TLP:GREEN  ·  States / Public Sector
When Print Servers Become Entry Points:

Active Exploitation, Ransomware Staging, and VPN Zero-Days Converge on Government Networks

ELEVATED. Unchanged from prior cycle — sustained by active exploitation of agency-common systems, fresh ransomware infrastructure targeting government, and critical VPN appliance vulnerabilities awaiting weaponization. A pre-authentication remote code execution chain in PaperCut NG/MF is being actively exploited in the wild — with a public Metasploit module accelerating attacker adoption — and CISA has set a September 14 federal remediation deadline. Simultaneously, WatchGuard disclosed five CVSS 9.3 critical vulnerabilities in its Fireware OS VPN daemon that require no authentication to exploit, and SafePay ransomware operators are standing up fresh C2 infrastructure explicitly tagged for government targeting.

I am a
My sector

DateDevelopmentSignificance
Aug 26–27CISA added nine vulnerabilities to the KEV catalog and published a strategic Vulnerability Review stating "basic security failures enable most compromises"Sets the policy tone: federal compliance expectations are tightening
Aug 28WatchGuard discloses 23+ vulnerabilities including five CVSS 9.3 critical flaws in the iked VPN daemon (CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-13086, CVE-2026-78174)Any internet-facing WatchGuard firewall running unpatched Fireware OS is exposed to unauthenticated RCE
Aug 28UK NCSC publishes advisory on escalating attacks against internet-exposed OT/ICS systems; CISA reports 100+ U.S. water/wastewater systems attacked in JulyDirect relevance to state-managed water treatment and building automation
Aug 28 – ongoingFake AI crawler campaign (824 IPs, active since Jul 28) scanning for exposed .env files, AWS credentials, and cloud secrets across internet-facing serversState agencies running citizen-facing web applications and cloud-backed API gateways are directly in scope
Aug 30Turkish hacktivist group Anka Team claims 1,922 defacements including confirmed U.S. .gov domainsAutomated CMS scanning continues to find unpatched government web properties
Aug 31CISA adds CVE-2026-81578 (CVSS 9.8) and CVE-2026-82078 (CVSS 9.1) to KEV — PaperCut NG/MF pre-auth RCE chain with confirmed exploitation and public Metasploit moduleTop action item this cycle. PaperCut is deployed across courts, schools, and agency offices statewide
Aug 31SafePay ransomware C2 infrastructure (3 IPs, confidence 94–96) ingested with explicit government targeting tagStaging activity — ransomware operators typically deploy 1–3 weeks after infrastructure setup
Aug 31Qilin (REVENANT SPIDER) updates targeting profile to explicitly name state/local government and law enforcement across 97 countriesConfirms government remains a primary ransomware target
Aug 31Compromise of npm package @7nohe/openapi-react-query-codegen confirmed — 10 malicious versions carried valid provenance attestations, bypassing standard npm audit signature checksAny state agency Node.js modernization project may be affected; developer workstations at risk even without direct production use
Sep 1Russia-nexus actors deploying "GuardBreaker" technique — adversarial prompt injections embedded in malware to evade or blind AI-assisted analysis toolsSOC teams using LLM-assisted triage pipelines should validate that raw malware content is sandboxed before LLM processing
Sep 1Cofense publishes active threat report on ConnectWise ScreenConnect RAT delivered via finance-themed phishingLegitimate remote access tools weaponized as persistent backdoors — a pattern increasingly aimed at government

WindowActor / CampaignTargetStatus
Jul 28 – Aug 23Fake AI Crawler Campaign (824 IPs)Cloud credentials, .env files, AWS secrets on any internet-facing serverActive scanning
Aug 14 – Aug 25Colorado voter data breach130K+ confidential voter records exposed via software glitchDisclosed; peer-state lesson
Aug 26 – Aug 27CISA KEV batch + Vulnerability ReviewFederal agencies, state agencies under BOD 22-01Compliance deadline active
Aug 28WatchGuard Fireware critical disclosuresAll WatchGuard customers with internet-facing appliancesPatch available; no exploitation yet
Aug 28UK NCSC OT/ICS advisoryWater, building automation, industrial control systems globallyActive exploitation of exposed OT
Aug 30Anka Team .gov defacementsU.S. government web propertiesConfirmed
Aug 31PaperCut dual-KEV (CVE-2026-81578 + CVE-2026-82078)Education, government, healthcare — PaperCut NG/MF deploymentsActive exploitation; Metasploit module public
Aug 31SafePay ransomware C2 stagingGovernment (explicit targeting tag)Infrastructure staging — pre-operational
OngoingQilin / REVENANT SPIDERState/local government, law enforcement (97 countries)Active; VPN credential compromise as primary vector
OngoingMuddyWater (MOIS/Iran)Government networks via supply chain compromisePersistent threat
OngoingIRGC (Iran)U.S. water/wastewater infrastructurePersistent threat
OngoingChina-nexus (Volt Typhoon, Salt Typhoon, APT41)U.S. state government — pre-positioning and espionageNo new activity detected; not assumed safe

CVE-2026-81578 (CVSS 9.8) allows an unauthenticated attacker to modify PaperCut system configurations through a page-rendering mismatch. CVE-2026-82078 (CVSS 9.1) enables arbitrary Java bytecode execution via unsafe reflection — running under SYSTEM privileges. Chained together, these deliver pre-authentication remote code execution on any reachable PaperCut server.

Huntress confirmed exploitation in two customer environments and independently reproduced a full RCE chain against a vanilla PaperCut NG installation. Observed attacker behavior included whoami, ver, and tasklist reconnaissance — classic pre-ransomware staging. A Metasploit module is publicly available, dramatically lowering the skill barrier for exploitation.

The critical statistic: approximately 47% of the ~2,500 PaperCut installations Huntress tracks still run version 23 or earlier, for which no patch exists. These systems must be isolated or decommissioned.

For state agencies, PaperCut is ubiquitous — courts, DMV offices, school districts, and administrative buildings all rely on centralized print management. A compromised PaperCut server running as SYSTEM on a domain-joined machine is a direct path to Active Directory compromise.

T1190T1059.007T1082T1057T1070.004

Five CVSS 9.3 vulnerabilities in WatchGuard's iked daemon — the process that handles IPsec VPN negotiations — can be exploited by sending specially crafted network traffic. No credentials required. No user interaction needed. Three of the five (CVE-2026-19313, CVE-2026-19318, CVE-2026-19315) target the IKE daemon directly; CVE-2026-13086 targets the Endpoint Protection Manager; CVE-2026-78174 exposes session IDs in the Dimension web UI.

No exploitation has been observed in the wild yet, but the attack surface — unauthenticated, network-reachable, handling untrusted traffic by design — makes weaponization highly likely. State agencies using WatchGuard for branch office or remote-site VPN connectivity should treat this as a race against exploit developers.

T1190T1210

Fresh command-and-control infrastructure for SafePay ransomware was ingested on August 31 with explicit government targeting tags and confidence scores of 94–96. Three C2 IPs are hosted on budget VPS providers (Nubes LLC in the U.S. and Contabo in France) — consistent with ransomware operators' preference for disposable infrastructure.

SafePay joins Qilin (REVENANT SPIDER), Rhysida, Akira (PUNK SPIDER), Play (RECESS SPIDER), and InterLock (VICE SPIDER) in actively targeting government entities. Qilin's recent update explicitly names state/local government and law enforcement across 97 countries, with VPN credential compromise as the primary initial access vector — a detail that intersects directly with the WatchGuard vulnerabilities above.

T1486T1071.001T1566

Between July 28 and August 23, GreyNoise identified 824 IP addresses impersonating legitimate AI web crawlers (ClaudeBot, GPTBot, Google-Extended, PerplexityBot, DeepSeek) to scan for exposed .env files, AWS credentials, Git configurations, and private keys. All 824 IPs shared a single HTTP client fingerprint and none matched any legitimate crawler IP range. Tellingly, none of the fake crawlers ever requested /robots.txt — a simple behavioral indicator that distinguishes them from real crawlers.

For state agencies running citizen-facing web applications, API gateways, or modernization projects with cloud backends, this campaign represents a direct credential theft risk. A single exposed .env file containing database credentials or API keys can provide initial access to production systems.

T1595.002T1552.001T1213

The compromise of the npm package @7nohe/openapi-react-query-codegen introduced a new dimension to supply chain risk: all 10 malicious package versions carried valid npm provenance attestations created through GitHub Actions trusted publishing. The attack exploited a vulnerable release.yml workflow that executed on issue_comment events without verifying commenter authorization. Standard npm audit signature checks would not flag these packages as malicious.

Any state agency modernization project using Node.js — citizen portals, API gateways, internal tools — should audit dependency lockfiles immediately. The malicious versions also targeted AI development tool configurations (Claude, Copilot, Cursor, Gemini), meaning developer workstations are at risk even if production systems don't use the compromised package directly.

Nation-state landscape: China-nexus TRACKSTOMP/EMPTYROAD targets education and government; Russia-nexus UAC-0099 deploys "GuardBreaker" (adversarial prompt injections embedding in malware to evade AI-assisted analysis); Iran's MuddyWater targets government via supply chain; North Korea's APT43/Famous Chollima target government for credential theft.

T1195.002

ScenarioProbabilityTimeframeBasis
PaperCut exploitation escalates from reconnaissance to ransomware deployment or persistent accessHIGH (>75%)7 daysPublic Metasploit module + 47% unpatched population + confirmed active exploitation
WatchGuard iked vulnerabilities see proof-of-concept exploit developmentMODERATE-HIGH (50–75%)7–14 daysUnauthenticated attack surface + detailed advisory information enabling reverse engineering
SafePay claims a government victimMODERATE (50–75%)14 daysFresh C2 infrastructure staging typically precedes deployment by 1–3 weeks
Fake AI crawler campaign expands to specifically target state government web applicationsLOW-MODERATE (25–50%)14–30 daysBroad scanning infrastructure (824 IPs) + government's increasing cloud adoption
Qilin or Rhysida ransomware incident at a U.S. state or local government entityMODERATE (50–75%)30 daysExplicit targeting declarations + VPN credential compromise vector aligns with WatchGuard exposure
Nation-state actor (China-nexus) discovery in a U.S. state government networkLOW-MODERATE (25–50%)60 daysHistorical pattern of long-dwell operations; absence of detection ≠ absence of presence

PaperCut Exploitation (CVE-2026-81578 + CVE-2026-82078):

Hunt Hypothesis: Attackers are exploiting PaperCut servers to achieve SYSTEM-level code execution, followed by reconnaissance and potential lateral movement. Detection: - Monitor PaperCut server processes for child process spawning: cmd.exe, powershell.exe, whoami.exe, tasklist.exe (T1082, T1057) - Search Derby database logs (/data/internal/derby.log) for the string memory:...pwn — this is a confirmed exploitation artifact - Alert on the temporary file Udydn.out creation and deletion on PaperCut servers - Monitor for deletion of server.log on PaperCut hosts (T1070.004 — Indicator Removal) - Watch for ScreenConnect.ClientSetup.msi downloads or installations on any endpoint (T1219 — Remote Access Software)

SafePay Ransomware C2:

Hunt Hypothesis: SafePay operators are using staged C2 infrastructure to prepare for ransomware deployment against government targets. Detection: - Block and alert on connections to: 89.117.23[.]185, 89.117.23[.]34, 37.60.242[.]86 - Monitor for any outbound traffic to ASN 40021 (Nubes LLC) and ASN 51167 (Contabo GmbH) — both are commonly used for disposable ransomware infrastructure - Correlate with data exfiltration indicators: large outbound transfers, connections to cloud storage services from servers (T1486, T1071.001)

ConnectWise ScreenConnect RAT Phishing:

Hunt Hypothesis: Finance-themed phishing emails are delivering ConnectWise ScreenConnect as a persistent RAT. Detection: - Email gateway: block emails with subject line Return Receipt - Governors Endodontics - Block SendGrid redirect URLs containing u113722640[.]ct[.]sendgrid at the proxy/email gateway - EDR: alert on ScreenConnect.ClientSetup.msi with MD5 ddaa8ed76059198b4fed3f0441b7fc48 - Network: block connections to bluespringsdentalkc[.]screenconnect[.]com and instance-pc58or-relay[.]screenconnect[.]com:443 - Audit for any unauthorized ScreenConnect installations across the environment (T1219)

Fake AI Crawler Credential Harvesting:

Hunt Hypothesis: Attackers impersonating AI crawlers are probing state web applications for exposed secrets and configuration files. Detection: - WAF/web server logs: alert on requests to /.env, /.aws/credentials, /.git/config, /app/.env, /api/.env, /backend/.env, /.env.local, /.env.production, /.env.bak - Correlate AI crawler user-agent strings (ClaudeBot, GPTBot, etc.) against legitimate IP ranges — legitimate Anthropic crawlers originate from 216.73.216.0/22 - Flag any crawler that does NOT request /robots.txt before scanning other paths - JA4H fingerprint (if your WAF supports it): ge11nn05enus_f3bb7a... is the confirmed impostor fingerprint vs. ge11nn080000_757a95... for real ClaudeBot

ThreatATT&CK
PaperCut Exploitation (CVE-2026-81578 + CVE-2026-82078)T1082 T1057 T1070.004 T1219 T1190 T1059.007
SafePay Ransomware C2T1486 T1071.001 T1566
ConnectWise ScreenConnect RAT PhishingT1219 T1566.002 T1204.001 T1105
Fake AI Crawler Credential HarvestingT1595.002 T1552.001 T1213
IOC Blocking Table:
89.117.23[.]18589.117.23[.]3437.60.242[.]86bluespringsdentalkc[.]screenconnect[.]cominstance-pc58or-relay[.]screenconnect[.]comu113722640[.]ct[.]sendgridUdydn.outmemory:...pwn in derby.log

Block the above at perimeter firewalls, proxies, and DNS. Hashes: ddaa8ed76059198b4fed3f0441b7fc48. Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1190
Attackers exploiting PaperCut servers to achieve SYSTEM-level code execution
Monitor PaperCut server processes for child process spawning: cmd.exe, powershell.exe, whoami.exe, tasklist.exe. Search Derby database logs (/data/internal/derby.log) for the string memory:...pwn — a confirmed exploitation artifact. Alert on the temporary file Udydn.out creation and deletion. Monitor for deletion of server.log. Watch for ScreenConnect.ClientSetup.msi downloads or installations on any endpoint.
HUNT 02 · T1486
SafePay operators staging C2 for ransomware deployment against government targets
Block and alert on connections to 89.117.23[.]185, 89.117.23[.]34, 37.60.242[.]86. Monitor for outbound traffic to ASN 40021 (Nubes LLC) and ASN 51167 (Contabo GmbH). Correlate with data exfiltration indicators: large outbound transfers, connections to cloud storage services from servers.
HUNT 03 · T1566.002
Finance-themed phishing delivering ConnectWise ScreenConnect as a persistent RAT
Email gateway: block emails with subject line "Return Receipt - Governors Endodontics." Block SendGrid redirect URLs containing u113722640[.]ct[.]sendgrid. EDR: alert on ScreenConnect.ClientSetup.msi with MD5 ddaa8ed76059198b4fed3f0441b7fc48. Network: block connections to bluespringsdentalkc[.]screenconnect[.]com and instance-pc58or-relay[.]screenconnect[.]com:443. Audit for any unauthorized ScreenConnect installations.
HUNT 04 · T1595.002
Attackers impersonating AI crawlers probing state web applications for exposed secrets
WAF/web server logs: alert on requests to /.env, /.aws/credentials, /.git/config, /app/.env, /api/.env, /backend/.env, /.env.local, /.env.production, /.env.bak. Correlate AI crawler user-agent strings against legitimate IP ranges — legitimate Anthropic crawlers originate from 216.73.216.0/22. Flag any crawler that does NOT request /robots.txt before scanning other paths.

Financial Services
State Treasury, Revenue, Benefits Systems
Primary threat
SafePay and Qilin ransomware targeting financial data; infostealer campaigns hijacking SaaS sessions.
Actions
  • Verify that all payment processing and benefits disbursement systems are segmented from general agency networks
  • Audit MFA enforcement on treasury management platforms and banking portals — session token theft bypasses password-only MFA
  • Review ConnectWise ScreenConnect and similar RMM tools for unauthorized installations on financial system endpoints
  • Ensure wire transfer and ACH processes have out-of-band verification that cannot be bypassed by a compromised email account
Energy
State Energy Regulatory Bodies, Utility Oversight
Primary threat
IRGC targeting U.S. water/energy infrastructure; internet-exposed OT/ICS systems under active scanning.
Actions
  • Coordinate with regulated utilities to verify no SCADA/PLC/HMI systems are directly internet-accessible
  • Request asset inventory from utilities under state jurisdiction — NCSC notes 88% of CPS systems fail to report accurate product codes
  • Ensure state energy emergency response plans account for a 4+ day outage scenario (per the UK power plant incident)
  • Verify that VPN access to OT networks uses hardware tokens, not software-based MFA susceptible to phishing
Healthcare
State Medicaid, Public Health, State Hospitals
Primary threat
PaperCut exploitation in hospital/clinic environments; ransomware targeting healthcare data.
Actions
  • PaperCut is widely deployed in healthcare settings — emergency patching or isolation is critical before September 14
  • Audit all PaperCut servers in state hospital and public health networks for exploitation artifacts (derby.log containing memory:...pwn)
  • Verify that EHR systems and Medicaid claims processing are on isolated network segments
  • Review incident response plans for ransomware scenarios that encrypt clinical systems — patient safety implications require pre-planned manual fallback procedures
Government
Executive Agencies, Legislature, Judiciary, Elections
Primary threats
Ransomware (Qilin, SafePay, Rhysida) explicitly targeting state/local government; nation-state espionage (China-nexus pre-positioning); election infrastructure integrity.
Actions
  • Conduct emergency PaperCut inventory across all agencies — CIO should direct agency IT leads to self-report installations within 48 hours
  • Review the Colorado voter data breach (130K+ confidential records exposed) as a peer-state lesson: audit voter database access controls and data exposure monitoring
  • Verify that CJIS-connected systems have current patches and that VPN access uses phishing-resistant MFA (FIDO2/hardware keys)
  • Ensure election infrastructure is air-gapped or on dedicated network segments with no shared services
Aviation / Logistics
State DOT, Airport Authorities, Port Authorities
Primary threat
OT/ICS exploitation of transportation control systems; supply chain compromise affecting logistics software.
Actions
  • Verify that traffic management systems, airport operational technology, and port control systems are not internet-exposed
  • Audit any Node.js-based logistics or scheduling applications for the compromised npm package @7nohe/openapi-react-query-codegen
  • Review WatchGuard firewall deployments at remote transportation facilities (weigh stations, maintenance depots, regional airports)
  • Ensure building automation systems (HVAC, access control) at transportation facilities are segmented from IT networks
No sector cards match the selected filters.

Emergency-patch all PaperCut NG/MF instances to the latest release before the CISA BOD 22-01 deadline of September 14. Agencies on version 23 or earlier — no patch exists — must isolate PaperCut servers from the network or place them behind an authenticated reverse proxy. Check derby.log for the string memory:...pwn as an exploitation indicator.
Incident Responder
Direct all agency IT leads to self-report PaperCut installations within 48 hours. You cannot patch what you cannot find.
CISO / Exec
Block SafePay ransomware C2 IPs at the perimeter firewall and add to SIEM watchlists: 89.117.23[.]185, 89.117.23[.]34, 37.60.242[.]86. Monitor for outbound connections to ASN 40021 (Nubes LLC) and ASN 51167 (Contabo GmbH).
SOC Analyst
Block ConnectWise ScreenConnect phishing IOCs at email gateway and EDR: MD5 ddaa8ed76059198b4fed3f0441b7fc48, domain bluespringsdentalkc[.]screenconnect[.]com, C2 instance-pc58or-relay[.]screenconnect[.]com:443, SendGrid redirect u113722640[.]ct[.]sendgrid.
SOC Analyst
No immediate actions for the selected roles.
Upgrade all WatchGuard Fireware OS appliances to version 2026.2.2, 12.12.2, or 12.5.20. Upgrade Dimension to 2.3.1. Every internet-facing WatchGuard appliance is exposed until patched.
Incident Responder
Audit all web-accessible directories on state-hosted applications for exposed .env, .aws/credentials, and .git/config files. Configure WAF rules to return 403 for requests to these paths. Validate that AI crawler user-agent allowlists verify source IP against published vendor ranges.
Incident Responder
Audit npm lockfiles and SBOMs for @7nohe/openapi-react-query-codegen. Malicious versions: 0.5.4, 0.5.5, 1.6.3, 1.6.4, 2.2.1, 2.2.2, 3.0.3, 3.0.4, and any 0.0.0-* prerelease. If found, treat the build system as compromised and rotate all GitHub, npm, AWS, Azure, and CI/CD credentials from a clean environment.
Incident Responder
Validate AI-assisted malware triage tools (if deployed) properly sandbox untrusted content and do not pass raw malware code comments to LLM safety filters — the "GuardBreaker" technique can cause analysis refusal or blind spots.
SOC Analyst
No 7-day actions for the selected roles.
Commission OT asset inventory verification across all agencies with SCADA/ICS/BAS systems. Cross-reference against NCSC advisory guidance: verify no PLCs, HMIs, or RTUs are directly internet-exposed.
ICS / OT
Conduct a peer-state election security review using the Colorado voter data breach as a case study. Audit voter database access controls and implement monitoring for bulk data access anomalies.
CISO / Exec
Review VPN authentication posture statewide. Mandate phishing-resistant MFA (FIDO2/hardware keys) for all VPN access to sensitive networks — particularly CJIS, election infrastructure, and OT/ICS segments.
IAM Analyst
Evaluate ransomware incident response readiness with a tabletop exercise specifically modeling a Qilin or SafePay scenario against a mid-size state agency.
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

This week's intelligence presents a familiar but dangerous pattern: commodity vulnerabilities in systems that every state agency uses — print management, firewalls, web applications — are being weaponized faster than most organizations can patch them. The PaperCut RCE chain went from vulnerability disclosure to public Metasploit module to confirmed exploitation to CISA KEV listing in a compressed timeline, and nearly half of all installations remain unpatched. Meanwhile, ransomware operators are not waiting. SafePay is staging infrastructure. Qilin has updated its target list to explicitly name state and local government. The WatchGuard VPN vulnerabilities provide exactly the kind of unauthenticated network access that ransomware operators use for initial entry. The convergence of these threats — actively exploited print servers, critically vulnerable VPN appliances, ransomware operators staging government-targeted infrastructure, and credential-harvesting campaigns scanning for cloud secrets — demands coordinated action across IT operations, security operations, and development teams simultaneously. The September 14 CISA deadline for PaperCut remediation is not aspirational — it is the outer bound. Given active exploitation and a public Metasploit module, the real deadline is this week.

1
Patch.
2
Inventory. Block.
3
Hunt. The intelligence is clear; the window for proactive defense is narrowing.
No items found.