| Date | Development | Why It Matters for State Government |
|---|---|---|
| Sep 9 | CISA adds CVE-2026-20079 (Cisco FMC, CVSS 10.0), CVE-2026-19490 (Citrix, CVSS 9.3), CVE-2025-25249 (Fortinet, CVSS 8.1) to KEV | Three perimeter vendors, one KEV update, Sep 12 deadline |
| Sep 9 | Chrome V8 zero-day CVE-2026-87491 added to KEV | Drive-by code execution; every unpatched Chrome browser is a target |
| Sep 9–10 | Microsoft discloses Storm-3121/3032 passkey vishing campaign | ShinyHunters/Helix-linked actors hijacking M365 identities via personal-phone vishing |
| Sep 10 | Barracuda discloses blob URL phishing technique | No persistent URL — invisible to gateways, proxies, sandboxes |
| Sep 10 | CVE-2026-58138 (Orkes Conductor, CVSS 9.8) under mass exploitation | 1,290 attacks/24h; public exploit; critical for any agency/MSP running Conductor |
| Continuing | PivotC2 RAT actively deploying on U.S. FortiGate devices | 178 U.S. devices confirmed infected via CVE-2025-25249 |
| Date | Event | Actor / CVE | Impact |
|---|---|---|---|
| Jul 2026 | Earliest CVE-2025-25249 (FortiOS) exploitation begins | Russian-speaking financial actor | PivotC2 deployment begins; 3,000+ IPs targeted |
| May 2026 | Storm-3121/3032 passkey vishing campaign begins | Storm-3121 (ShinyHunters), Storm-3032 (Helix) | M365 identity theft, cloud exfiltration at scale |
| Aug 2026 | CVE-2026-20079 (Cisco FMC) exploitation confirmed | Fire Ant (China-nexus) | Root access on Cisco FMC; routers used as collection platforms |
| Sep 3 | CVE-2026-19490 (Citrix NetScaler) exploitation begins | Unattributed | 56 attempts observed; accelerating daily |
| Sep 8 | PoisonedRefresh rootkit disclosed on F5 BIG-IP | Unattributed | ~795 exposed endpoints; fileless, firmware-persistent |
| Sep 8 | NSA/CISA/FBI advisory on Chinese AI IP theft | DeepSeek, Alibaba, Moonshot AI | Strategic espionage concern |
| Sep 9 | Microsoft Patch Tuesday: 964 CVEs, 2 zero-days | Unattributed | CVE-2026-81963/85880 — SYSTEM-level privilege escalation |
| Sep 9 | CISA KEV: Cisco FMC, Citrix NetScaler, Fortinet, Chrome V8 | Multiple actors | Four critical CVEs, Sep 12 federal patch deadline |
| Sep 9–10 | Microsoft discloses Storm-3121/3032 vishing campaign | Storm-3121, Storm-3032 | 7 IOC domains; active M365 identity hijacking |
| Sep 10 | Blob URL phishing technique disclosed | Unattributed | Novel evasion defeats URL-based scanning |
| Sep 10 | CVE-2026-58138 (Orkes Conductor) mass exploitation | Unattributed | 1,290 attacks/day; CVSS 9.8 unauthenticated RCE |
Three perimeter vendors — Cisco, Citrix, Fortinet — landed on CISA KEV the same day.
| CVE | Product | CVSS |
|---|---|---|
| CVE-2026-20079 | Cisco FMC | 10.0 |
| CVE-2026-19490 | Citrix NetScaler | 9.3 |
| CVE-2025-25249 | Fortinet FortiOS | 8.1 |
CVE-2025-25249 is weaponized as PivotC2 RAT; 178 U.S. devices infected. Fire Ant (China-nexus) is exploiting Cisco IOS XR as collection platforms.
Storm-3121 (ShinyHunters) and Storm-3032 (Helix) run an M365 identity pipeline active since May: vishing to a personal phone → fake passkey portal → AiTM capture → new MFA registered → Graph API recon → controlled exfiltration, outside EDR/MDM visibility.
Barracuda disclosed blob URL phishing: pages render entirely in browser memory, invisible to gateways/proxies/sandboxes. DocuSign-themed lures are ubiquitous in state procurement.
CVE-2026-87491 is a Chrome V8 out-of-bounds write enabling drive-by code execution. Fixed in 153.0.8010.36+.
CVE-2026-58138 (CVSS 9.8) allows unauthenticated RCE on Orkes Conductor. 1,290 attacks blocked in 24h (+132%); public PoC available.
| Scenario | Probability | Basis |
|---|---|---|
| FortiGate compromise (CVE-2025-25249) → PivotC2 → lateral movement into agency networks | HIGH (>75%) | 178 devices already infected; state agencies are known Fortinet customers |
| M365 hijack via Storm-3121/3032 → exfiltration → extortion demand | HIGH (70–80%) | Active since May; targets personal devices outside MDM; ShinyHunters link |
| Drive-by compromise via CVE-2026-87491 (Chrome V8) | MODERATE-HIGH (50–65%) | Actively exploited zero-day; fleet update lag creates exposure |
| Blob URL phishing vs. state procurement/finance via DocuSign lures | MODERATE (40–55%) | DocuSign ubiquitous in gov procurement; defeats current defenses |
| Ransomware following identity compromise (ShinyHunters/Falcon) | MODERATE (40–50%) | Identity-to-extortion pipeline is a logical next step |
| China-nexus exploitation of Cisco IOS XR backbone routers | MODERATE (35–50%) | Fire Ant confirmed; Volt Typhoon pattern consistent |
| OT/ICS targeting of water SCADA via CyberAv3ngers | LOW-MODERATE (20–35%) | Remains active; absence ≠ reassurance |
| ATT&CK | Detection Logic | Data Source |
|---|---|---|
| T1566.004 | Help desk impersonation correlated with MFA registration <1hr | User reports, Entra ID |
| T1098.005 | New MFA method from non-corporate IP/geolocation | Entra ID audit logs |
| T1528 | Device-code OAuth flows from unexpected user agents | Entra ID sign-in logs |
| T1087.004 | Rapid Graph API calls to /users, /groups, /directoryRoles | Graph API audit logs |
| T1530 | Bulk SharePoint/OneDrive access (>100 files/hr) | Defender for Cloud Apps |
| ATT&CK | Detection Logic | Data Source |
|---|---|---|
| T1190 | Anomalous HTTP to mgmt interfaces from external IPs | FortiGate/web filter logs |
| T1059.007 | Node.js process execution on appliances | FortiGate CLI audit |
| T1573 | Outbound TLS from mgmt to non-Fortinet IPs | Network flow, egress logs |
| T1005 | Config export/credential access outside backup windows | FortiGate config audit |
| ATT&CK | Detection Logic | Data Source |
|---|---|---|
| T1566.002 | Calendar-invite emails with OAuth/Teams redirects | Email gateway |
| T1204.001 | blob: URL generation in Chrome auth contexts | Chrome telemetry |
| T1102 | Service-worker registrations tied to cdn.bloom[.]io | Proxy logs |
Block the above at perimeter firewalls, proxies, and DNS. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
- Require managed devices; pilot FIDO2
- Patch/rotate creds on IT/OT firewalls
- Block vishing domains
- Push Chrome fleet-wide
- Inventory perimeter devices; enforce MFA
The threat landscape facing state government networks is compounding risk across multiple layers at once: perimeter under pressure from three vendor vulnerabilities in the wild, identity under vishing that bypasses MFA, and a novel phishing technique blinding URL-based defenses. A compromised FortiGate yields lateral-movement credentials; a hijacked M365 identity yields extortion data. The kill chains converge, and the Sep 12 KEV deadline is 48 hours away.