TLP:GREEN  ·  States / Public Sector
When Both Locks on the Front Door Break:

Dual Check Point Zero-Days and AI-Powered Hacking at $25 a Target

ELEVATED. Two critical Check Point vulnerabilities - both CVSS 9.8 - are under active exploitation and hit CISA KEV this cycle. A novel infostealer uses a Microsoft-signed kernel driver to kill 145 endpoint security tools before stealing credentials. A supply chain attack compromised a CI/CD pipeline to ship backdoored packages. And autonomous AI agents were documented conducting end-to-end cyberattacks against online retailers for roughly $25 per target - a methodology directly transferable to state citizen-facing payment portals.

I am a
My sector

DevelopmentSignificance
Two Check Point...If your state network uses...
Rapuncel infostealer...Distributed via SEO-poisoned...
MemTensor npm/PyPI...Signals CI/CD pipeline...
NightEagle demonstrate...The playbook maps directly...
Autonomous AI...A methodology directly...
CISA published...Relevant to state facility...
Prior cycle...Both from the September 22...

DateEventSeverity
Aug 2026 (ongoing)Chinese-nexus actor...CRITICAL
Sep 7, 2026APT41 campaign update —...HIGH
Sep 14, 2026Public proof-of-concept...HIGH
Sep 21, 2026LockBit 5.0 (BITWISE...HIGH
Sep 21, 2026Qilin + Metaencryptor...HIGH
Sep 21, 2026Rapuncel infostealer...HIGH
Sep 21, 2026NightEagle (APT-Q-95)...MODERATE
Sep 22, 2026CISA adds 4 vulnerabilities...CRITICAL
Sep 22, 2026CISA publishes 10 ICS...MODERATE
Sep 22, 2026Detailed technical analyses...HIGH
Sep 23, 2026MemTensor npm/PyPI packages...MODERATE
Sep 23, 2026Gambit Security discloses...HIGH (emerging)
Sep 23, 2026TanStack/CrowdSec supply...MODERATE

CVE-2026-85102 allows unauthenticated RCE on Check Point Quantum Gateways via certificate trust validation bypass during VPN negotiation. CVE-2026-93616 allows unauthenticated arbitrary script upload on Management Servers via directory traversal. Both CVSS 9.8, both confirmed actively exploited, both added to KEV Sep 22.

An attacker who...

T1190T1059

Rapuncel uses a kernel driver (Alinubx.sys, renamed CcProtect.sys) carrying a legitimate Microsoft attestation signature through the CnCrypt certificate chain. Windows loads it without complaint; once loaded at Ring 0, it terminates 145 antivirus and EDR processes, then steals credentials from 25+ browsers, Windows Credential Manager, and...

T1189T1574.002T1562.001T1003

The MemTensor attacker infiltrated the GitHub Actions release workflow itself, intercepting publish tokens before the legitimate build job could use them, then shipped backdoored packages to npm and PyPI under the project's real name - no malicious PR, no typosquatting. This follows the TanStack/CrowdSec pattern and signals CI/CD pipeline...

T1195.002T1528

NightEagle (APT-Q-95) demonstrated a complete attack chain currently targeting Russian organizations: compromised VPN credentials, Exchange server backdoor, BlueKeep lateral movement, DCSync credential replication. The playbook maps directly onto typical state government hybrid Active Directory architecture - the techniques, not just the...

T1078T1133T1210T1003.006

A financially motivated operator directed three open-source AI agent tools (Strix, Cairn, Hermes) to autonomously discover vulnerabilities, exploit targets, deploy web skimmers, and steal 600,000+ credit card records - at roughly $25 per compromised target. This methodology is directly transferable to state citizen-facing payment portals and...

ScenarioProbabilityBasis
Exploitation of unpatched...HIGH (75-85%)CVSS 9.8, confirmed active...
Ransomware group (LockBit...HIGH (70-80%)State/local government is the...
BYOVD technique (Rapuncel...MODERATE (40-55%)...SEO poisoning targets...
Supply chain compromise...MODERATE (35-50%)...Four active supply chain...
Autonomous AI agent...LOW-MODERATE...Currently documented...
NightEagle TTPs (VPN→Exchange→...MODERATE (40-50%)...The technique sequence is...
Exploitation of Siemens...LOW-MODERATE...No active exploitation...

Check Point Exploitation (CVE-2026-85102 / CVE-2026-93616):

Monitor for anomalous VPN...

Rapuncel BYOVD Detection:

Hunt for service creation with...

NightEagle / AD Attack Chain Detection:

DCSync detection:...

Supply Chain / CI-CD Compromise:

Alert on unexpected package...

"Are any state endpoints running a kernel driver signed by Henan Dafeng Software or CnCrypt?":

Query EDR telemetry for driver...

"Has any non-DC host in our Active Directory issued a DRS replication request in the past 30 days?":

This is the definitive DCSync...

"Have any Check Point Management Server logs shown file upload events from non-administ...:

Covers the exploitation window...

"Are any state GitHub Actions workflows using long-lived publish tokens instead of OIDC...:

Identifies exposure to the...

ThreatATT&CK
Check Point Exploitation...T1059.001...
Rapuncel BYOVD DetectionT1574.002...
NightEagle / AD Attack...T1003.006...
Supply Chain / CI-CD...T1195.002...
IOC Blocking Table:
155.254.22[.]215209.126.4[.]170213.21.239[.]62172.245.224[.]188172.245.89[.]1372.26.126[.]5027.14.2[.]173172.252.225[.]152142.115.58[.]2723.234.84[.]102medbooksource[.]comtraffic-analyzer[.]netb8t[.]shopcdn[.]netlfjs[.]comx1opay[.]costatic-js[.]comcdn[.]js-static[.]comjs-static[.]comjsnetlify[.]comnetlifyjs[.]comnewssjs[.]com

Block the above at perimeter...

Host-Based IndicatorControl Layer
nvfsflt64.sys in...EDR / WDAC
vsdbg.dll side-loaded...File-integrity monitoring
Hunting Hypotheses:
HUNT 01
"Are any state endpoints running a kernel driver signed by Henan Dafeng Software or CnCrypt?"
Query EDR telemetry for driver load events matching these signer names. Any hit indicates Rapuncel or a related BYOVD campaign.
HUNT 02
"Has any non-DC host in our Active Directory issued a DRS replication request in the past 30 days?"
This is the definitive DCSync indicator. Zero false positives if your DC inventory is accurate. 3. *"Are any state systems resolving .devtunnels.ms?"** — Microsoft Dev Tunnels is a legitimate service but has no authorized use case in most state government environments. Any resolution is suspicious.
HUNT 03
"Have any Check Point Management Server logs shown file upload events from non-administ...
Covers the exploitation window for CVE-2026-93616.
HUNT 04
"Are any state GitHub Actions workflows using long-lived publish tokens instead of OIDC...
Identifies exposure to the MemTensor-style token interception attack. ---

Financial Services
Treasury, Revenue, Tax Systems
Primary threat
Check Point dual-RCE directly threatens VPN/management infrastructure; AI agent skimmer methodology...
Actions
  • Patch Check Point deployments immediately; audit citizen-facing payment portals for skimmer indicators
Energy
Grid Coordination, Utility Oversight
Primary threat
10 ICS advisories affect Siemens and lwIP-based systems common in state energy oversight; Volt...
Actions
  • Cross-reference ICS advisories against OT inventory; verify IT/OT segmentation
Healthcare
Medicaid, HHS Systems
Primary threat
Rapuncel's credential theft and NightEagle's AD attack chain both threaten hybrid identity...
Actions
  • Deploy Rapuncel driver/hash detection; audit VPN-to-AD attack surface given the NightEagle playbook
Government
Executive Agencies, Law Enforcement
Primary threats
Primary target across every threat this cycle - perimeter, endpoint, supply chain, and AI-enabled...
Actions
  • Verify and patch Check Point deployments today; brief agency CIOs on the convergence of threats
Aviation / Logistics
DOT, Airport Authorities
Primary threat
ICS advisories relevant to facility management; supply chain risk from CI/CD-dependent...
Actions
  • Review 10 CISA ICS advisories against transportation OT inventory; audit CI/CD pipeline token security
No sector cards match the selected filters.

Verify and patch Check Point for CVE-2026-85102...
Incident Responder
Deploy Rapuncel detection: hunt Alinubx/CcProtect...
SOC Analyst
Audit GitHub Actions token security given the...
Incident Responder
Block AI agent IOCs (see table); monitor...
SOC Analyst
No immediate actions for the selected roles.
Review CISA ICS advisories against state OT/SCADA...
ICS / OT
Audit hybrid AD against the NightEagle VPN-to-DC...
IAM Analyst
Resolve outstanding Zyxel/Veeam vulnerabilities from...
Incident Responder
Brief dev teams on CI/CD token security given...
CISO / Exec
No 7-day actions for the selected roles.
Commission a payment review given the AI agent...
CISO / Exec
Develop an AI-threat detection strategy for agents...
CISO / Exec
Conduct a tabletop for a Check Point scenario...
CISO / ExecIncident Responder
Review CI/CD posture across all state...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

This cycle: critical perimeter vulnerabilities, endpoint protection defeated by kernel-level evasion, supply chain integrity compromised at the pipeline level, and autonomous AI-powered exploitation making every internet-facing app a cost-effective target. Verify and patch Check...

1
Verify and patch Check Point deployments today.
2
Reassess endpoint protection assumptions given Rapuncel's BYOVD technique.
3
Start thinking about the security of every citizen-facing web application.
No items found.