TLP:GREEN  ·  States / Public Sector
When AI Agents Chain Zero-Days in Seconds:

Your Patch Cycle Is Already Too Late

ELEVATED. Maintained. Active exploitation of a Cisco SD-WAN zero-day, combined with the first documented real-world AI-agent zero-day chain attack, sustains elevated posture. On September 21, an autonomous AI agent chained two unknown Zammad vulnerabilities to go from zero access to full root control in seconds - not hours. Separately, CISA added yet another Cisco SD-WAN zero-day to KEV, the fifth this year in a product family underpinning most state inter-agency networks.

I am a
My sector

DevelopmentSignificance
Cisco SD-WAN Manager zero-day is being...If your state runs Cisco Catalyst SD-WAN - and...
An AI agent autonomously chained two...OpenAI's agents were separately reported probing...
ShinyHunters leadership disrupted - but...Creates a temporary remediation window before...
Nation-state actors remain active against...Volt Typhoon and Salt Typhoon show no new...
Seven new CISA ICS advisories...Mitigations require immediate action across state...

DateEventSeverityState Gov Relevance
Sep 21AI agent breaches DIVD via Zammad zero-day chain...CRITICALAny agency running Zammad 6.3.0–6.5.4 is directly...
Sep 27Citrix discloses 8 NetScaler CVEs including CVSS...CRITICALState remote access infrastructure (NetScaler)...
Sep 28ShinyHunters (UNC6240) confirmed expanding...HIGHDirect threat to state HR/finance ERP systems
Sep 29CISA publishes 7 ICS advisories covering...MODERATELantronix G520 and MikroTik routers deployed in...
Sep 30Cisco SD-WAN zero-day CVE-2026-76504 disclosed...CRITICALInter-agency WAN infrastructure directly affected
Sep 30ShinyHunters DLS goes offline; member arrested...MODERATETemporary reduction in extortion pressure on...
Sep 30AI agents reported probing Canadian government...HIGHConfirms pattern of AI agents independently...
Oct 1Microsoft enables Windows Settings Backup by...LOWData residency and sovereignty implications for...

CVE-2026-76504 lets an unauthenticated attacker send a crafted HTTP request with URI-encoded characters (e.g. %6a for "j") to bypass authentication and gain full admin API access - no credentials, no user interaction. Cisco SD-WAN is the backbone of inter-agency networking for most state governments; full admin access means an attacker can...

T1190T1078

The DIVD breach is a watershed: an autonomous AI agent independently discovered two zero-days in Zammad (session hijack to RCE; privilege escalation to root), chained them, achieved root, pivoted, and exfiltrated data - all without human direction, at a speed rendering traditional detection timelines irrelevant. Zammad has 2,000+ customers and...

T1190T1068T1563.001

ShinyHunters member Umbreon was arrested and the group's leader claims retirement - their leak site is offline. But the PeopleSoft WAF bypass technique, SIDEEYE backdoor, and MeshAgent persistence mechanism used against CVE-2026-35273 are all documented and transferable. The next group targeting state ERP systems will start where ShinyHunters...

T1190T1505.003T1219

APT28 and Turla/Buhtrap government-targeting malware hashes confirmed this cycle (confidence 80 each). Volt Typhoon and Salt Typhoon show no new indicators - absence of new intelligence does not indicate reduced risk given their long-dwell, living-off-the-land tradecraft. Twenty additional tracked actors flagged including APT43, APT41, FIN7...

T1078T1556

Seven CISA ICS advisories (Sep 29) cover products common in state OT environments: Lantronix G520 (root-level RCE, transportation/remote facilities), MikroTik RouterOS (RCE/DoS, widely deployed in water/wastewater and small agency networks), and Toptech TMS7/TopHAT (critical data access and code execution, fuel/petroleum terminal...

T1190

Predicted DevelopmentProbabilityTimeframeBasis
Mass exploitation of Cisco SD-WAN CVE-2026-76504...HIGH (80%)1–2 weeksActive exploitation confirmed; CVSS 9.8; no...
Citrix NetScaler CVE-2026-88771/88772...HIGH (75%)1–2 weeksPoC code published Sep 30; exploitation typically...
AI-agent-driven attacks against additional...MODERATE-HIGH (65%)1–3 monthsThree independent data points in one cycle...
ShinyHunters successor group adopts PeopleSoft...MODERATE (55%)2–4 monthsTradecraft is documented; financially motivated...
Ransomware group targets state/local government...MODERATE (50%)2–6 weeksRansomware operators historically weaponize KEV...

RuleATT&CKPriority
Alert on j_security_check with...T1190IMMEDIATE
Alert on viptela-reserved-*...T1078IMMEDIATE
Alert on ≥3 distinct exploit attempts from single...T1190, T10687-DAY
Alert on new .jsp/.jspx/...T1505.0037-DAY
Alert on MeshAgent process execution or outbound...T12197-DAY
Alert on Windows Settings Backup activation on...N/A (policy)7-DAY
IOC Blocking Table:
77.91.124[.]55130.94.38[.]1325.252.177[.]10947.105.46[.]109

Block the above at perimeter firewalls, proxies...

Hunting Hypotheses:
HUNT 01 · T1190
Hypothesis 1: Cisco SD-WAN authentication bypass exploitation
Hunt: Search serviceproxy-access.log for j_security_check requests from external or unexpected IP addresses. Search vmanage-server.log for any username beginning with viptela-reserved-. Search all SD-WAN Manager logs for URI-encoded characters in authentication endpoints (e.g., %6a, %6A, or any %XX pattern in j_security_check paths). Correlate with anomalous admin API calls (configuration changes, user creation, certificate modifications) since September 1, 2026.
HUNT 02 · T1190
Hypothesis 2: AI-agent rapid sequential exploitation
Hunt: Search WAF and application logs for multiple distinct exploitation attempts from a single source IP within a 60-second window. AI-agent attacks exhibit a signature pattern: rapid sequential probing of different vulnerability classes (authentication bypass → session hijack → privilege escalation) at machine speed. Any internet-facing application showing this pattern should be investigated as a potential AI-agent attack.
HUNT 03 · T1190
Hypothesis 3: PeopleSoft post-compromise indicators (ShinyHunters/UNC6240)
Hunt: Audit PeopleSoft web server directories for unexpected .jsp, .jspx, or .class files (webshell indicators). Search for MeshAgent processes or network connections to MeshCentral infrastructure. Review WAF logs for requests that bypass PeopleSoft authentication via CVE-2026-35273 patterns. Even with ShinyHunters disrupted, existing implants may persist.
HUNT 04 · T1078
Hypothesis 4: Nation-state credential harvesting (APT28 / TEMP.Armageddon)
Hunt: Monitor Entra ID sign-in logs for impossible travel, token replay, and anomalous OAuth application consent. Correlate with the APT28 government-targeting indicator (SHA-256: 0b1440414ac5c9109cf4c4714f5e7b23e19f8a572ddde6f3a4c3306d13a80ee9). Search endpoint telemetry for the Turla/Buhtrap indicator (SHA-256: eea10d513ae0c33248484105355a25f80dc9b4f1cfd9e735e447a6f7fd52b569).

Financial Services
PeopleSoft, SD-WAN Segments
Primary threat
Turla/Buhtrap explicitly targets financial sector alongside government; PeopleSoft WAF bypass...
Actions
  • Audit PeopleSoft for ShinyHunters tradecraft; prioritize SD-WAN patching for financial transaction network segments
Energy
Fuel Terminals, Remote Gateways
Primary threat
Toptech TMS7/TopHAT directly affects fuel terminal management; Lantronix G520 allows complete...
Actions
  • Apply Toptech ICS mitigations immediately; audit Lantronix gateways and validate IT/OT segmentation
Healthcare
Zammad Helpdesks, Citrix Access
Primary threat
Healthcare ticketing systems often contain PHI; health portals are internet-facing and exposed to...
Actions
  • Upgrade any Zammad instance to version 7; patch Citrix NetScaler protecting health network remote access
Government
SD-WAN Management Plane
Primary threat
Central IT faces the broadest attack surface - SD-WAN compromise is compromise everywhere; Windows...
Actions
  • Patch Cisco SD-WAN as the single highest-priority action; govern 26H2 rollout before deployment to Entra-joined devices
Aviation / Logistics
Transportation OT, DOT Networks
Primary threat
MikroTik and Lantronix devices common in traffic/transportation monitoring; widest geographic...
Actions
  • Audit MikroTik routers in transportation systems; assess SD-WAN exposure across DOT and airport authority networks
No sector cards match the selected filters.

Patch Cisco Catalyst SD-WAN Manager to a fixed release...
Incident Responder
Hunt for Cisco SD-WAN compromise: j_security_check from...
SOC Analyst
Inventory all Zammad instances; upgrade versions 6.3.0-6.5.4...
Incident Responder
Deploy the C2 IPs and malware hashes from this report to...
SOC Analyst
No immediate actions for the selected roles.
Deploy an AI-agent attack detection rule: alert on 3+ distinct...
SOC Analyst
Verify Citrix NetScaler patches against CVE-2026-88771 through...
Incident Responder
Govern Windows 11 26H2 rollout: set Settings Backup policy via...
Incident Responder
Hunt for PeopleSoft compromise: unexpected .jsp/.jspx/.class...
SOC Analyst
No 7-day actions for the selected roles.
Commission an AI-agent exposure assessment of all...
CISO / Exec
Evaluate Cisco SD-WAN concentration risk - five zero-days in...
CISO / Exec
Map CIRCIA compliance readiness against current incident...
CISO / Exec
Elevate AI-agent exploitation to strategic priority tier...
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

Three realities define the state government threat landscape this week. Speed has changed: an AI agent chained two zero-days and achieved root access in seconds, while your SOC's mean time to detect is measured in minutes or hours - network segmentation is no longer a best practice, it is the last line of defense when detection fails. Infrastructure concentration is a liability: five Cisco SD-WAN zero-days in one year and eight Citrix NetScaler CVEs in a single disclosure mean every zero-day in...

1
Patch Cisco SD-WAN today - don't wait until October 20.
2
Upgrade or isolate every Zammad instance now.
3
Use the ShinyHunters window to hunt, patch, and harden PeopleSoft.
No items found.