TLP:GREEN  ·  States / Public Sector
SonicWall Zero-Day, SharePoint RCE Chain, and a Record Patch Tuesday Converge:

What State CISOs Must Do in the Next 24 Hours

ELEVATED. State government IT leaders face an unprecedented remediation window. A confirmed, actively-exploited CVSS 10.0 zero-day in SonicWall SMA 1000 appliances, a three-CVE SharePoint chain including unauthenticated remote code execution, and Microsoft’s largest-ever Patch Tuesday (570 vulnerabilities) have converged in a single 24-hour window — while attackers weaponize legitimate ConnectWise ScreenConnect and MSP360 remote-management tools as phishing payloads. CISA has added the critical flaws to its Known Exploited Vulnerabilities catalog. For agencies running SonicWall SMA or SharePoint, the time to act is measured in hours.

I am a
My sector

DevelopmentDateWhy It Matters
SonicWall confirms active exploitation of CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2) in SMA 1000 appliances; CISA adds to KEV2026-07-14Any state agency using SMA 1000 for VPN is potentially compromised
CISA issues urgent SharePoint hardening advisory citing active exploitation of CVE-2026-32201, CVE-2026-45659, CVE-2026-209632026-07-14SharePoint hybrid environments (common in state gov) face unauthenticated RCE
Microsoft releases record 570-patch Patch Tuesday with 3 confirmed exploited zero-days2026-07-14Massive remediation backlog; prioritization is critical
CISA publishes 4 ICS advisories: ABB Ability Edgenius (CVE-2026-31431), ABB Advant Master, ABB T-MAC Plus, Rockwell 1715-AENTR2026-07-14Water/wastewater SCADA partnerships at risk; PoC available for the kernel vuln
Miasma npm supply-chain campaign identified: AsyncAPI packages trojanized, ~1,500 downloads, cloud credential theft2026-07-14Developer and logistics/cloud toolchains at risk; supply-chain vector active
Cofense identifies dual phishing campaigns weaponizing ConnectWise ScreenConnect and MSP360 RMM tools2026-07-15Legitimate MSP tools used as payloads bypass EDR and application whitelists
White House announces “Gold Eagle” AI cyber-defense coordination platform2026-07-15Policy signal: state CI operators may face new participation requirements by August

DateEventActor / CVEImpact
2025-12Destructive ICS attack (DynoWiper) on Poland power gridFSB Center 16 (Russia)Formally attributed 2026-07-13; same unit scanning U.S. gov routers
2026-06Destructive breach of California water utilityVOID MANTICORE (Iran/IRGC)Confirmed; demonstrates state-level CI targeting
2026-07-13EU/UK sanctions against FSB Center 16 (33+ entities)FSB Center 16Escalation risk: sanctioned actors may intensify operations
2026-07-14SonicWall SMA dual zero-day exploitation beginsUnattributed (Volexity investigating)Active exploitation confirmed
2026-07-14SharePoint 3-CVE chain exploitationUnattributedActive exploitation confirmed; CISA KEV
2026-07-14Miasma npm supply-chain campaign (AsyncAPI trojanized)Unattributed~1,500 downloads; cloud credential theft
2026-07-15RMM tool phishing campaigns (ConnectWise + MSP360)UnattributedActive campaigns with fresh IOCs

Why it matters for state government: SonicWall SMA appliances are widely deployed across state agencies for remote-workforce VPN access. The chain requires no authentication — an unauthenticated attacker exploits CVE-2026-15409 (SSRF, CVSS 10.0) for initial access, then chains CVE-2026-15410 (post-auth OS command injection, CVSS 7.2) for full system compromise.

Affected: SMA 1000 models 6210, 7210, 8200v running 12.4.3-03245–12.4.3-03434 and 12.5.0-02283–12.5.0-02800. Fixed: 12.4.3-03453+ or 12.5.0-02835+.

Attribution: currently unattributed. Volexity’s involvement is a strong indicator of nation-state activity; attribution may emerge within 72 hours. IOCs: unusual login/logout API requests, suspicious WebSocket proxy connections, hotfix rollback via path traversal, unauthorized API routes.

T1190T1059.004T1556

Why it matters for state government: most state agencies run SharePoint in hybrid configurations (on-premises servers federated with SharePoint Online). The exploitation chain combines three vulnerabilities:

CVETypeCVSSAuth RequiredKEV Status
CVE-2026-20963Deserialization RCE9.8NoIn KEV
CVE-2026-45659Deserialization RCE8.8YesIn KEV
CVE-2026-32201Input validation / spoofing6.5YesIn KEV

The critical concern is CVE-2026-20963: unauthenticated RCE on internet-facing SharePoint, exploitable without credentials. Post-exploitation typically involves PowerShell execution and web-shell deployment for persistence. Cross-domain risk: a compromised on-prem SharePoint server in a hybrid environment becomes a pivot into the Azure/M365 tenant — lateral movement to cloud resources, email, and potential ransomware deployment.

T1190T1059.001T1505.003

Why it matters for state government: state agencies routinely authorize MSP partners to use remote-management tools. When attackers deploy the same tools as their payload, malicious traffic is indistinguishable from legitimate MSP activity, and EDR often whitelists these signed binaries.

Campaign 1 — ConnectWise ScreenConnect: French-language phishing → OAuth redirect via Google → VBS dropper → ScreenConnect MSI install; C2 at houndsregimeskid[.]com (port 8041). Campaign 2 — MSP360: “Warm Invitation” PDF → fake Adobe update → MSP360 agent install; C2 at client[.]rmm[.]mspbackups[.]com, rm[.]mspbackups[.]com.

Critical question for state CISOs: do you have a complete inventory of which RMM tools are authorized, which hosts should reach their relay servers, and alerting for unauthorized RMM installations?

T1219T1204.002T1566.001

Four ICS advisories in a single day affect equipment common in municipal water/wastewater systems that state agencies oversee or partner with: ABB Ability Edgenius (CVE-2026-31431, Linux kernel privilege escalation, CVSS 7.8, public PoC), ABB Advant Master, ABB T-MAC Plus, and Rockwell 1715-AENTR (EtherNet/IP adapter allowing file read/delete, memory modification, and I/O manipulation).

Combined with the confirmed VOID MANTICORE breach of a California water utility (June 2026) and FSB Center 16’s demonstrated willingness to conduct destructive attacks on power infrastructure (DynoWiper, December 2025), the ICS threat to state-partnered utilities is concrete and current.

ActorAttributionCurrent StatusConcern
FSB Center 16Russian FSBScanning U.S. gov routers; sanctioned Jul 13Destructive capability proven (DynoWiper)
VOID MANTICOREIranian IRGCConfirmed CA water utility breach Jun 2026Destructive intent against U.S. CI
Volt TyphoonChinese PLASilent — multiple cyclesPre-positioning may be complete; LOTL evades detection
Salt TyphoonChinese MSSSilent — multiple cyclesTelecom/ISP targeting could affect state network transit
SCATTERED SPIDERCybercriminalQuiet — no recent vishing/Entra activitySummer staffing rotations create help-desk vulnerability

The silence of Volt Typhoon and Salt Typhoon is not reassuring. These actors specialize in living-off-the-land techniques that blend with normal administrative activity; their absence from reporting may indicate successful concealment rather than an operational pause.

T1078T1072T1003.003

The White House’s “Gold Eagle” announcement signals that state critical-infrastructure operators may face new requirements to participate in AI-driven vulnerability scanning and coordinated response. An AI model pre-release government review framework is expected by early August 2026. State CISOs should engage legal and policy teams now to understand potential participation obligations and data-sharing implications.

ScenarioProbabilityBasis
Attribution of the SonicWall zero-day exploitation to a nation-state actor75%Within 72 hours — Volexity involvement pattern; severity suggests an APT-level operator
Additional SonicWall SMA exploitation IOCs (IPs/domains) published80%Within 48 hours — Volexity/SonicWall investigation ongoing; IOC release typical within days
RMM tool abuse campaigns expand to target state government help desks60%Within 14 days — dual campaigns in a single day suggest a trend; state MSP relationships create attack surface
SharePoint exploitation chain linked to a ransomware or espionage campaign50%Within 7 days — unauthenticated RCE + deserialization chain is an ideal ransomware entry point
Volt Typhoon activity detected in state government network infrastructure30%Within 30 days — prolonged silence plus known pre-positioning doctrine equals elevated latent risk
AI-autonomous ransomware (JadePuffer paradigm) targets state/local government25%Within 30 days — paradigm proven, but current targeting is opportunistic (cloud databases)

SonicWall SMA Compromise Indicators:

Monitor login/logout API endpoint request patterns, WebSocket proxy connections, hotfix rollback attempts via path traversal, and unauthorized API-route access. Pull SMA access logs for the past 30 days and search for these behavioral indicators. If the SMA version is vulnerable and cannot be patched immediately, restrict the management interface to internal-only and implement IP allowlisting.

SharePoint Web Shell Detection:

Watch for new .aspx/.asmx files in SharePoint web directories, PowerShell spawned by w3wp.exe, unusual IIS worker-process behavior, and new scheduled tasks on SharePoint servers. Baseline file integrity and alert on any new executable content in web-accessible directories; review IIS logs for POST requests to unusual endpoints with large request bodies (deserialization payloads).

Unauthorized RMM Tool Detection:

Monitor ScreenConnect relay connections (default port 8041), MSP360 agent traffic to mspbackups[.]com domains, new service installations matching RMM patterns, and VBS/MSI execution chains. Query EDR for all ScreenConnect and MSP360 installations in the past 7 days and compare against the authorized MSP tool inventory — any install on a host not managed by an authorized MSP is suspicious.

Volt Typhoon / Salt Typhoon Living-off-the-Land Hunt:

Hunt for unusual use of valid accounts, software deployment tools, and ntdsutil, netsh, wmic, and PowerShell by service accounts or from unexpected source hosts. Schedule a 30-day proactive hunt and correlate administrative tool usage against change-management tickets, flagging any discrepancies.

ThreatATT&CK
SonicWall SMA CompromiseT1190 T1059.004 T1556
SharePoint Web ShellT1190 T1059.001 T1505.003
Unauthorized RMM ToolsT1219 T1204.002 T1566.001 T1566.002
Volt/Salt Typhoon LOTLT1078 T1072 T1003.003 T1059.001
IOC Blocking Table:
houndsregimeskid[.]com titledocs00707133908080[.]com shadow0527[.]github[.]io infolet[.]org pub-fbe607a57d3a46a2886f1858f38d0bae[.]r2[.]dev client[.]rmm[.]mspbackups[.]com rm[.]mspbackups[.]com

ConnectWise ScreenConnect infrastructure: houndsregimeskid[.]com (C2, port 8041), titledocs00707133908080[.]com (phishing), shadow0527[.]github[.]io (staging). MSP360 infrastructure: infolet[.]org (delivery), pub-fbe607a57d3a46a2886f1858f38d0bae[.]r2[.]dev (payload hosting), client[.]rmm[.]mspbackups[.]com / rm[.]mspbackups[.]com (C2). Malware hashes (MD5): 16564e962e1e3f75625acde88a6aae80 (dropper VBS), d77ad8069a8c516b634563f7dbc9b182 (archive), b398033895b64ce505729fafa106043c (ScreenConnect installer), b6104630ee79cf34fbdea983fa7b17ca (lure PDF), 300c93aeb6144b9d796e8da02d2cbe0f (fake Adobe update). Before blocking mspbackups[.]com domains, verify whether any authorized MSP partners use MSP360 in your environment — if so, create granular rules allowing only managed hosts to reach legitimate MSP360 infrastructure. Additional IOCs available via Anomali ThreatStream and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
SMA appliance exploited via SSRF for initial access?
Search for anomalous API calls to internal management endpoints from external source IPs, followed by shell command execution and potential TOTP re-enrollment events.
HUNT 02 · T1505.003
SharePoint compromised via deserialization, web shell dropped?
Search for w3wp.exe spawning cmd.exe or powershell.exe, new files written to inetpub or SharePoint hive directories, and outbound connections from the SharePoint server to unusual destinations.
HUNT 03 · T1219
Phishing payload installed an unauthorized RMM tool?
Search for a VBS or MSI execution followed by new service registration, then outbound HTTPS connections to relay infrastructure not on your authorized RMM list.
HUNT 04 · T1078
Pre-positioned nation-state actor operating via LOTL?
Search for administrative tool usage from non-admin workstations, service-account authentication from unusual source IPs, and lateral-movement patterns that don’t match your change-management schedule.

Financial Services
State Treasury, Revenue, Comptroller
Primary threat
SharePoint exploitation chain (CVE-2026-20963) could expose financial records, tax data, and procurement systems hosted on SharePoint
Secondary threat
RMM tool abuse targeting financial system administrators
Actions
  • Isolate SharePoint servers hosting financial data from internet-facing SharePoint instances; apply the CVE-2026-20963 patch as an emergency priority
  • Review SharePoint permissions so financial document libraries use least-privilege access
  • Include treasury/revenue IT staff in phishing awareness for fake Adobe/document lures
Energy
State Energy Office, Utility Oversight, Grid Coordination
Primary threat
FSB Center 16 demonstrated destructive capability (DynoWiper vs. Poland’s grid) and is scanning U.S. gov infrastructure; VOID MANTICORE confirmed destructive breach of a California water utility
Secondary threat
ABB Ability Edgenius (CVE-2026-31431, public PoC); energy operators may be early Gold Eagle scanning participants
Actions
  • Coordinate with regulated utilities on ABB Ability Edgenius patching; verify network segmentation between IT and OT environments
  • Ensure out-of-band communication plans exist for grid coordination if primary networks are disrupted
  • Begin internal assessment of which systems would be in scope for the AI vulnerability-scanning framework
Healthcare
State Health Dept, Medicaid, Public Health Labs
Primary threat
Ransomware operators (AiLock, Akira, Nightspire) actively target healthcare and government; SharePoint compromise could expose PHI subject to HIPAA
Secondary threat
Healthcare IT often uses RMM tools for distributed clinic support — ConnectWise ScreenConnect exposure
Actions
  • Prioritize SharePoint patching for instances hosting PHI or Medicaid data
  • Ensure IR plans account for ransomware encrypting both clinical and administrative systems; verify backup integrity for Medicaid claims processing
  • Audit the RMM tool inventory with particular attention to ConnectWise ScreenConnect deployments
Government
Executive Agencies, Legislature, Courts, Elections
Primary threat
Nation-state pre-positioning (Volt Typhoon’s silence is concerning); credential phishing via RMM tools; SharePoint is the primary collaboration platform for most state agencies
Secondary threat
Gold Eagle framework and the AI executive order may require legislative action or appropriation
Actions
  • Emergency SharePoint patching across all agency instances; reinforce help-desk verification against social engineering (SCATTERED SPIDER TTPs)
  • Conduct a proactive hunt for LOTL indicators in Active Directory and network infrastructure; ensure election-related SharePoint sites are patched and monitored with enhanced logging
  • Brief legislative IT leadership on potential Gold Eagle requirements
Aviation / Logistics
State DOT, Airport Authorities, Port Systems
Primary threat
Supply-chain compromise via trojanized npm packages (Miasma) could affect logistics apps; Rockwell 1715-AENTR affects industrial Ethernet adapters used in transportation SCADA
Secondary threat
Transportation agencies with distributed field offices often use SonicWall SMA appliances for remote connectivity
Actions
  • Audit any custom Node.js applications used in logistics/transportation management for AsyncAPI package dependencies
  • Coordinate with airport and port authorities on Rockwell firmware verification; segment transportation management systems from administrative IT
  • Verify all SMA instances are identified and patched
No sector cards match the selected filters.

Patch all SonicWall SMA 1000 appliances to 12.4.3-03453+ or 12.5.0-02835+. If patching is not possible within 24 hours, restrict the management interface to internal access only and implement IP allowlisting. CVSS 10.0, actively exploited, CISA KEV deadline imminent.
Incident Responder
Apply SharePoint Server security updates — prioritize CVE-2026-20963 (unauthenticated RCE, CVSS 9.8) and CVE-2026-45659 (deserialization RCE, CVSS 8.8). Both are in CISA KEV with confirmed active exploitation.
Incident Responder
Block phishing campaign IOCs at email gateway, DNS, and web proxy — houndsregimeskid[.]com, titledocs00707133908080[.]com, infolet[.]org, and pub-fbe607a57d3a46a2886f1858f38d0bae[.]r2[.]dev.
SOC Analyst
Hunt for SonicWall SMA compromise indicators in existing logs: anomalous login/logout API requests, WebSocket proxy connections, hotfix rollback via path traversal, unauthorized API routes. Assume compromise if running vulnerable versions.
SOC Analyst
No immediate actions for the selected roles.
Audit all RMM tools in the environment — create a definitive inventory of authorized platforms (ConnectWise, MSP360, AnyDesk, TeamViewer, etc.), their legitimate relay-server domains, and which hosts should communicate with them. Implement application control to block unauthorized RMM installations.
SOC Analyst
Coordinate with municipal water/wastewater partners to verify ABB Ability Edgenius, ABB Advant Master, ABB T-MAC Plus, and Rockwell 1715-AENTR firmware versions. Apply vendor patches per CISA ICS advisories — CVE-2026-31431 has a public PoC, treat as high priority.
ICS / OTIncident Responder
Review SonicWall SMA logs for the past 30 days for behavioral indicators of prior compromise — the zero-day may have been exploited before public disclosure.
SOC Analyst
Triage remaining Patch Tuesday updates with a risk-tiered approach: Tier 1 (actively exploited/KEV) done now; Tier 2 (CVSS ≥9.0) this week; Tier 3 standard 14-day cycle. Request extended maintenance windows from agency leadership.
Incident Responder
Reinforce social-engineering awareness for help-desk staff — summer staffing rotations increase vishing risk (SCATTERED SPIDER TTPs). Verify all password-reset and MFA re-enrollment requests through out-of-band confirmation.
IAM Analyst
No 7-day actions for the selected roles.
Conduct a proactive threat hunt for Volt Typhoon / Salt Typhoon living-off-the-land indicators: valid account abuse (T1078), software deployment tool misuse (T1072), unusual administrative tool execution, and service-account authentication anomalies. Correlate against change-management records.
Threat Hunter
Assess Gold Eagle participation requirements — the AI model pre-release government review framework is expected by early August. Engage legal and policy teams on obligations, data-sharing implications, and budget requirements for state CI operators.
CISO / Exec
Implement a risk-tiered patching SLA as formal policy: Tier 1 (actively exploited/KEV) = 24 hours; Tier 2 (CVSS ≥9.0, no confirmed exploitation) = 72 hours; Tier 3 = 14 days.
Incident ResponderCISO / Exec
Review SharePoint hybrid architecture for segmentation between on-prem servers and the Azure/M365 tenant — a compromised on-prem server should not grant unfettered cloud access. Implement conditional access and network segmentation.
Incident Responder
Update incident response playbooks for: (a) VPN appliance zero-day compromise with possible nation-state attribution; (b) SharePoint compromise leading to ransomware; (c) legitimate RMM tool abuse requiring differentiation from authorized MSP activity. Tabletop these with agency leadership.
Incident ResponderCISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

Three realities demand immediate executive attention. Your SonicWall SMA appliances may already be compromised — a CVSS 10.0 vulnerability requiring no authentication is under active exploitation, and Volexity’s involvement points to a sophisticated adversary. The trust model for remote-management tools is broken: when attackers deploy the same ConnectWise ScreenConnect and MSP360 agents your MSP partners use legitimately, EDR cannot tell friend from foe. And the remediation math doesn’t work at current velocity — 570 Microsoft patches plus SonicWall emergency fixes plus four ICS advisories in a single day exceeds any agency’s normal capacity. Against the nation-state backdrop — FSB Center 16 scanning U.S. government routers, VOID MANTICORE breaching U.S. water utilities, Volt Typhoon’s conspicuous silence — any unpatched vulnerability is a potential foothold for adversaries with destructive intent.

1
Patch SonicWall SMA and SharePoint today. If you cannot patch immediately, pull the appliance off the internet.
2
Build an authoritative RMM inventory and block everything else; block the phishing IOCs and hunt for what’s already inside.
3
Authorize emergency maintenance windows — the threat actors exploiting these flaws are not waiting for your next scheduled window.
No items found.