TLP:GREEN  ·  States / Public Sector
When Basic Failures Meet Advanced Adversaries:

What State IT Leaders Need to Know This Week

ELEVATED. Maintained from the prior cycle — driven by accelerating vulnerability exploitation, confirmed ransomware targeting of state/local government, and expanding ICS/OT attack surface. CISA said it plainly this week: "Basic security failures enable most compromises." Nine new actively exploited vulnerabilities were added to CISA's KEV catalog in two days, a CVSS 9.9 SaaS vulnerability allows cross-tenant data destruction, a critical identity flaw lets a standard user forge administrator tokens, and a ransomware group has explicitly named state government, local government, and law enforcement as targets — with VPN credential compromise as their preferred way in.

I am a
My sector

DevelopmentSignificance
Nine new CISA KEV entries were added on August 26–27, representing an elevated pace of confirmed in-the-wild exploitation. BOD 22-01 compliance timelines are now running on all nine.9 KEVs in 2 days — elevated exploitation tempo requiring immediate cross-reference against asset inventory
REVENANT SPIDER (Qilin ransomware) had its threat profile updated on August 31, explicitly confirming state government, local government, and law enforcement as named target sectors across 97 countries including the United States. Their primary initial access method: compromised VPN credentials.VPN credential compromise is the confirmed #1 ransomware entry vector for state government
CVE-2026-82874 (ToolJet, CVSS 9.9) was disclosed — a cross-tenant authorization bypass in a low-code internal tool builder that allows authenticated users to read, modify, and permanently destroy data belonging to other organizations sharing the same platform.Systemic multi-tenant isolation failure in low-code platforms agencies are rapidly adopting
CVE-2026-16102 (Keycloak/Red Hat SSO, CVSS 8.1) was disclosed — a privilege escalation flaw that allows any standard user with a limited access token to forge administrative roles, take over other clients, steal secrets, and gain full realm administrative control.Any standard user account can escalate to realm administrator
Five new ICS advisories from CISA included a remote code execution vulnerability in All-Line Equipment Fuel-Boss fuel management systems — the kind of system that manages fuel dispensing for state government vehicle fleets — and vulnerabilities in Rockwell Automation OTTO Fleet Manager and multiple IoT devices.Direct physical-world risk to state fleet fuel management and logistics operations
Multi-actor supply chain indicators surfaced, attributed to MuddyWater/MOIS (Iran), Silent Chollima (North Korea), and DustSquad (Central Asia) — all targeting government networks via supply chain compromise techniques.Multiple nation-state actors converging on government supply chain vectors
Turkish hacktivist group Anka Team claimed 1,922 defacements on August 30, including confirmed U.S. .gov domains, demonstrating automated CMS scanning capability at scale against web-facing government assets.Automated CMS scanning at scale demonstrates capability and intent against .gov domains
The FBI/DOJ seizure of the QScan/QTRouter IoT botnet (reported August 30) — operated on behalf of China's Ministry of State Security and People's Liberation Army, and used to target NASA, the Department of Energy, and the U.S. Senate — remains a significant contextual event from the prior cycle.Confirms Chinese state targeting of U.S. government networks; compromised devices may persist after seizure

DateEventRelevance to State Government
Aug 26CISA adds 6 vulnerabilities to KEV catalogBOD 22-01 compliance — patch or mitigate within mandated timelines
Aug 26CISA publishes strategic Vulnerability ReviewPolicy signal: "basic security failures enable most compromises"
Aug 27CISA adds 3 more vulnerabilities to KEV catalog9 KEVs in 2 days — elevated exploitation tempo
Aug 275 ICS advisories published (Rockwell, Fuel-Boss, IoT devices)Fuel-Boss RCE directly threatens state fleet fuel management
Aug 28Multiple supply chain attack campaigns updated in threat feedsGovernment-targeting supply chain IOCs with Iran/DPRK attribution
Aug 30FBI/DOJ seizes China MSS/PLA IoT botnet infrastructureConfirms Chinese state targeting of U.S. government networks
Aug 30Turkish hacktivist group Anka Team claims 1,922 defacements including U.S. .gov domainsWeb-facing state government assets at risk from automated CMS scanning
Aug 31REVENANT SPIDER (Qilin) profile updated — state/local gov confirmed as targetsVPN credential compromise is their primary entry vector
Aug 31CVE-2026-82874 (ToolJet CVSS 9.9) and CVE-2026-16102 (Keycloak CVSS 8.1) disclosedSaaS and IAM platforms used by government agencies carry critical flaws

The REVENANT SPIDER group — operators of the Qilin ransomware (also tracked as Agenda/Stinkbug) — updated their operational profile this week with explicit confirmation of what many state CISOs already suspected: state government, local government, law enforcement, and emergency services are named target industries.

Their playbook is well-documented: initial access via compromised VPN credentials (directly relevant to Palo Alto GlobalProtect, Cisco ASA/FTD, and Citrix NetScaler deployments common in state environments); post-compromise using legitimate system tools (living-off-the-land), making detection harder; double extortion — data exfiltration before encryption, with DDoS and legal pressure as additional coercion tactics; and Rust-based ransomware distributed through a ransomware-as-a-service affiliate model.

This is not theoretical. Qilin recently breached a federal law enforcement entity, and the Rhysida ransomware group has directly hit state government through VPN-to-exfiltration attack chains. Both groups are active, both target government, and both exploit the same entry point: VPN infrastructure.

T1133T1078T1486T1567

CVE-2026-16102 in Keycloak (Red Hat SSO) is the kind of vulnerability that keeps identity architects up at night. The flaw is in the Dynamic Client Registration component: an attacker with nothing more than a standard user account and a limited Initial Access Token can manipulate claim paths to forge administrative roles in their access token. From there, they can take over other clients, steal secrets, and gain full realm administrative control.

For state agencies using Keycloak or Red Hat SSO for identity federation — common in open-source-leaning government IT environments — this is an immediate patching priority. Patches are available in RHSA-2026:50846 through RHSA-2026:50849.

T1134.001T1078.004T1528T1068

CVE-2026-82874 carries a CVSS score of 9.9 — nearly the maximum possible — for good reason. In ToolJet (a low-code internal tool builder used by some government organizations for dashboards and workflow automation), any authenticated Builder user can manipulate the organizationId path parameter to read, modify, and permanently destroy data belonging to other tenants on the same platform.

Attackers can extract victim organization IDs from publicly accessible app endpoints, then exploit schema operation endpoints to disclose database schemas, plant malicious tables, corrupt data, or destroy it entirely.

This vulnerability is part of an emerging pattern. Combined with the triple-CVSS-10 vulnerabilities in ServiceNow disclosed earlier this month, state IT leaders face a systemic risk: the low-code/no-code platforms agencies are rapidly adopting for internal tooling carry catastrophic multi-tenant isolation failures.

T1190T1485T1530

Five new ICS advisories from CISA this week included one that should get immediate attention from state fleet and transportation operations: ICSA-26-239-02 (All-Line Equipment Fuel-Boss) — a remote code execution vulnerability in fuel dispensing management systems.

State governments operate large vehicle fleets for law enforcement, transportation, and public works, often with centralized fuel management. Remote code execution on these systems could enable fuel theft at scale, disruption of emergency vehicle fueling during crisis response, and manipulation of fuel inventory records.

Additional advisories covered Rockwell Automation OTTO Fleet Manager (weak cryptographic hashing enabling offline brute-force) and multiple IoT devices (Xiiaozet LK100W, Ebyte NA111-M) with full device takeover vulnerabilities — relevant given the China MSS IoT botnet infrastructure seized by the FBI on August 30.

T1190T0831T0836

Threat intelligence feeds this week surfaced file indicators carrying multi-actor attribution tags that tell a concerning story about the supply chain threat to government networks. Attributed actors include MuddyWater/MOIS (Iran), Silent Chollima (DPRK), Dalbit, and DustSquad (Central Asia), with associated malware families including Neshta, Hive ransomware, and Expiro.

The MuddyWater/MOIS-attributed indicator is particularly notable — it carries tags for three different nation-state actor groups plus both APT espionage and ransomware malware families, suggesting either shared tooling across actor ecosystems or a file infector (Neshta) that has propagated across multiple threat actor supply chains.

Continued context: Volt Typhoon and Salt Typhoon showed zero new activity signals this cycle — historical patterns suggest a 2–4 week infrastructure rebuild cycle following the QScan/QTRouter botnet exposure. IRGC-affiliated groups continue targeting U.S. water and wastewater systems (100+ facilities), while MuddyWater/UNC5667 actively targets Siemens S7 PLCs across seven or more states.

T1195.002T1204.002

ScenarioProbabilityBasis
Additional CISA KEV additions at elevated pace (5+ per week)HIGH (75–85%)9 KEVs in 2 days indicates sustained exploitation tempo; CISA's strategic review signals continued aggressive cataloging
Qilin/REVENANT SPIDER affiliate attack against a U.S. state or local government entityMODERATE-HIGH (50–65%)Refreshed targeting profile explicitly names state/local gov; VPN credential compromise is a low-barrier initial access method; RaaS affiliate model increases attack volume
Exploitation of Keycloak CVE-2026-16102 in the wildMODERATE (45–60%)Straightforward token forgery from standard user account; Red Hat advisories are public; 14-day exploitation window typical for IAM vulnerabilities
Volt Typhoon/Salt Typhoon operational resurgence on new infrastructureLOW-MODERATE (30–45%)Historical 2–4 week rebuild cycle following infrastructure exposure; MSS/PLA operational tempo unlikely to decrease despite seizure
Exploitation of ToolJet CVE-2026-82874 against government tenantsMODERATE (40–55%)CVSS 9.9 with straightforward exploitation path; government adoption of low-code platforms creates target-rich environment
Anka Team or similar hacktivist group targeting additional .gov domainsMODERATE (45–55%)Automated CMS scanning at scale; 1,922 claimed defacements demonstrates capability and intent

What to Block:

Verified file hashes and network indicators for the supply chain campaigns (MuddyWater/MOIS, Silent Chollima, DustSquad) and ransomware infrastructure (Qilin/REVENANT SPIDER) discussed in this report are available through Anomali ThreatStream. Analysts should pull current indicators directly from ThreatStream and ingest into EDR blocklists, SIEM watchlists, and email gateway filters. IOCs are updated continuously as new samples and infrastructure are confirmed; static publication of hashes in this report has been omitted to prevent dissemination of unverified indicators. Contact your Anomali representative or access ThreatStream directly for the latest structured indicator sets tagged to the threat actors and CVEs covered in this report.

What to Monitor:

CISA KEV catalog — pull the full CVE list from the August 26–27 additions (9 new entries) and cross-reference against your asset inventory immediately. BOD 22-01 compliance timelines are running. VPN authentication anomalies — credential stuffing, impossible travel, and post-authentication lateral movement are the leading indicators of Qilin/Rhysida intrusion. ICS/OT network segments — any unexpected outbound connections from fuel management, building automation, or water treatment systems should be treated as high-priority alerts.

Hunting Hypotheses:
HUNT 01 · T1133
Hypothesis 1: VPN Credential Stuffing / Brute Force (Qilin/Rhysida Initial Access)
Data sources: VPN authentication logs (Palo Alto GlobalProtect, Cisco ASA, Citrix NetScaler), Azure AD/Entra ID sign-in logs Hunt query logic: Look for multiple failed VPN authentications from a single source IP followed by a successful login, especially from residential proxy or VPN exit node IP ranges. Flag successful VPN logins from geographies inconsistent with the user's normal pattern. Correlate with any subsequent lateral movement (RDP, SMB, WMI) within 60 minutes of VPN session establishment. Detection priority: HIGH — this is the confirmed #1 ransomware entry vector for state government
HUNT 02 · T1134.001
Hypothesis 2: Keycloak/Red Hat SSO Token Forgery (CVE-2026-16102)
Data sources: Keycloak audit logs, OAuth/OIDC token issuance logs, Red Hat SSO event logs Hunt query logic: Look for Dynamic Client Registration (DCR) requests that include User Property mapper configurations with unusual claim paths. Alert on any token issuance where the granted roles exceed the user's assigned roles in the identity store. Monitor for rapid client creation/modification followed by token requests with elevated privileges. Detection priority: IMMEDIATE if Keycloak/Red Hat SSO is deployed; N/A otherwise
HUNT 03 · T1195.002
Hypothesis 3: Supply Chain File Infector Execution (Neshta/Expiro)
Data sources: EDR telemetry, file integrity monitoring, email gateway logs Hunt query logic: Hunt for Neshta behavioral indicators: modification of legitimate executables to prepend malicious code, unusual file size changes in system binaries. Hunt for Expiro indicators: injection into running processes with network callback behavior. For verified file hashes associated with MuddyWater/MOIS, Silent Chollima, Dalbit, and DustSquad supply chain campaigns targeting government networks, retrieve current indicators directly from Anomali ThreatStream — hashes are updated as new samples are confirmed. Detection priority: HIGH — confirmed government-targeting actor campaigns
HUNT 04 · T1562.001
Hypothesis 4: Living-off-the-Land Post-Compromise (Qilin Affiliate Playbook)
Data sources: Sysmon, Windows Event Logs (4688, 4624, 7045), EDR process telemetry Hunt query logic: Following any VPN authentication anomaly, look for: disabling of security tools (Windows Defender, AV services), use of vssadmin delete shadows, wmic shadowcopy delete, or bcdedit /set {default} recoveryenabled No. Monitor for PsExec, Cobalt Strike, or other lateral movement tools deployed within hours of VPN session start. Detection priority: HIGH — directly tied to Qilin/Rhysida post-compromise playbook
HUNT 05 · T1190
Hypothesis 5: Cross-Tenant SaaS Exploitation (ToolJet)
Data sources: ToolJet application logs, WAF logs, API gateway logs Hunt query logic: Monitor for API requests where the organizationId path parameter does not match the authenticated user's organization. Alert on schema operation endpoint access (table creation, modification, deletion) from users who are not platform administrators. Look for enumeration patterns against public app endpoints that could be used to harvest organization IDs. Detection priority: IMMEDIATE if ToolJet is deployed; N/A otherwise

Financial Services
State Treasury, Revenue, Pension Funds
Primary threats
State financial agencies process billions in tax revenue, pension disbursements, and bond transactions. The Keycloak/Red Hat SSO privilege escalation (CVE-2026-16102) is particularly dangerous here — forged administrative tokens could grant access to financial systems federated through SSO.
Actions
  • Audit all identity federation configurations for Keycloak/Red Hat SSO deployments
  • Enforce step-up authentication (hardware token MFA) for any transaction exceeding defined thresholds
  • Review ToolJet or similar low-code platforms used for financial dashboards — CVE-2026-82874 could expose cross-agency financial data
  • Monitor for Qilin/REVENANT SPIDER targeting, which includes financial institutions in its 97-country target list
Energy
State-Regulated Utilities, Power Grid Coordination
Primary threats
The convergence of Iranian IRGC targeting of water/wastewater systems, MuddyWater/MOIS activity against Siemens PLCs, and the China MSS IoT botnet seizure creates a multi-vector threat to energy infrastructure.
Actions
  • Validate network segmentation between IT and OT environments — ensure no flat network paths from VPN concentrators to SCADA/PLC networks
  • Audit Siemens Desigo and S7 PLC firmware versions against known MuddyWater/MOIS targeting profiles
  • Inventory all IoT devices on utility networks following the QScan/QTRouter botnet exposure
  • Implement unidirectional gateways or data diodes for OT network monitoring where feasible
Healthcare
State Health Agencies, Medicaid Systems, Public Health Labs
Primary threats
Healthcare remains a top ransomware target, and Qilin's explicit targeting of government services includes health agencies.
Actions
  • Prioritize VPN credential hygiene — enforce MFA on all remote access to health information systems
  • Ensure HIPAA-regulated systems are segmented from general state network infrastructure
  • Patch Keycloak/Red Hat SSO immediately if used for patient portal or provider federation
  • Maintain offline backups of Medicaid enrollment and claims processing databases
Government
Executive Agencies, Legislature, Courts, Elections
Primary threat
State government agencies are the primary target for every threat discussed in this report.
Actions
  • VPN hardening is the single highest-impact action: implement conditional access policies requiring device compliance + MFA + geolocation verification across Palo Alto, Cisco, and Citrix platforms
  • Conduct emergency inventory of Keycloak, Red Hat SSO, and ToolJet deployments across all agencies
  • Review CMS platforms powering .gov websites for vulnerabilities exploitable by automated scanning
  • Ensure BOD 22-01 compliance processes can handle the current KEV addition pace
Aviation / Logistics
State DOT, Airports, Fleet Operations
Primary threat
The All-Line Fuel-Boss RCE (ICSA-26-239-02) and Rockwell OTTO Fleet Manager vulnerabilities directly affect state transportation and logistics operations.
Actions
  • Inventory all fuel dispensing management systems (Fuel-Boss or equivalent) across state fleet operations
  • Apply vendor patches per ICSA-26-239-02 for Fuel-Boss and ICSA-26-239-03 for Rockwell OTTO Fleet Manager
  • Ensure fuel management and fleet logistics systems are on isolated network segments with no direct internet exposure
  • Assess whether autonomous mobile robot (AMR) systems in state warehouses use OTTO Fleet Manager — apply cryptographic hardening
No sector cards match the selected filters.

Retrieve current file hash indicators for MuddyWater/MOIS, Silent Chollima, and DustSquad supply chain campaigns from Anomali ThreatStream and ingest into EDR blocklists and SIEM watchlists.
SOC Analyst
Verify whether any agency deploys Keycloak or Red Hat SSO for identity federation. If yes, apply patches RHSA-2026:50846 through RHSA-2026:50849 immediately — CVE-2026-16102 allows any standard user to escalate to realm administrator.
Incident Responder
Inventory all ToolJet deployments across agencies. Any instance below v3.16.208 must be upgraded immediately — CVE-2026-82874 (CVSS 9.9) allows cross-tenant data destruction.
Incident Responder
Pull the full CVE list from CISA KEV additions of August 26–27 (9 new entries) and cross-reference against the state asset inventory. Prioritize any matches for emergency patching per BOD 22-01 timelines.
SOC Analyst
Audit VPN authentication logs across all three VPN platforms (Palo Alto GlobalProtect, Cisco ASA, Citrix NetScaler) for credential stuffing patterns, impossible travel, and anomalous post-authentication behavior.
SOC Analyst
No immediate actions for the selected roles.
Determine whether state fleet operations use All-Line Equipment Fuel-Boss or similar fuel management systems. If deployed, apply vendor patches per ICSA-26-239-02.
ICS / OT
Review Rockwell Automation OTTO Fleet Manager deployments in warehouses and logistics facilities. Apply cryptographic hardening per ICSA-26-239-03.
ICS / OT
Implement VPN-focused detection rules: alert on multiple failed VPN authentications from a single source followed by successful login; alert on VPN sessions followed by lateral movement within 60 minutes; alert on VPN logins from residential proxy or VPN exit node IP ranges.
SOC Analyst
Audit all .gov web properties for CMS vulnerabilities exploitable by automated scanning tools, in light of the Anka Team's confirmed defacement of U.S. .gov domains.
Incident Responder
Inventory IoT devices on state networks and cross-reference against known QScan/QTRouter botnet indicators — compromised devices may persist after infrastructure seizure.
Incident Responder
No 7-day actions for the selected roles.
Use CISA's Vulnerability Review strategic guidance to reinforce patching program budget justification with the Governor's office and legislature.
CISO / Exec
Commission a security assessment of all low-code/no-code SaaS platforms deployed across agencies. ToolJet and ServiceNow represent a systemic pattern of critical multi-tenant vulnerabilities.
CISO / Exec
Implement conditional access policies for all VPN authentication requiring device compliance verification + phishing-resistant MFA + geolocation validation.
IAM Analyst
Establish a centralized OT asset registry covering fuel management, water treatment, building automation, and manufacturing PLC systems across all agencies.
ICS / OT
Develop or update the state's ransomware incident response playbook to specifically address the Qilin/REVENANT SPIDER double-extortion model: simultaneous data exfiltration, encryption, DDoS, and legal pressure tactics require coordinated response.
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

The threat environment facing state government IT is not defined by exotic zero-days or novel attack techniques. It is defined by the gap between what we know we should do and what we have actually done. CISA's message this week was unusually direct: most compromises succeed because of basic failures — unpatched VPN appliances, misconfigured identity platforms, unaudited SaaS tools, uninventoried OT systems. The adversaries exploiting these gaps are not abstract. Qilin has named your sector as a target and is using your VPN infrastructure as the front door. MuddyWater/MOIS is probing the PLCs that control your water systems. China's MSS was caught this month running an IoT botnet against federal agencies — and the infrastructure rebuild is already underway. A CVSS 9.9 vulnerability in a tool your agencies may have adopted for internal dashboards can destroy data across organizational boundaries. The nine CISA KEV additions in two days are not a statistical anomaly. They are the new normal. The question for state IT leadership is not whether these threats will reach your environment — several of them already have.

1
Start with the VPN logs.
2
Inventory the identity platforms. Patch what you can today.
3
Have the budget conversation with your leadership — CISA just gave you the talking points.
No items found.