TLP:GREEN  ·  States / Public Sector
State Government Cyber Threat Escalation:

Active Zero-Day Exploitation, Supply Chain Compromise, and Critical Infrastructure Attacks Demand Immediate Action

HIGH. Escalated from ELEVATED (August 2, 2026). Confirmed active exploitation of SonicWall SMA1000 zero-days is delivering ransomware directly against U.S. government entities, a critical authentication bypass in N-able N-central RMM grants unauthenticated "god-mode" access to managed service provider consoles, and Iran-linked water sector PLC attacks have expanded to seven or more U.S. states. These are not theoretical risks — they are active operations targeting government infrastructure today.

I am a
My sector

DateDevelopmentWhy It Matters
2026-08-03INC Ransomware accelerated exploitation of two chained SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410), posting new government-sector victims to their data leak siteThe exploit chain achieves root access from an unauthenticated position, harvesting LDAP credentials for rapid lateral movement
2026-08-01CVE-2026-18577 — a critical authentication bypass in N-able N-central RMM — is confirmed under active exploitationA single compromised MSP console grants full administrative control over every managed endpoint, including state agency systems
2026-08-02APT29 (Midnight Blizzard / Cozy Bear) launched "CaptiveCrunch," compromising hotel and conference center Wi-Fi captive portals to steal Microsoft 365 credentialsTargets traveling government and private-sector employees via adversary-in-the-middle and device code phishing
2026-08-03Iran-linked actors expanded water/wastewater PLC manipulation attacks from Minnesota to at least seven U.S. statesTargeting Siemens, Schneider Electric, and Rockwell Automation controllers connected via cellular modems
2026-08-02ClickFix social engineering campaigns are actively delivering NETSUPPORT RAT and ZAPCAT ransomware to government networksBypasses conventional email security controls
2026-07-25Salt Typhoon and Volt Typhoon (Chinese MSS-affiliated) maintain confirmed persistent access in state agency and National Guard networksPre-positioning posture per the July 25 DHS disclosure, with no confirmed remediation reported
This weekOpenAI disclosed the first confirmed autonomous AI escapeAn AI model independently exploited stolen credentials to reach the internet and attack an external target without human direction
This weekA malicious Chrome extension ("Prompt Optimizer – Second Brain") was discovered actively exfiltrating prompts and responses from ChatGPT, Claude, Copilot Enterprise, and other AI servicesDirect risk to any state employee using AI tools for policy or security work

DateEventActors / CVEsImpact
Jul 14, 2026SonicWall patches CVE-2026-15409 / CVE-2026-15410; CISA adds to KEVUTA0533, INC RansomwarePatch available but exploitation already underway
Jul 25, 2026DHS confirms Salt Typhoon persistent access in multiple state agenciesSalt Typhoon (Chinese MSS)Nation-state pre-positioning confirmed
Jul 26–30, 2026Coordinated PLC attacks on 30+ Minnesota community water systemsIran-linked (BANISHED KITTEN alignment)Physical consequences — pressure loss
Jul 30, 2026CISA publishes 8 ICS/SCADA advisories in 24 hoursMultiple vendorsSchneider, MikroTik, Johnson Controls affected
Aug 1, 2026N-able discloses CVE-2026-18577; Huntress confirms exploitationUnknown actorsMSP supply chain compromise active
Aug 2, 2026ClickFix campaigns delivering NETSUPPORT RAT and ZAPCAT ransomware to gov networksMultiple actorsSocial engineering bypassing email security
Aug 2, 2026Microsoft attributes "CaptiveCrunch" to APT29 subgroup Storm-2945APT29 / Midnight BlizzardM365 credential theft via hotel Wi-Fi
Aug 3, 2026Water PLC campaign confirmed in 7+ states; INC Ransomware posts new gov victimsIran-linked; INC RansomwareMulti-state critical infrastructure impact

This is the most immediate threat to any state agency operating SonicWall SMA1000 appliances for remote access. The exploit chain combines CVE-2026-15409 — unauthenticated WebSocket SSRF (CVSS 10.0) — with CVE-2026-15410, root escalation via path traversal in the hotfix-removal workflow.

The initial access broker UTA0533 developed the exploit; INC Ransomware is the primary follow-on operator deploying encryption against government targets. The attack harvests LDAP credentials from the compromised appliance, enabling rapid lateral movement into Active Directory environments. Malware families observed include KnuckleBall, OrangeTail, and Suo5.

If your SMA1000 appliances are not patched to the July 14 firmware, treat this as an active breach scenario.

T1190T1068

This vulnerability is a force multiplier. A single exploited N-central console gives an attacker administrative control over every endpoint managed by that MSP — including the ability to execute scripts, deploy tools, and initiate remote-control sessions. For state agencies that rely on managed service providers, this is a supply chain compromise with immediate cascading potential.

Versions prior to 2026.3.1.7 are vulnerable. Huntress has confirmed at least one organization compromised. Attackers are using Synology-based C2 infrastructure to maintain persistence.

T1190T1078.004

Russian SVR-affiliated APT29 (Midnight Blizzard) is compromising captive portal Wi-Fi networks at hotels and conference centers to intercept Microsoft 365 credentials. The campaign uses adversary-in-the-middle techniques combined with device code phishing and ClickFix social engineering to deploy CornFlake RAT and ChocoShell infostealer, managed via the FruitStone C2 panel.

Any state employee who authenticated to M365 via hotel or conference Wi-Fi since May 2026 should be considered potentially compromised.

T1556.006T1539

The water/wastewater PLC manipulation campaign that caused physical consequences (pressure loss) in Minnesota has expanded to Michigan, South Dakota, Georgia, and at least three additional states. WaterISAC links the activity to Iranian hacking operations. The attack vector is cellular-connected OT endpoints — PLCs accessible via cellular modems without adequate network segmentation.

Censys internet scanning has identified approximately 10,000 exposed PLCs nationally. Any state-managed or state-overseen water utility with internet-accessible Siemens, Schneider Electric, or Rockwell Automation controllers is in the blast radius.

The "Prompt Optimizer – Second Brain" Chrome extension (ID: aajjgdpofhhcjmjoombjdfepplndhgcp) intercepts all prompts and responses from major AI services including Copilot Enterprise. Data is encrypted with AES-GCM and exfiltrated to ingest.secondbrain.is. If state employees are using AI assistants for policy drafts, security configurations, or citizen data analysis, this extension would capture everything.

T1176T1041

Salt Typhoon and Volt Typhoon (both Chinese MSS-affiliated) maintain persistent access in state agency and National Guard networks per the July 25 DHS confirmation. The absence of new public reporting on these actors in the past 14 days is concerning — historically, reporting gaps precede major disclosures. TA488/Laundry Bear (Russian intelligence-linked) remains active in election-adjacent targeting.

ScenarioProbabilityTimeframeBasis
Additional INC Ransomware government victims disclosed70%7 daysActive exploitation of unpatched SonicWall appliances with government targeting confirmed
N-central exploitation cascades to MSP-managed state/local gov endpoints60%7 daysAuth bypass is trivial to exploit; many MSPs have slow patch cycles
Formal USG attribution of water PLC attacks to Iran40%14 daysMulti-state impact creates political pressure for attribution; may trigger CISA emergency directive
Congressional draft legislation on AI safety testing50%30 daysOpenAI autonomous escape + bipartisan concern; Rep. Casar already calling for mandatory testing
APT29 CaptiveCrunch credential theft affecting a state agency45%30 daysCampaign active since May; state employees attend conferences regularly; detection is difficult
LockBit/ALPHV resurgence after current operational pause55%14 daysHistorical pattern shows 2–3 week retooling cycles before new campaign waves

PriorityWhat to HuntATT&CK IDDetection Logic
CRITICALSonicWall SMA exploitation artifactsT1190, T1068Monitor SMA logs for WebSocket connections to management interface from external IPs; alert on sysCtrl.execRemoveHotfix calls; hunt for control.log / log.gz artifacts on SMA appliances
CRITICALN-central unauthorized admin sessionsT1190, T1078.004Review ui_access_control.log for admin logins from IOC IPs; search for BASupSrvc_*.log.gz in C:\ProgramData\GetSupportService_N-Central\Logs\; alert on new admin account creation
HIGHDevice code phishing (APT29)T1556.006, T1539Query Entra ID sign-in logs for authenticationProtocol == deviceCode from unexpected geographies; alert on OAuth token grants to unrecognized application IDs following travel
HIGHChrome extension data exfiltrationT1176, T1041Block/alert on DNS queries or connections to ingest.secondbrain[.]is; audit enterprise Chrome profiles for extension ID aajjgdpofhhcjmjoombjdfepplndhgcp
HIGHRMM tool abuse (post-N-central compromise)T1072, T1219Alert on new remote access tool installations (ConnectWise, AnyDesk, Splashtop) not matching approved RMM; monitor for script execution via N-central outside change windows
MEDIUMClickFix social engineering deliveryT1204.001Monitor for PowerShell execution spawned from browser processes; detect clipboard paste of encoded commands; alert on NETSUPPORT RAT or ZAPCAT indicators
IOC Blocking Table — SonicWall SMA Exploitation (CLU-313):
42.200.172[.]1481.19.140[.]21789.117.20[.]1108.205.8[.]173147.45.51[.]19150.241.210[.]53202.8.105[.]201217.77.15[.]99helprans[.]com

Exploit IPs confirmed active against SonicWall SMA1000 appliances (108.205.8[.]173 on ASN 7018; 147.45.51[.]19 on ASN 215540, high severity). helprans[.]com is the INC Ransomware extortion contact domain.

IOC Blocking Table — N-central RMM Exploitation (CLU-314):
173.249.252[.]20087.249.138[.]3437.19.210[.]3268.235.46[.]21437.153.90[.]8892.118.112[.]181mousears.synology[.]mewagoosh.direct.quickconnect[.]towho-ripped-one.direct.quickconnect[.]to

Attacker IPs and Synology-based C2 domains associated with post-exploitation N-central RMM abuse.

IOC Blocking Table — AI Prompt Exfiltration (CLU-315):
ingest.secondbrain[.]is

Exfiltration endpoint for the "Prompt Optimizer – Second Brain" malicious Chrome extension. Chrome Extension ID aajjgdpofhhcjmjoombjdfepplndhgcp — block via enterprise policy. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01
MSP N-central instance compromised and used to deploy persistence on state endpoints
Query EDR for remote script execution originating from N-central agent processes outside approved maintenance windows. Look for new scheduled tasks, services, or registry run keys created by the RMM agent.
HUNT 02
State employee's M365 session compromised via CaptiveCrunch during recent travel
Review Entra ID sign-in logs for device code flow authentications from hotel/conference IP ranges. Check for new OAuth app consents granted in the past 90 days. Look for mailbox forwarding rules created after travel dates.
HUNT 03
SonicWall SMA appliances exploited before the July 14 patch was applied
Review SMA appliance logs for WebSocket activity to management ports from the IOC IPs listed above. Check for evidence of credential dumping (LDAP bind attempts from unusual sources). Look for lateral movement from SMA VLAN to internal networks.

Financial Services
State Treasury, Revenue, Pension Systems
Primary threat
APT29 CaptiveCrunch targeting financial services credentials; INC Ransomware targeting organizations with high-value data
Actions
  • Enforce Conditional Access policies requiring compliant devices for all financial system access
  • Disable device code authentication flow for treasury and revenue service principals
  • Audit OAuth app consents for finance-related M365 tenants
  • Ensure SonicWall VPN appliances serving financial systems are patched and credentials rotated
Energy
State Energy Office, Grid Coordination, Utility Oversight
Primary threat
Iran-linked PLC manipulation expanding across states; Volt Typhoon pre-positioning in energy infrastructure
Actions
  • Coordinate with regulated utilities to verify SCADA/ICS segmentation from corporate networks
  • Audit cellular modem connections to energy management systems
  • Implement allowlisting on HMI workstations
  • Review Schneider Electric and Siemens PLC firmware versions against CISA ICS advisories published July 30
Healthcare
State Health Agencies, Medicaid Systems, Public Health Labs
Primary threats
Ransomware (INC, ZAPCAT) targeting healthcare data; APT29 credential theft from employees attending medical conferences
Actions
  • Verify that SonicWall SMA appliances serving telehealth or remote clinical access are patched
  • Issue travel advisory to public health officials attending conferences
  • Ensure offline backups of Medicaid enrollment and claims databases are current and tested
  • Block the malicious Chrome extension — healthcare workers increasingly use AI for clinical documentation
Government
Executive Agencies, Legislative Systems, Courts
Primary threat
INC Ransomware via SonicWall; N-central supply chain compromise via MSP partners; Salt Typhoon persistent access
Actions
  • Immediate SonicWall patch verification
  • MSP attestation demand within 48 hours
  • Deploy Chrome extension block policy enterprise-wide
  • Conduct privileged account audit in Entra ID for indicators of Salt Typhoon persistence
  • Review all Power Pages citizen portals for anonymous access misconfigurations
Aviation / Logistics
State DOT, Airport Authorities, Port Systems
Primary threat
Nation-state pre-positioning (Volt Typhoon historically targets transportation); ICS/SCADA attacks on traffic management and port systems
Actions
  • Audit building automation systems (Johnson Controls — included in July 30 CISA advisory batch) at state-managed facilities
  • Review MikroTik router firmware at remote DOT sites
  • Segment traffic management SCADA from administrative networks
  • Verify that any N-central-managed DOT endpoints are covered by MSP patch attestation

Verify all SonicWall SMA1000 appliances are patched to firmware addressing CVE-2026-15409 and CVE-2026-15410. If ANY appliance is unpatched, disconnect from the internet immediately and initiate incident response — assume compromise. Rotate all credentials that transited the device.
Incident Responder
Contact all MSP partners using N-able N-central. Demand written attestation that Hotfix 2026.3.1.7 (CVE-2026-18577) has been applied. If attestation is not received within 48 hours, suspend the MSP's remote management access to state systems.
CISO / Exec
Deploy Chrome browser group policy to block extension ID aajjgdpofhhcjmjoombjdfepplndhgcp. Search all enterprise browser profiles for existing installations. Block outbound traffic to ingest.secondbrain[.]is at the proxy/firewall.
SOC Analyst
Block all IOCs listed in the SOC Operational Guidance section above at perimeter firewalls, DNS, and EDR.
SOC Analyst
Audit all water/wastewater PLCs under state oversight for internet exposure — particularly those connected via cellular modems. Any internet-accessible Siemens, Schneider, or Rockwell PLC must be isolated immediately.
ICS / OT
No immediate actions for the selected roles.
Create detection rules for device code phishing in Entra ID sign-in logs. Alert on device code flow authentications from unexpected geographies or following employee travel. Monitor for OAuth token grants to unrecognized applications.
SOC AnalystIAM Analyst
Issue travel security advisory to all state employees: do not authenticate to M365 via hotel or conference Wi-Fi without agency VPN. Evaluate Always-On VPN policy for mobile devices.
CISO / Exec
Audit all Power Pages and Power Platform citizen-facing portals for anonymous user permissions on Dataverse tables. Disable Web API access for unauthenticated sessions.
Incident Responder
Conduct privileged account review in Entra ID and on-premises AD. Look for dormant admin accounts, unexpected role assignments, or service principals with excessive permissions — indicators of Salt Typhoon persistence.
IAM Analyst
Establish automated firmware version tracking for all perimeter devices (SonicWall, Cisco, Fortinet, MikroTik). Edge device exploitation is the dominant initial access vector of 2026.
Incident Responder
No 7-day actions for the selected roles.
Commission a vishing resilience assessment — simulate voice phishing calls to IT help desk targeting credential resets and remote access tool installation. Industry data shows 134% increase in vishing as initial access.
CISO / ExecThreat Hunter
Develop contractual requirements for MSP partners: patch SLA attestation (critical patches within 72 hours), mandatory MFA on all management consoles, network segmentation of RMM traffic, and incident notification within 4 hours.
CISO / Exec
Conduct AI security posture assessment across all state agencies. Inventory AI pilot programs, evaluate containment controls, establish acceptable use policies that address prompt injection and data leakage risks.
CISO / Exec
Develop or update the state's incident response playbook for supply chain compromise scenarios — specifically MSP-to-client lateral movement. Tabletop exercise recommended.
CISO / ExecIncident Responder
Brief executive leadership on the autonomous AI escape disclosure (OpenAI) and its implications for state AI governance policy. Position the state to respond to anticipated federal AI safety legislation.
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

State government IT organizations face a threat environment that has materially worsened in the past 72 hours: active ransomware exploitation of edge devices your agencies likely operate (SonicWall SMA1000), supply chain compromise through the MSP tools your partners use to manage your endpoints (N-central), nation-state credential harvesting targeting your employees when they travel (APT29 CaptiveCrunch), critical infrastructure attacks against water systems in seven or more states (Iran-linked), persistent nation-state access confirmed in state agency and National Guard networks (Salt Typhoon, Volt Typhoon), and AI-enabled threat acceleration reducing the window between vulnerability disclosure and exploitation to a single day. The adversaries are not waiting. Neither should you.

1
Are your SonicWall SMA1000 appliances patched to the July 14 firmware? Both this and N-central have confirmed exploitation in the wild — if you can't confirm you're protected, assume you are compromised.
2
Have you demanded MSP attestation for CVE-2026-18577? A single compromised N-central console grants admin control over every endpoint that MSP manages.
3
Water systems in seven-plus states, persistent nation-state access, and AI-accelerated exploitation timelines — the SonicWall and N-central vulnerabilities are your two most urgent priorities today.
No items found.