TLP:GREEN  ·  States / Public Sector
When AI Agents Become Attack Vectors:

A Critical Week for State Government Cybersecurity

ELEVATED. Upgraded due to a full public proof-of-concept exploit for F5 BIG-IP APM, imminent CISA KEV compliance deadlines, and four independent AI agent exploitation campaigns documented in a single 24-hour window. Three critical vulnerabilities - one a perfect CVSS 10.0 - carry a federal remediation deadline of September 27. This is not a drill: patching, AI governance, and identity security decisions made in the next 48-72 hours will materially determine agency risk posture for the quarter.

I am a
My sector

DevelopmentSignificance
F5 BIG-IP APM exploit...CERT-SE issued an emergency...
CISA adds two actively...Adobe Commerce has been actively...
AI agent exploitation...AI-integrated enterprise tools...
Microsoft disrupts...A single Conditional Access policy...
Compliance processes...Works in both directions for state...
Roundcube webmail...SQL injection enabling credential...
A new EDR evasion...Not yet observed in the wild, but...

DateEventSeverityState Gov Impact
August 2026Active exploitation of Adobe...CRITICALAny agency e-commerce or payment...
11 Sep 2026Two arrests linked to EvilTokens...HIGHM365 tenants across all agencies
19 Aug 2026Salesforce patches SalesBleed...HIGHAgencies using Salesforce CRM with...
22 Sep 2026CISA adds F5 BIG-IP APM...CRITICALAll F5 BIG-IP deployments with...
23 Sep 2026CISA/FBI publish ICS third-party...MODERATEWater, transportation, building...
24 Sep 2026CISA adds CVE-2026-5430 (WSO2) and...CRITICALAPI gateways, SSO, constituent...
24 Sep 2026Flashpoint discloses process...MODERATEAll endpoints relying on EDR/XDR...
25 Sep 2026WatchTowr Labs publishes full F5...CRITICALExploitation now trivial; public...
25 Sep 2026Microsoft announces EvilTokens...HIGHAll state M365 tenants
25 Sep 2026SalesBleed disclosure — Salesforce...HIGHAgencies deploying Salesforce...
25 Sep 2026Four AI agent exploitation reports...HIGHAll agencies adopting AI-integrated...

CVE-2026-94127 is a heap overflow in the data plane - not the management interface - meaning internet-facing virtual servers are directly exposed. Exploitation requires only an oversized Authorization header to a virtual server with an OAuth profile; the pre-patch code performed no bounds check at all. F5, CISA, and CERT-SE have all confirmed...

T1190

WSO2 (CVE-2026-5430, CVSS 10.0): JWT signature algorithm confusion enables full unauthenticated account takeover - used by some agencies for API gateway authentication and SSO. CISA BOD 22-01 deadline: September 27.

Adobe Commerce/Magento (CVE-2026-71362, CVSS 9.1): incorrect authorization enabling...

T1190T1078T1134

SalesBleed (Salesforce Agentforce): poisoned Web-to-Lead forms trigger zero-click CRM data exfiltration when processed by AI agents - explicitly tagged as targeting government. EvilTokens: AI chatbot analyzed 12,000 compromised inboxes for fraud opportunities. Balonx CallFlow: fully automated...

T1190T1567T1534T1528

EvilTokens exploited OAuth 2.0 device authorization flow to grant attackers long-lived tokens that bypass MFA entirely, without needing real-time attacker infrastructure. Storm-2992 ran this as a commercial platform ($600-$1,500 tiers, 44 phishing themes) compromising 12,000 inboxes.

The fix is straightforward: block device code flow in...

T1528T1114.002T1078.004

Compliance weaponization: the Revolut breach proved attackers can spoof a government domain to trigger automated compliance data handover with zero malware - this works in both directions for agencies processing legal data requests (law enforcement, courts, revenue, CPS).

Process parameter poisoning: a...

T1566.002T1055T1574.002

Predicted DevelopmentProbabilityTimeframeBasis
Mass exploitation of F5 BIG-IP APM...HIGH (85%)1–2 weeksFull exploit details now public...
Ransomware operators incorporate...MODERATE-HIGH (70%)...2–4 weeksAuthentication bypass vulnerabiliti...
AI agent prompt injection attacks...MODERATE (60%)1–3 monthsSalesBleed demonstrated...
Device code phishing campaigns...HIGH (80%)2–6 weeksTechnique is well-documented...
Process parameter poisoning...MODERATE (55%)3–6 monthsTechnique validated but requires...
Ransomware attack against a U.S...HIGH (80%)1–4 weeksHistorical cadence, active LockBit...
Nation-state exploitation of...MODERATE-HIGH (65%)...1–4 weeksConfirmed active exploitation...

PriorityHuntData SourceATT&CK
1Oversized Authorization headers to...WAF logs, F5 access logsT1190
2Device code authentication from...Azure AD sign-in logsT1528
3Mailbox rules created within 1...M365 Unified Audit LogT1564.008
4Outbound image tag requests from...Salesforce event logs, CASBT1567
5Abnormally long process...EDR telemetry, Sysmon Event ID 1T1055
6DMARC failures on inbound...Email gateway logsT1566.002
7Roundcube webmail SQL injection...Web server logs, IDS/IPST1190
Hunting Hypotheses:
HUNT 01 · T1190
Oversized Authorization headers to F5 BIG-IP virtual servers
1 — Oversized Authorization headers to F5 BIG-IP virtual servers — WAF logs, F5 access logs — T1190
HUNT 02 · T1528
Device code authentication from unmanaged devices
2 — Device code authentication from unmanaged devices — Azure AD sign-in logs — T1528
HUNT 03 · T1564.008
Mailbox rules created within 1 hour of device code auth
3 — Mailbox rules created within 1 hour of device code auth — M365 Unified Audit Log — T1564.008
HUNT 04 · T1567
Outbound image tag requests from Salesforce Agentforce
4 — Outbound image tag requests from Salesforce Agentforce — Salesforce event logs, CASB — T1567
HUNT 05 · T1055
Abnormally long process command-line parameters
5 — Abnormally long process command-line parameters — EDR telemetry, Sysmon Event ID 1 — T1055
HUNT 06 · T1566.002
DMARC failures on inbound government domain emails
6 — DMARC failures on inbound government domain emails — Email gateway logs — T1566.002
HUNT 07 · T1190
Roundcube webmail SQL injection attempts
7 — Roundcube webmail SQL injection attempts — Web server logs, IDS/IPS — T1190

Financial Services
Treasury, Revenue, Tax Portals
Primary threat
Adobe Commerce vulnerability directly threatens payment portals; Revolut-style compliance spoofing...
Actions
  • Patch CVE-2026-71362 on all Magento payment portals before Sep 27; implement callback verification for financial data requests
Energy
Water, Power, Transportation OT
Primary threat
CISA/FBI's Sep 23 third-party ICS integrator guidance directly addresses state-operated OT...
Actions
  • Distribute the ICS integrator fact sheet; verify third-party remote access is segmented and monitored
Healthcare
Medicaid, Case Management
Primary threat
SalesBleed is directly relevant for Salesforce-based case management; AI vishing could target call...
Actions
  • Verify Agentforce patch status on Medicaid CRM instances; brief call center staff on AI vishing threats
Government
Central IT, Elections
Primary threats
Broadest attack surface - F5 threatens citizen-facing portal load balancers, WSO2 could compromise...
Actions
  • Confirm emergency patching for F5 and WSO2 across all agencies; block OAuth device code flow in Conditional Access
Aviation / Logistics
DOT, Ports, CI/CD Pipelines
Primary threat
Supply chain risk from CI/CD pipeline compromise threatens custom logistics applications; F5/WSO2...
Actions
  • Verify F5 patching on transportation load balancers; pin CI/CD dependency versions to specific commits
No sector cards match the selected filters.

Apply F5 BIG-IP APM hotfix for CVE-2026-94127 on all virtual...
Incident Responder
Patch WSO2 identity products for CVE-2026-5430; verify all API...
Incident Responder
Patch Adobe Commerce/Magento for CVE-2026-71362; verify all...
Incident Responder
Block OAuth device code flow in Azure AD Conditional Access...
SOC AnalystIAM Analyst
No immediate actions for the selected roles.
Audit Roundcube webmail deployments; upgrade to 1.6.16+/1.7.1+...
Incident Responder
Audit Salesforce Agentforce configurations: restrict Trusted...
SOC Analyst
Deploy detection for process parameter poisoning: monitor...
SOC Analyst
Conduct device code phishing awareness training for IT staff...
CISO / Exec
No 7-day actions for the selected roles.
Develop an AI agent security policy covering Agentforce...
CISO / Exec
Commission a red team assessment of compliance data request...
CISO / Exec
Update third-party ICS integrator requirements per CISA/FBI...
CISO / Exec
Establish AI agent threat monitoring keywords and collection...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The threat environment this week is defined by three converging pressures. A hard patching deadline in 48 hours: three critical vulnerabilities carry a September 27 federal remediation deadline, and the F5 flaw now has a full public proof-of-concept - mass exploitation is expected within days. AI agent exploitation is no longer theoretical: four independent production exploits in a single 24-hour window confirm AI-integrated enterprise tools are a new, largely undefended attack surface, with...

1
Patch the three KEV vulnerabilities before September 27.
2
Block device code authentication today.
3
Begin the governance conversation on AI agent security this week.
No items found.