| Date | Event | Significance |
|---|---|---|
| 2026-07-22 | CISA adds CVE-2026-16232 (Check Point SmartConsole auth bypass, CVSS 9.1) to KEV catalog | Any internet-exposed management server is at immediate risk of full admin takeover |
| 2026-07-22 | CISA adds CVE-2026-41940 (cPanel/WHM auth bypass, CVSS 9.8) to KEV catalog | Mass exploitation confirmed; GitHub Actions botnet scanning at scale |
| 2026-07-22 | CISA adds CVE-2021-27137 (DD-WRT UPnP buffer overflow) to KEV catalog | Legacy router firmware under active exploitation |
| 2026-07-23 | Cofense confirms dual phishing campaigns delivering ConnectWise ScreenConnect and Action1 RMM agents | HR/payroll and Adobe/invoice lures bypassing controls via "legitimate" tool signatures |
| 2026-07-23 | Socket Research publishes GitHub Actions botnet analysis (~6,100 compromised workflows) | CI/CD runners weaponized as distributed scanning/exploitation fleet |
| 2026-07-23 | Sekoia/Gen Threat Labs publishes "Remus" analysis — 64-bit Lumma Stealer rebuild | Stealer ecosystem survives takedown; blockchain C2 evades traditional domain blocking |
| 2026-07-21 | CISA publishes 7 ICS advisories (Rockwell Automation, Siemens, Tycon Systems) | Rockwell Studio 5000 arbitrary file execution affects water/transportation SCADA |
Continuity from prior cycle: VOID MANTICORE (IRGC-affiliated) destructive ICS breach of California water utility remains the highest-severity confirmed incident. UTA0533 exploitation of SonicWall SMA 1000 zero-day chain (CVE-2026-15409/15410) continues. Seven ransomware groups — including Qilin, LockBit 5, and Cactus — remain actively retooled with government-sector targeting. Volt Typhoon and Salt Typhoon pre-positioning in critical infrastructure persists without new observable activity (absence noted — not assumed safe).
| Date | Actor / Campaign | Target | Impact |
|---|---|---|---|
| Jun 2026 | VOID MANTICORE (IRGC) | California water utility | Destructive ICS breach — operational technology compromised |
| 22 Jun 2026 | UTA0533 | SonicWall SMA 1000 users | Zero-day chain (CVE-2026-15409/15410) for LDAP credential harvesting |
| 21 Jul 2026 | Multiple (KEV additions) | Langflow, Rockwell, others | CVE-2026-0770 unauthenticated RCE; 4 ICS advisories same day |
| 21 Jul 2026 | CISA ICS batch | Rockwell, Siemens, Tycon | 7 advisories — Studio 5000 arbitrary execution highest priority |
| 22 Jul 2026 | UNATTRIBUTED | Check Point SmartConsole users | CVE-2026-16232 active exploitation — full admin takeover |
| 22 Jul 2026 | UNATTRIBUTED (botnet) | cPanel/WHM hosting servers | CVE-2026-41940 mass exploitation via GitHub Actions fleet |
| 23 Jul 2026 | UNATTRIBUTED (phishing) | Enterprise HR/finance staff | Dual RMM-as-RAT campaigns (ConnectWise, Action1) |
| 23 Jul 2026 | Lumma ecosystem | Browser/cloud credential holders | "Remus" 64-bit stealer with blockchain C2 active in wild |
This vulnerability allows unauthenticated remote attackers to obtain full administrative access to Check Point management servers. Check Point has confirmed exploitation affecting "a very small number of customers" — language that historically precedes broader campaign discovery.
Why state government cares: Many state agencies deploy Check Point as their primary perimeter security platform. Administrative access to the management server means an attacker can modify firewall rules, disable logging, create VPN accounts, and establish persistent access — all while appearing as a legitimate administrator. The pattern matches Qilin/LockBit 5 playbook of disabling security tools prior to ransomware deployment.
Socket researchers documented approximately 6,100 compromised GitHub workflow files converting CI/CD runners into a distributed scanning and exploitation fleet. The botnet targets CVE-2026-41940 (cPanel/WHM authentication bypass) to harvest cloud credentials — AWS keys, GitHub tokens, SSH keys, and database credentials.
Why state government cares: This is a dual threat. Any state GitHub repositories using Actions could be involuntarily conscripted into the botnet. State-hosted cPanel/WHM instances are direct exploitation targets. The attacker gets free compute, clean IP addresses, and automatic scaling — rendering traditional IP-based blocking ineffective.
Two simultaneous phishing campaigns are delivering ConnectWise ScreenConnect and Action1 RMM agents as initial access tools. The ConnectWise campaign uses HR/payroll-themed PDFs linking to VBS scripts. The Action1 campaign uses Adobe/invoice-themed emails. Both exploit a fundamental detection gap: these are legitimate, signed tools that many organizations — and their managed service providers — already use.
Why state government cares: State agencies rely heavily on MSP vendors who use these exact tools for legitimate remote support. Without a baseline of authorized RMM installations, SOC teams cannot distinguish a vendor performing maintenance from an attacker establishing persistence. This is "living off the land" — except the land belongs to your vendors.
Despite the May 2025 takedown of Lumma Stealer infrastructure and doxxing of its developer, the codebase has been rebuilt as "Remus" — a 64-bit variant using EtherHiding (blockchain-based C2 resolution) that renders traditional domain takedowns ineffective. It includes a previously undocumented bypass of Application-Bound Encryption in Chromium browsers.
Why state government cares: Remus targets browser credentials, cloud tokens, and session cookies. State employees accessing Azure, M365 admin portals, financial systems, and citizen-facing portals are high-value targets. Combined with the emerging "Dolphin X" stealer that uses AI-powered victim triage to prioritize endpoints running cloud CLIs and database clients, the stealer-to-ransomware pipeline is becoming more efficient at identifying state government's most sensitive workstations.
CISA published seven ICS advisories on July 21, with the highest-priority finding being arbitrary file execution and configuration alteration in Rockwell Automation Studio 5000 Logix Designer. Additional advisories cover Rockwell 1734 POINT I/O denial-of-service, Siemens RUGGEDCOM APE1808 PAN-OS vulnerabilities, and Tycon Systems TPDIN-Monitor-WEB2 credential exposure.
Why state government cares: State water utilities and transportation departments commonly deploy Rockwell PLCs. The Studio 5000 vulnerability allows a local attacker to execute arbitrary files and alter controller configurations — the exact capability needed for a destructive attack like VOID MANTICORE's June 2026 water utility breach. Rockwell patches require OT maintenance windows, creating an exposure gap.
| Scenario | Probability | Basis |
|---|---|---|
| Ransomware group exploits CVE-2026-16232 to disable perimeter security before deploying payload | HIGH (70–80%) | Pattern matches Qilin/LockBit 5 playbook of disabling security tools pre-encryption; active exploitation already confirmed |
| State agency compromised via RMM phishing campaign (ConnectWise/Action1) | HIGH (65–75%) | HR/payroll lures specifically crafted for government workforce; legitimate tool signatures bypass most EDR |
| Remus/stealer infection leads to cloud management console compromise | MODERATE-HIGH (50–60%) | State employees accessing Azure/M365 admin portals are high-value targets; AI triage accelerates exploitation |
| GitHub Actions botnet conscripts state repository for exploitation operations | MODERATE (40–50%) | Depends on state GitHub usage and Actions configuration; 6,100 compromised workflows suggests broad targeting |
| ICS incident at state water/transportation facility exploiting Rockwell vulnerabilities | MODERATE (30–40%) | VOID MANTICORE demonstrated capability in June; Rockwell patches require OT maintenance windows creating exposure gap |
| Volt Typhoon/Salt Typhoon pre-positioned access activated for destructive effect | LOW-MODERATE (15–25%) | Absence of activity may indicate operational patience; geopolitical trigger would change this assessment rapidly |
Alert on admin logins from non-approved IPs; monitor for policy changes outside change windows. Review SmartConsole audit logs for admin sessions from unrecognized source IPs. Check for firewall policy modifications, new VPN user creation, or logging configuration changes in the past 7 days. Any admin activity from IPs outside the Trusted Clients list warrants immediate investigation — restrict per vendor advisory sk185169.
Alert on ScreenConnect.ClientSetup.msi or action1_agent*.msi installations not matching authorized vendor hashes. Any installation after 2026-07-20 from non-standard deployment paths warrants immediate investigation. Correlate with MD5 hashes: fb0632c5ef572f03f3fb7f498c78cf0b (malicious PDF), da2ad826591656b22b10cff944d47f56 (UpdatedPayrollDocument.vbs), be004763f7b248e1cd781f2ddc776f48 (ScreenConnect MSI), 1caca71d6ece3cb362f0d7291027276a (Action1 agent MSI).
Monitor cscript.exe or wscript.exe spawning from %TEMP%, Downloads, or email attachment paths. Alert on VBS execution from user temp/download directories — the ConnectWise campaign uses HR/payroll-themed PDFs that deliver VBS scripts as the first execution stage.
Alert on .github/workflows/ file additions or modifications in state repositories. Audit all workflow files for references to external IPs, /api/dl/ paths, or base64-encoded payloads. Any workflow referencing 43[.]228[.]157[.]68 or heartbeat/results API endpoints requires immediate investigation. Pin all Actions to commit SHAs — not version tags.
Query for non-browser processes accessing Chrome/Edge credential stores (Login Data, Cookies databases). Monitor for outbound connections to blockchain RPC endpoints (Infura, Alchemy, public Ethereum nodes) from non-developer endpoints. Look for steamcommunity[.]com profile page access from enterprise endpoints — used as a dead-drop resolver by Remus.
| Priority | Threat | ATT&CK |
|---|---|---|
| CRITICAL | Check Point SmartConsole auth anomalies | T1190 T1078 T1562.001 |
| CRITICAL | RMM tool installations outside approved baselines | T1219 |
| HIGH | VBS execution from user temp/download directories | T1059.005 |
| HIGH | GitHub Actions workflow modifications | T1195.002 |
| HIGH | Outbound connections to blockchain RPC endpoints | T1102.002 |
| MEDIUM | cPanel/WHM admin access from unexpected sources | T1190 |
| MEDIUM | Credential file access patterns on CI/CD infrastructure | T1552.001 |
IPs: 85[.]137[.]249[.]224, 45[.]90[.]97[.]211 — threat infrastructure; block at all perimeters and DNS. Domain steamcommunity[.]com/profiles/76561199861614181 — Remus/Lumma dead-drop resolver; block this specific profile URL. pub-7d9ebca991b14a299e221e5c296216da[.]r2[.]dev — ConnectWise phishing staging. SHA-256: dbf6facd28406361a6a81417b3ff5eb272ccc8dcc58a36bd5335a253ae4bf036 (Remus stealer sample). Additional IOCs available via Anomali ThreatStream and partner feeds.
ScreenConnect.ClientSetup.msi, action1_agent*.msi, or service registrations for ConnectWise/Action1 not matching approved vendor deployments. Any installation after 2026-07-20 from non-standard paths warrants immediate investigation..github/workflows/ files for references to external IPs, /api/dl/ paths, or base64-encoded payloads. Check for workflows not pinned to commit SHAs. Flag any workflow referencing 43[.]228[.]157[.]68 or heartbeat/results API endpoints.Login Data, Cookies databases) outside of browser processes. Look for steamcommunity[.]com profile page access from non-gaming endpoints — a Remus dead-drop indicator. Non-browser process reading browser credential files is a high-confidence IOC.- Enforce hardware security keys (FIDO2) for all financial system administrators
- Deploy browser isolation for access to banking and payment platforms
- Audit for unauthorized ConnectWise/Action1 installations on finance team endpoints
- Monitor: T1555.003 (browser credential theft), T1219 (unauthorized RMM), T1566.001 (spearphishing with financial lures)
- Verify network segmentation between IT and OT environments
- Patch Rockwell Studio 5000 per ICSA-26-202-10 during next maintenance window
- Audit Siemens RUGGEDCOM devices for PAN-OS vulnerability exposure
- Monitor: anomalous engineering workstation connections to PLCs, unexpected SCADA configuration changes
- Enforce conditional access policies requiring compliant devices for EHR/Medicaid system access
- Block VBS execution on clinical workstations
- Ensure offline backups of Medicaid enrollment databases are current and tested
- Monitor: T1059.005 (VBS execution), T1486 (data encrypted for impact), unusual bulk access to patient record databases
- Conduct proactive hunt for T1078 (Valid Accounts) anomalies in network infrastructure
- Verify Check Point SmartConsole Trusted Clients configuration immediately
- Implement RMM tool allowlisting — only approved vendor tools should be permitted to install/execute
- Monitor: T1078 (valid account abuse), T1219 (remote access software), admin console access from unexpected sources
- Audit GitHub Actions configurations for any transit/logistics application repositories
- Patch Rockwell 1734 POINT I/O and 1718/1719-AENTR devices
- Review vendor remote access agreements — ensure all MSP connections are logged and time-bounded
- Monitor: T1195.002 (supply chain compromise), T0831 (ICS manipulation), unauthorized workflow modifications
5starcredit[.]com, pentagonfundinggroup[.]com, pub-7d9ebca991b14a299e221e5c296216da[.]r2[.]dev; IPs 85[.]137[.]249[.]224, 45[.]90[.]97[.]211. HR/payroll-themed lures are delivering RMM tools as RATs.ScreenConnect.ClientSetup.msi or action1_agent*.msi installation not initiated through approved change management. Correlate with MD5 hashes: be004763f7b248e1cd781f2ddc776f48 (ScreenConnect), 1caca71d6ece3cb362f0d7291027276a (Action1)..github/workflows/ additions. Pin all GitHub Actions to commit SHAs (not version tags). Review for workflows referencing external IPs or suspicious API paths (flag 43[.]228[.]157[.]68 or heartbeat/results endpoints).The threat landscape facing state government this week is defined by trust exploitation — attackers weaponizing the tools, platforms, and infrastructure that organizations depend on for daily operations. Check Point management consoles, GitHub Actions runners, ConnectWise remote support, and even the blockchain itself are being turned from defensive assets into offensive weapons. Every threat documented here has a concrete, implementable defensive response. But the window for proactive defense is measured in days, not weeks: CVE-2026-16232 and CVE-2026-41940 are under active mass exploitation today. The RMM phishing campaigns landed in inboxes this morning.