| Development | Significance |
|---|---|
| Nine new CISA KEV entries were added on August 26–27, representing an elevated pace of confirmed in-the-wild exploitation. BOD 22-01 compliance timelines are now running on all nine. | 9 KEVs in 2 days — elevated exploitation tempo requiring immediate cross-reference against asset inventory |
| REVENANT SPIDER (Qilin ransomware) had its threat profile updated on August 31, explicitly confirming state government, local government, and law enforcement as named target sectors across 97 countries including the United States. Their primary initial access method: compromised VPN credentials. | VPN credential compromise is the confirmed #1 ransomware entry vector for state government |
| CVE-2026-82874 (ToolJet, CVSS 9.9) was disclosed — a cross-tenant authorization bypass in a low-code internal tool builder that allows authenticated users to read, modify, and permanently destroy data belonging to other organizations sharing the same platform. | Systemic multi-tenant isolation failure in low-code platforms agencies are rapidly adopting |
| CVE-2026-16102 (Keycloak/Red Hat SSO, CVSS 8.1) was disclosed — a privilege escalation flaw that allows any standard user with a limited access token to forge administrative roles, take over other clients, steal secrets, and gain full realm administrative control. | Any standard user account can escalate to realm administrator |
| Five new ICS advisories from CISA included a remote code execution vulnerability in All-Line Equipment Fuel-Boss fuel management systems — the kind of system that manages fuel dispensing for state government vehicle fleets — and vulnerabilities in Rockwell Automation OTTO Fleet Manager and multiple IoT devices. | Direct physical-world risk to state fleet fuel management and logistics operations |
| Multi-actor supply chain indicators surfaced, attributed to MuddyWater/MOIS (Iran), Silent Chollima (North Korea), and DustSquad (Central Asia) — all targeting government networks via supply chain compromise techniques. | Multiple nation-state actors converging on government supply chain vectors |
| Turkish hacktivist group Anka Team claimed 1,922 defacements on August 30, including confirmed U.S. .gov domains, demonstrating automated CMS scanning capability at scale against web-facing government assets. | Automated CMS scanning at scale demonstrates capability and intent against .gov domains |
| The FBI/DOJ seizure of the QScan/QTRouter IoT botnet (reported August 30) — operated on behalf of China's Ministry of State Security and People's Liberation Army, and used to target NASA, the Department of Energy, and the U.S. Senate — remains a significant contextual event from the prior cycle. | Confirms Chinese state targeting of U.S. government networks; compromised devices may persist after seizure |
| Date | Event | Relevance to State Government |
|---|---|---|
| Aug 26 | CISA adds 6 vulnerabilities to KEV catalog | BOD 22-01 compliance — patch or mitigate within mandated timelines |
| Aug 26 | CISA publishes strategic Vulnerability Review | Policy signal: "basic security failures enable most compromises" |
| Aug 27 | CISA adds 3 more vulnerabilities to KEV catalog | 9 KEVs in 2 days — elevated exploitation tempo |
| Aug 27 | 5 ICS advisories published (Rockwell, Fuel-Boss, IoT devices) | Fuel-Boss RCE directly threatens state fleet fuel management |
| Aug 28 | Multiple supply chain attack campaigns updated in threat feeds | Government-targeting supply chain IOCs with Iran/DPRK attribution |
| Aug 30 | FBI/DOJ seizes China MSS/PLA IoT botnet infrastructure | Confirms Chinese state targeting of U.S. government networks |
| Aug 30 | Turkish hacktivist group Anka Team claims 1,922 defacements including U.S. .gov domains | Web-facing state government assets at risk from automated CMS scanning |
| Aug 31 | REVENANT SPIDER (Qilin) profile updated — state/local gov confirmed as targets | VPN credential compromise is their primary entry vector |
| Aug 31 | CVE-2026-82874 (ToolJet CVSS 9.9) and CVE-2026-16102 (Keycloak CVSS 8.1) disclosed | SaaS and IAM platforms used by government agencies carry critical flaws |
The REVENANT SPIDER group — operators of the Qilin ransomware (also tracked as Agenda/Stinkbug) — updated their operational profile this week with explicit confirmation of what many state CISOs already suspected: state government, local government, law enforcement, and emergency services are named target industries.
Their playbook is well-documented: initial access via compromised VPN credentials (directly relevant to Palo Alto GlobalProtect, Cisco ASA/FTD, and Citrix NetScaler deployments common in state environments); post-compromise using legitimate system tools (living-off-the-land), making detection harder; double extortion — data exfiltration before encryption, with DDoS and legal pressure as additional coercion tactics; and Rust-based ransomware distributed through a ransomware-as-a-service affiliate model.
This is not theoretical. Qilin recently breached a federal law enforcement entity, and the Rhysida ransomware group has directly hit state government through VPN-to-exfiltration attack chains. Both groups are active, both target government, and both exploit the same entry point: VPN infrastructure.
CVE-2026-16102 in Keycloak (Red Hat SSO) is the kind of vulnerability that keeps identity architects up at night. The flaw is in the Dynamic Client Registration component: an attacker with nothing more than a standard user account and a limited Initial Access Token can manipulate claim paths to forge administrative roles in their access token. From there, they can take over other clients, steal secrets, and gain full realm administrative control.
For state agencies using Keycloak or Red Hat SSO for identity federation — common in open-source-leaning government IT environments — this is an immediate patching priority. Patches are available in RHSA-2026:50846 through RHSA-2026:50849.
CVE-2026-82874 carries a CVSS score of 9.9 — nearly the maximum possible — for good reason. In ToolJet (a low-code internal tool builder used by some government organizations for dashboards and workflow automation), any authenticated Builder user can manipulate the organizationId path parameter to read, modify, and permanently destroy data belonging to other tenants on the same platform.
Attackers can extract victim organization IDs from publicly accessible app endpoints, then exploit schema operation endpoints to disclose database schemas, plant malicious tables, corrupt data, or destroy it entirely.
This vulnerability is part of an emerging pattern. Combined with the triple-CVSS-10 vulnerabilities in ServiceNow disclosed earlier this month, state IT leaders face a systemic risk: the low-code/no-code platforms agencies are rapidly adopting for internal tooling carry catastrophic multi-tenant isolation failures.
Five new ICS advisories from CISA this week included one that should get immediate attention from state fleet and transportation operations: ICSA-26-239-02 (All-Line Equipment Fuel-Boss) — a remote code execution vulnerability in fuel dispensing management systems.
State governments operate large vehicle fleets for law enforcement, transportation, and public works, often with centralized fuel management. Remote code execution on these systems could enable fuel theft at scale, disruption of emergency vehicle fueling during crisis response, and manipulation of fuel inventory records.
Additional advisories covered Rockwell Automation OTTO Fleet Manager (weak cryptographic hashing enabling offline brute-force) and multiple IoT devices (Xiiaozet LK100W, Ebyte NA111-M) with full device takeover vulnerabilities — relevant given the China MSS IoT botnet infrastructure seized by the FBI on August 30.
Threat intelligence feeds this week surfaced file indicators carrying multi-actor attribution tags that tell a concerning story about the supply chain threat to government networks. Attributed actors include MuddyWater/MOIS (Iran), Silent Chollima (DPRK), Dalbit, and DustSquad (Central Asia), with associated malware families including Neshta, Hive ransomware, and Expiro.
The MuddyWater/MOIS-attributed indicator is particularly notable — it carries tags for three different nation-state actor groups plus both APT espionage and ransomware malware families, suggesting either shared tooling across actor ecosystems or a file infector (Neshta) that has propagated across multiple threat actor supply chains.
Continued context: Volt Typhoon and Salt Typhoon showed zero new activity signals this cycle — historical patterns suggest a 2–4 week infrastructure rebuild cycle following the QScan/QTRouter botnet exposure. IRGC-affiliated groups continue targeting U.S. water and wastewater systems (100+ facilities), while MuddyWater/UNC5667 actively targets Siemens S7 PLCs across seven or more states.
| Scenario | Probability | Basis |
|---|---|---|
| Additional CISA KEV additions at elevated pace (5+ per week) | HIGH (75–85%) | 9 KEVs in 2 days indicates sustained exploitation tempo; CISA's strategic review signals continued aggressive cataloging |
| Qilin/REVENANT SPIDER affiliate attack against a U.S. state or local government entity | MODERATE-HIGH (50–65%) | Refreshed targeting profile explicitly names state/local gov; VPN credential compromise is a low-barrier initial access method; RaaS affiliate model increases attack volume |
| Exploitation of Keycloak CVE-2026-16102 in the wild | MODERATE (45–60%) | Straightforward token forgery from standard user account; Red Hat advisories are public; 14-day exploitation window typical for IAM vulnerabilities |
| Volt Typhoon/Salt Typhoon operational resurgence on new infrastructure | LOW-MODERATE (30–45%) | Historical 2–4 week rebuild cycle following infrastructure exposure; MSS/PLA operational tempo unlikely to decrease despite seizure |
| Exploitation of ToolJet CVE-2026-82874 against government tenants | MODERATE (40–55%) | CVSS 9.9 with straightforward exploitation path; government adoption of low-code platforms creates target-rich environment |
| Anka Team or similar hacktivist group targeting additional .gov domains | MODERATE (45–55%) | Automated CMS scanning at scale; 1,922 claimed defacements demonstrates capability and intent |
Verified file hashes and network indicators for the supply chain campaigns (MuddyWater/MOIS, Silent Chollima, DustSquad) and ransomware infrastructure (Qilin/REVENANT SPIDER) discussed in this report are available through Anomali ThreatStream. Analysts should pull current indicators directly from ThreatStream and ingest into EDR blocklists, SIEM watchlists, and email gateway filters. IOCs are updated continuously as new samples and infrastructure are confirmed; static publication of hashes in this report has been omitted to prevent dissemination of unverified indicators. Contact your Anomali representative or access ThreatStream directly for the latest structured indicator sets tagged to the threat actors and CVEs covered in this report.
CISA KEV catalog — pull the full CVE list from the August 26–27 additions (9 new entries) and cross-reference against your asset inventory immediately. BOD 22-01 compliance timelines are running. VPN authentication anomalies — credential stuffing, impossible travel, and post-authentication lateral movement are the leading indicators of Qilin/Rhysida intrusion. ICS/OT network segments — any unexpected outbound connections from fuel management, building automation, or water treatment systems should be treated as high-priority alerts.
vssadmin delete shadows, wmic shadowcopy delete, or bcdedit /set {default} recoveryenabled No. Monitor for PsExec, Cobalt Strike, or other lateral movement tools deployed within hours of VPN session start. Detection priority: HIGH — directly tied to Qilin/Rhysida post-compromise playbookorganizationId path parameter does not match the authenticated user's organization. Alert on schema operation endpoint access (table creation, modification, deletion) from users who are not platform administrators. Look for enumeration patterns against public app endpoints that could be used to harvest organization IDs. Detection priority: IMMEDIATE if ToolJet is deployed; N/A otherwise- Audit all identity federation configurations for Keycloak/Red Hat SSO deployments
- Enforce step-up authentication (hardware token MFA) for any transaction exceeding defined thresholds
- Review ToolJet or similar low-code platforms used for financial dashboards — CVE-2026-82874 could expose cross-agency financial data
- Monitor for Qilin/REVENANT SPIDER targeting, which includes financial institutions in its 97-country target list
- Validate network segmentation between IT and OT environments — ensure no flat network paths from VPN concentrators to SCADA/PLC networks
- Audit Siemens Desigo and S7 PLC firmware versions against known MuddyWater/MOIS targeting profiles
- Inventory all IoT devices on utility networks following the QScan/QTRouter botnet exposure
- Implement unidirectional gateways or data diodes for OT network monitoring where feasible
- Prioritize VPN credential hygiene — enforce MFA on all remote access to health information systems
- Ensure HIPAA-regulated systems are segmented from general state network infrastructure
- Patch Keycloak/Red Hat SSO immediately if used for patient portal or provider federation
- Maintain offline backups of Medicaid enrollment and claims processing databases
- VPN hardening is the single highest-impact action: implement conditional access policies requiring device compliance + MFA + geolocation verification across Palo Alto, Cisco, and Citrix platforms
- Conduct emergency inventory of Keycloak, Red Hat SSO, and ToolJet deployments across all agencies
- Review CMS platforms powering .gov websites for vulnerabilities exploitable by automated scanning
- Ensure BOD 22-01 compliance processes can handle the current KEV addition pace
- Inventory all fuel dispensing management systems (Fuel-Boss or equivalent) across state fleet operations
- Apply vendor patches per ICSA-26-239-02 for Fuel-Boss and ICSA-26-239-03 for Rockwell OTTO Fleet Manager
- Ensure fuel management and fleet logistics systems are on isolated network segments with no direct internet exposure
- Assess whether autonomous mobile robot (AMR) systems in state warehouses use OTTO Fleet Manager — apply cryptographic hardening
The threat environment facing state government IT is not defined by exotic zero-days or novel attack techniques. It is defined by the gap between what we know we should do and what we have actually done. CISA's message this week was unusually direct: most compromises succeed because of basic failures — unpatched VPN appliances, misconfigured identity platforms, unaudited SaaS tools, uninventoried OT systems. The adversaries exploiting these gaps are not abstract. Qilin has named your sector as a target and is using your VPN infrastructure as the front door. MuddyWater/MOIS is probing the PLCs that control your water systems. China's MSS was caught this month running an IoT botnet against federal agencies — and the infrastructure rebuild is already underway. A CVSS 9.9 vulnerability in a tool your agencies may have adopted for internal dashboards can destroy data across organizational boundaries. The nine CISA KEV additions in two days are not a statistical anomaly. They are the new normal. The question for state IT leadership is not whether these threats will reach your environment — several of them already have.