt Typhoon | Chinese MSS | Silent — multiple cycles | Telecom/ISP targeting could affect state network transit |
| SCATTERED SPIDER | Cybercriminal | Quiet — no recent vishing/Entra activity | Summer staffing rotations create help-desk vulnerability |
The silence of Volt Typhoon and Salt Typhoon is not reassuring. These actors specialize in living-off-the-land techniques that blend with normal administrative activity; their absence from reporting may indicate successful concealment rather than an operational pause.
The White House’s “Gold Eagle” announcement signals that state critical-infrastructure operators may face new requirements to participate in AI-driven vulnerability scanning and coordinated response. An AI model pre-release government review framework is expected by early August 2026. State CISOs should engage legal and policy teams now to understand potential participation obligations and data-sharing implications.
| Scenario | Probability | Basis |
|---|---|---|
| Attribution of the SonicWall zero-day exploitation to a nation-state actor | 75% | Within 72 hours — Volexity involvement pattern; severity suggests an APT-level operator |
| Additional SonicWall SMA exploitation IOCs (IPs/domains) published | 80% | Within 48 hours — Volexity/SonicWall investigation ongoing; IOC release typical within days |
| RMM tool abuse campaigns expand to target state government help desks | 60% | Within 14 days — dual campaigns in a single day suggest a trend; state MSP relationships create attack surface |
| SharePoint exploitation chain linked to a ransomware or espionage campaign | 50% | Within 7 days — unauthenticated RCE + deserialization chain is an ideal ransomware entry point |
| Volt Typhoon activity detected in state government network infrastructure | 30% | Within 30 days — prolonged silence plus known pre-positioning doctrine equals elevated latent risk |
| AI-autonomous ransomware (JadePuffer paradigm) targets state/local government | 25% | Within 30 days — paradigm proven, but current targeting is opportunistic (cloud databases) |
Monitor login/logout API endpoint request patterns, WebSocket proxy connections, hotfix rollback attempts via path traversal, and unauthorized API-route access. Pull SMA access logs for the past 30 days and search for these behavioral indicators. If the SMA version is vulnerable and cannot be patched immediately, restrict the management interface to internal-only and implement IP allowlisting.
Watch for new .aspx/.asmx files in SharePoint web directories, PowerShell spawned by w3wp.exe, unusual IIS worker-process behavior, and new scheduled tasks on SharePoint servers. Baseline file integrity and alert on any new executable content in web-accessible directories; review IIS logs for POST requests to unusual endpoints with large request bodies (deserialization payloads).
Monitor ScreenConnect relay connections (default port 8041), MSP360 agent traffic to mspbackups[.]com domains, new service installations matching RMM patterns, and VBS/MSI execution chains. Query EDR for all ScreenConnect and MSP360 installations in the past 7 days and compare against the authorized MSP tool inventory — any install on a host not managed by an authorized MSP is suspicious.
Hunt for unusual use of valid accounts, software deployment tools, and ntdsutil, netsh, wmic, and PowerShell by service accounts or from unexpected source hosts. Schedule a 30-day proactive hunt and correlate administrative tool usage against change-management tickets, flagging any discrepancies.
| Threat | ATT&CK |
|---|---|
| SonicWall SMA Compromise | T1190 T1059.004 T1556 |
| SharePoint Web Shell | T1190 T1059.001 T1505.003 |
| Unauthorized RMM Tools | T1219 T1204.002 T1566.001 T1566.002 |
| Volt/Salt Typhoon LOTL | T1078 T1072 T1003.003 T1059.001 |
ConnectWise ScreenConnect infrastructure: houndsregimeskid[.]com (C2, port 8041), titledocs00707133908080[.]com (phishing), shadow0527[.]github[.]io (staging). MSP360 infrastructure: infolet[.]org (delivery), pub-fbe607a57d3a46a2886f1858f38d0bae[.]r2[.]dev (payload hosting), client[.]rmm[.]mspbackups[.]com / rm[.]mspbackups[.]com (C2). Malware hashes (MD5): 16564e962e1e3f75625acde88a6aae80 (dropper VBS), d77ad8069a8c516b634563f7dbc9b182 (archive), b398033895b64ce505729fafa106043c (ScreenConnect installer), b6104630ee79cf34fbdea983fa7b17ca (lure PDF), 300c93aeb6144b9d796e8da02d2cbe0f (fake Adobe update). Before blocking mspbackups[.]com domains, verify whether any authorized MSP partners use MSP360 in your environment — if so, create granular rules allowing only managed hosts to reach legitimate MSP360 infrastructure. Additional IOCs available via Anomali ThreatStream and partner feeds.
w3wp.exe spawning cmd.exe or powershell.exe, new files written to inetpub or SharePoint hive directories, and outbound connections from the SharePoint server to unusual destinations.CVE-2026-20963) could expose financial records, tax data, and procurement systems hosted on SharePoint- Isolate SharePoint servers hosting financial data from internet-facing SharePoint instances; apply the CVE-2026-20963 patch as an emergency priority
- Review SharePoint permissions so financial document libraries use least-privilege access
- Include treasury/revenue IT staff in phishing awareness for fake Adobe/document lures
CVE-2026-31431, public PoC); energy operators may be early Gold Eagle scanning participants- Coordinate with regulated utilities on ABB Ability Edgenius patching; verify network segmentation between IT and OT environments
- Ensure out-of-band communication plans exist for grid coordination if primary networks are disrupted
- Begin internal assessment of which systems would be in scope for the AI vulnerability-scanning framework
- Prioritize SharePoint patching for instances hosting PHI or Medicaid data
- Ensure IR plans account for ransomware encrypting both clinical and administrative systems; verify backup integrity for Medicaid claims processing
- Audit the RMM tool inventory with particular attention to ConnectWise ScreenConnect deployments
- Emergency SharePoint patching across all agency instances; reinforce help-desk verification against social engineering (SCATTERED SPIDER TTPs)
- Conduct a proactive hunt for LOTL indicators in Active Directory and network infrastructure; ensure election-related SharePoint sites are patched and monitored with enhanced logging
- Brief legislative IT leadership on potential Gold Eagle requirements
- Audit any custom Node.js applications used in logistics/transportation management for AsyncAPI package dependencies
- Coordinate with airport and port authorities on Rockwell firmware verification; segment transportation management systems from administrative IT
- Verify all SMA instances are identified and patched
CVE-2026-20963 (unauthenticated RCE, CVSS 9.8) and CVE-2026-45659 (deserialization RCE, CVSS 8.8). Both are in CISA KEV with confirmed active exploitation.houndsregimeskid[.]com, titledocs00707133908080[.]com, infolet[.]org, and pub-fbe607a57d3a46a2886f1858f38d0bae[.]r2[.]dev.CVE-2026-31431 has a public PoC, treat as high priority.Three realities demand immediate executive attention. Your SonicWall SMA appliances may already be compromised — a CVSS 10.0 vulnerability requiring no authentication is under active exploitation, and Volexity’s involvement points to a sophisticated adversary. The trust model for remote-management tools is broken: when attackers deploy the same ConnectWise ScreenConnect and MSP360 agents your MSP partners use legitimately, EDR cannot tell friend from foe. And the remediation math doesn’t work at current velocity — 570 Microsoft patches plus SonicWall emergency fixes plus four ICS advisories in a single day exceeds any agency’s normal capacity. Against the nation-state backdrop — FSB Center 16 scanning U.S. government routers, VOID MANTICORE breaching U.S. water utilities, Volt Typhoon’s conspicuous silence — any unpatched vulnerability is a potential foothold for adversaries with destructive intent.