TLP:GREEN  ·  States / Public Sector
When the Help Desk Calls Back:

Teams Vishing, 153 Million Stolen Licenses, and the Threats Bearing Down on State Government Networks

ELEVATED. Unchanged from the prior cycle — no single event warrants escalation to HIGH, but the cumulative weight of new campaigns, accelerating vulnerability exploitation, and a massive identity document breach sustains elevated risk across all state agency verticals. A sophisticated social engineering campaign is weaponizing Microsoft Teams to compromise Active Directory infrastructure, 153 million U.S. and Canadian driver's license images have surfaced on the dark web traced to a major identity verification vendor, and CISA has added nine vulnerabilities to its KEV catalog in just three days.

I am a
My sector

DevelopmentWhy It Matters for State Government
Spring Ring Campaign — Teams-based vishing with PowerShell RAT and NTLM relay escalation against domain controllersState agencies running Microsoft 365 with unrestricted external Teams access are directly exposed. Attackers impersonate IT help desks, escalate to voice calls, then deploy remote access tools and attempt PetitPotam-based NTLM relay attacks to compromise Active Directory.
153M Driver's License Breach (IDScan.net) — "Nexus" dark web service offering stolen identity documentsState DMVs issue the very documents now circulating on the dark web. Whether or not your state contracts with IDScan.net, your residents' licenses are almost certainly in this dataset. The FBI has opened an investigation.
6 Rockwell Automation ICS Advisories (ICSA-26-244-01 through -06)ControlLogix, CompactLogix, GuardLogix, RSLinx Classic, FactoryTalk, and Historian ME — the backbone of state water/wastewater and transportation SCADA — all received new vulnerability advisories from CISA on September 1.
9 CISA KEV Additions in 3 DaysActive exploitation is accelerating. Seven new CVEs added September 2, on top of two added August 31 (including CVE-2026-81578, the PaperCut MF/NG CVSS 9.8 flaw with a public Metasploit module). Federal remediation deadline for PaperCut: September 14.
CVE-2026-19949 — WordPress All-in-One WP Migration Plugin (CVSS 8.8)SQL injection to remote code execution affecting 5 million+ installations. Only 35% have patched, leaving ~3.2 million sites vulnerable — including state agency public websites using this popular backup/migration plugin.
UNC6924 — New ClickFix Actor Targeting State GovernmentA newly profiled threat group using blockchain-based C2 obfuscation ("etherhiding") and legitimate Node.js binaries to evade detection. Google Threat Intelligence confirms explicit targeting of federal and state government.
GoTo RAT + ConnectWise RAT Phishing CampaignActive phishing campaign using document-themed lures to deploy dual remote access tools via AWS S3-hosted VBS droppers. Directly relevant to agencies that allowlist AWS domains for GovCloud traffic.
Nation-State Actor Profile Updates (Kimsuky, TEMP.Isotope, APT28)Kimsuky and TEMP.Isotope/Dragonfly IOCs refreshed September 2 with active government-targeting indicators. APT28 HOOKEDGE backdoor activity confirmed against government targets. Multiple actors updated within a single 48-hour window signals a coordinated intelligence collection surge.
Ransomware Retooling — VICE SPIDER and PUNK SPIDERVICE SPIDER (Rhysida/Interlock) and PUNK SPIDER (Akira) profiles updated September 3 with new zero-day local privilege escalation staging and AI-generated attack scripts. Actor retooling at this scale typically precedes new campaign waves against high-value targets including state government.

DateEventRelevance to State Government
Jul 27, 2026 →FBI/EPA confirm AI-assisted attacks on water utility SCADA across 7+ U.S. states targeting Rockwell MicroLogix controllersDirect OT threat to state water/wastewater infrastructure
Aug 18, 2026CVE-2026-18963 published — Keycloak SSO authentication bypass (CVSS 9.1)Agencies using Keycloak for federated identity are exposed to unauthenticated account takeover
Aug 20, 2026UNC6924 threat group profiled — targets federal/state government with blockchain-based C2Novel actor with confirmed state government targeting
Aug 31, 2026CISA adds CVE-2026-81578 (PaperCut MF/NG, CVSS 9.8) to KEV catalog; Metasploit module publicAgencies running PaperCut face active exploitation; federal remediation deadline Sep 14
Sep 1, 2026CISA publishes 6 Rockwell Automation ICS advisories (ICSA-26-244-01 through -06)ControlLogix, CompactLogix, GuardLogix, RSLinx, FactoryTalk, Historian ME — core state OT platforms
Sep 2, 2026CISA adds 7 additional CVEs to KEV catalog (9 total in 3 days)Acceleration in active exploitation across multiple product categories
Sep 2, 2026Full proof-of-concept released for CVE-2026-18963 (Keycloak bypass)Lowers exploitation barrier from skilled attacker to script-level
Sep 2, 2026Kimsuky and TEMP.Isotope/Dragonfly IOCs refreshed with active government-targeting indicatorsActive espionage and energy/government targeting; updated blocklist required
Sep 3, 2026Unit 42 publishes Spring Ring campaign — Teams vishing + NTLM relay targeting 150+ employees across 10+ organizationsM365 Teams external access is the new open SMTP relay for social engineering
Sep 3, 2026IDScan.net breach disclosed — 153M+ driver's license images on dark web "Nexus" platformState-issued identity documents compromised at vendor level; FBI investigating
Sep 3, 2026CVE-2026-19949 disclosed — WordPress plugin SQLi→RCE (CVSS 8.8), 3.2M sites unpatchedState agency WordPress sites using All-in-One WP Migration are vulnerable
Sep 3, 2026Cofense publishes active threat reports on GoTo RAT + ConnectWise RAT phishing via AWS S3Dual-RMM deployment chain bypasses agencies that allowlist AWS domains
Sep 3, 2026VICE SPIDER and PUNK SPIDER profiles updated — zero-day LPE staging and AI-generated attack scriptsRansomware actor retooling precedes new campaign waves; state government remains a high-value target

The Spring Ring campaign, documented by Palo Alto Unit 42, represents a structural shift in social engineering tactics. Between January and April 2026, attackers used 26 distinct external identities on attacker-controlled .onmicrosoft[.]com tenants to impersonate corporate IT help desks via Microsoft Teams. After establishing trust through chat, they escalated to voice calls (vishing), convinced targets to grant remote access via Quick Assist or other RMM tools, deployed PowerShell-based remote access trojans, and then attempted PetitPotam-based NTLM relay attacks against domain controllers.

The campaign hit 150+ employees across 10+ organizations. The NTLM relay escalation path — from a single compromised workstation to domain controller compromise — is directly applicable to state Active Directory environments.

Key takeaway: Microsoft Teams with unrestricted external access is the 2026 equivalent of an open email relay. Policy changes — not just detection rules — are required.

T1566.003T1059.001T1219T1557.001T1046

A threat actor launched "Nexus," a dark web service offering 153 million+ U.S. and Canadian driver's license scans, 10 million+ ID cards, 3 million+ travel documents, and 580,000 medical cards. Investigative journalist Brian Krebs traced the data to IDScan.net, an identity verification firm serving clients across automotive, banking, gaming, education, government, hospitality, law enforcement, retail, and transportation.

The FBI has opened an investigation. Some exfiltrated licenses belong to FBI agents. The Nexus platform was taken down after public reporting, but the data is now in circulation.

Why this matters for every state government: State DMVs issue driver's licenses. Even if your state does not contract with IDScan.net directly, the 153 million figure almost certainly includes licenses issued by your state — because IDScan's clients (banks, car dealerships, casinos, hotels) scan licenses from every jurisdiction. This exposes a supply chain risk that doesn't appear in traditional software bills of materials: the vendors that verify identities.

CISA published six Rockwell Automation ICS advisories on September 1, covering the platforms that form the backbone of state operational technology:

AdvisoryProductImpact
ICSA-26-244-01RSLinx ClassicProgramming/configuration tool for Rockwell PLCs
ICSA-26-244-02Redundancy Module Configuration ToolHigh-availability configuration
ICSA-26-244-03Logix PlatformCore PLC firmware (ControlLogix, CompactLogix)
ICSA-26-244-04FactoryTalk Activation ManagerLicense/activation management
ICSA-26-244-05ControlLogix/CompactLogix/GuardLogixPrimary PLCs in water/wastewater and transportation
ICSA-26-244-06Historian MEOperational data historian

These advisories arrive in the context of ongoing AI-assisted attacks against water utility SCADA across at least seven U.S. states (confirmed by FBI and EPA since July 27), with IRGC-affiliated actors maintaining persistent targeting of U.S. water and wastewater infrastructure.

T0855T0831

Multiple nation-state actors continue to target state government networks:

ActorAffiliationPrimary Concern
APT28 / GRU Unit 26165RussiaHOOKEDGE backdoor — espionage, pre-positioning
MuddyWaterIran (MOIS)Supply chain compromise for state network access
IRGC-affiliated actorsIran (IRGC)Persistent water/wastewater OT targeting
Volt Typhoon / Salt TyphoonPRCNo new indicators — silence consistent with long-dwell pre-positioning
UNC6924Unattributed"Etherhiding" blockchain C2 — evades domain-based detection
KimsukyNorth Korea (RGB)Credential theft, espionage (IOCs refreshed Sep 2)
Famous ChollimaNorth KoreaForged identities for remote hiring infiltration
TEMP.Isotope / DragonflyRussiaEnergy sector and government espionage (updated Sep 2)
Stardust ChollimaNorth KoreaPoisoned 131 AI framework packages

Critical absence note: Volt Typhoon and Salt Typhoon have been quiet for multiple intelligence cycles. Given their documented strategy of long-dwell, living-off-the-land operations, silence does not indicate cessation.

No new ransomware incidents against state or local government were confirmed this cycle. However, the quiet is deceptive: VICE SPIDER (Rhysida/Interlock) — profile updated September 3 with zero-day local privilege escalation staging and AI-generated attack scripts; PUNK SPIDER (Akira) — profile updated September 3; Qilin — actor intelligence refreshed September 2; SafePay — remains active in tracking. Actor retooling — particularly VICE SPIDER's zero-day LPE staging — typically precedes new campaign waves.

Separately, today's intelligence collection surfaced multiple very-high-severity malicious domains hosted on legitimate cloud infrastructure — Azure Front Door, Azure Blob Storage, and AWS S3 buckets. State agencies that allowlist *.azurefd.net, *.web.core.windows.net, or *.s3.amazonaws.com for legitimate Microsoft 365 and AWS GovCloud traffic are creating detection blind spots that attackers are actively exploiting. Detection must shift from domain-based to behavior-based for cloud-hosted threats.

ScenarioProbabilityBasis
Additional CISA KEV additions as the September exploitation wave continues70%9 KEV additions in 3 days indicates an active exploitation surge; historical pattern shows clustering
Ransomware actors (VICE SPIDER/Rhysida, PUNK SPIDER/Akira) launch new campaigns against government targets60%Actor profiles updated Sep 3 with new tooling (zero-day LPE staging, AI-generated scripts); retooling precedes campaigns
Spring Ring or similar Teams vishing campaign directly targets a state government agency50%The TTP is proven, scalable, and requires minimal infrastructure; state agencies with open Teams external access are soft targets
CVE-2026-0257 (Palo Alto GlobalProtect) exploitation details emerge with China-nexus attribution40%Campaign tracked in commercial feeds targeting government, energy, manufacturing; details pending
Exploitation of CVE-2026-19949 (WordPress plugin) against state agency public websites40%3.2 million unpatched sites; state agencies commonly use WordPress; SQLi→RCE chain is straightforward
Secondary exploitation of IDScan breach data for targeted spearphishing against state employees35%153M license images provide high-quality identity data for social engineering; state employees are high-value targets
Volt Typhoon/Salt Typhoon activity surfaces in state government networks25%Low probability of detection per cycle, but cumulative risk grows; pre-positioned access may activate during geopolitical escalation

IOC Blocking Table — Network Indicators (Spring Ring Campaign):
193.32.248[.]251193.138.7[.]142185.65.134[.]209178.130.47[.]465.181.3[.]1062.56.172[.]214185.234.67[.]5345.8.157[.]18580.66.72[.]215136.0.20[.]6185.213.155[.]226185.155.99[.]161san-sid[.]com

12 Spring Ring C2 IPs + PowerShell RAT C2 domain. Block at perimeter firewalls, proxies, and DNS.

IOC Blocking Table — Network Indicators (GoTo RAT / ConnectWise RAT Campaign):
erqnkg584rn[.]s3[.]us-east-1[.]amazonaws[.]comejfqe38459trebj[.]s3[.]us-east-1[.]amazonaws[.]comfjvjs34rk[.]s3[.]us-east-1[.]amazonaws[.]comgsre56e7dty[.]s3[.]us-east-1[.]amazonaws[.]comda[.]haybachdban[.]orgrelay[.]haybachdban[.]orgdevices-iot[.]console[.]gotoresolve[.]comdumpster[.]console[.]gotoresolve[.]com

S3-hosted VBS dropper/payload hosting, ConnectWise ScreenConnect C2 (relay.haybachdban.org uses port 8041), and GoTo RAT C2/API endpoints.

IOC Blocking Table — Cloud Infrastructure (Malicious Domains):
charcharnahifgallanchar-fggderfgc0ddb7fn[.]z03[.]azurefd[.]nettheshawshankredwwww[.]z13[.]web[.]core[.]windows[.]netxoot[.]iozbxcgtqt[.]comgehie246[.]com

Malware hosting on Azure Front Door and Azure Blob Storage (do not blanket-block *.azurefd.net or *.web.core.windows.net — implement behavioral/entropy-based detection instead per the 7-day recommendation); bot C2 and malware distribution domains.

IOC Blocking Table — Typosquatting / Impersonation (Chinese-Language Campaigns):
app-microsoft-edge[.]com[.]cnbaidu-pan[.]com[.]cncalibre-ebook[.]com[.]cncn-drawio[.]com[.]cngw-sogou[.]com[.]cnkaspersky-lab[.]hl[.]cnmindmoster[.]com[.]cnocam-pc[.]com[.]cnpc-razerzone[.]com[.]cnsejda[.]hl[.]cnsteelseries-cn[.]com[.]cntranslate-youdao[.]hl[.]cnzh-diskgenius[.]com[.]cn

Typosquatted domains impersonating legitimate software vendors (Microsoft Edge, Baidu, Calibre, Draw.io, Sogou, Kaspersky, MindMaster, oCam, Razer, Sejda PDF, SteelSeries, Youdao, DiskGenius).

File hashes — GoTo RAT / ConnectWise RAT Campaign (MD5): db70d4853c4281e403ae149e33a6a283 (Klean Corp phishing .docx), 1f39eb1cb0bae66197a586176b8d8114 (Klean Corp phishing .pdf), a4c7abbe460af3fe33b26bd4abf7c450 (Adobe_Reader_Installer_File.vbs dropper), a7f62ab54b9807deffb0739087e022a2 (LogMeInResolve_Unattended.msi — GoTo RAT), 9bbab8e6740d6e551cb68d011e9216c6 (ScreenConnect.ClientSetup.msi — ConnectWise RAT). File hashes — Nation-State / APT (SHA-256): b4bd3c50a5d7a7102a7e723f4b742f556a1ab93e3f5d4a36567a651109c4dfd9 (Kimsuky, government targeting, confidence 80), 5dfd79503b19b67052ec060d74e1f2a9a5ee34de74d578c5b4499468bad8f1cb (APT-associated, high confidence), 8075aac45cdbf0aae6572d8039978c587715d33d6b330539092189c91804f031 (APT-associated, high confidence). Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.

Hunting Hypotheses:
HUNT 01 · T1566.003
Hunt Hypothesis 1: Teams-Based Social Engineering (Spring Ring)
Monitor: Microsoft Teams audit logs for external-to-internal chat creation from .onmicrosoft[.]com tenants not in your approved federation list, especially when followed by voice/video calls within 5 minutes Detect: T1566.003 — Alert on Quick Assist (quickassist.exe), AnyDesk, or other RMM tool execution within 15 minutes of a Teams voice call Detect: T1059.001 — PowerShell execution spawned by RMM processes; look for encoded commands, download cradles, or connections to san-sid[.]com Detect: T1557.001 — PetitPotam/NTLM relay indicators: anomalous EFS RPC calls to domain controllers, unexpected NTLM authentication from workstations to ADCS servers Block: The 12 Spring Ring C2 IPs listed in the IOC table below
HUNT 02 · T1059.005
Hunt Hypothesis 2: Dual-RMM Phishing (GoTo RAT + ConnectWise)
Monitor: T1059.005 — cscript.exe or wscript.exe executing .vbs files downloaded from S3 buckets Detect: T1219 — Simultaneous presence of GoTo Resolve (gotoresolve.com connections) AND ConnectWise ScreenConnect on the same endpoint is a strong indicator of compromise Detect: T1105 — msiexec.exe fetching MSI installers from non-standard domains (e.g., haybachdban[.]org, randomized S3 bucket names) Block: Cofense ATR IOCs — domains and hashes listed in the IOC table below
HUNT 03 · T1204.002
Hunt Hypothesis 3: ClickFix/UNC6924 Blockchain C2
Monitor: Outbound connections to Polygon blockchain RPC endpoints from non-development workstations — this is the "etherhiding" technique where C2 addresses are resolved via smart contract queries Detect: T1204.002 — Execution of Node.js (node.exe) or Update.js from user-writable directories (AppData, Temp, Downloads) — UNC6924's "Bring Your Own Interpreter" technique Detect: Fake browser update pages ("ClickFix" lures) — monitor for browser processes spawning PowerShell or cmd.exe with download commands
HUNT 04 · T1102
Hunt Hypothesis 4: Cloud Infrastructure Abuse
Monitor: T1102 — DNS queries and HTTPS connections to Azure Front Door (*.azurefd.net) and Azure Blob Storage (*.web.core.windows.net) subdomains with high-entropy or randomized names Detect: File downloads from S3 buckets with randomized names (e.g., erqnkg584rn, ejfqe38459trebj, gsre56e7dty) — legitimate S3 usage typically has human-readable bucket names Action: Move from domain allowlisting to behavioral analysis for cloud-hosted content; implement URL filtering that inspects the full path, not just the domain
HUNT 05 · T1190
Hunt Hypothesis 5: WordPress Plugin Exploitation
Monitor: T1190 — Web application firewall logs for SQL injection attempts against WordPress sites, particularly targeting /wp-content/plugins/all-in-one-wp-migration/ paths Detect: T1505.003 — New files appearing in WordPress mu-plugins directory (must-use plugins) — this is the RCE delivery mechanism for CVE-2026-19949 Action: Inventory all agency WordPress installations and plugin versions immediately

Financial Services
State Treasury, Revenue, Retirement Systems
Primary threat
Spring Ring Teams vishing campaign — state treasury and revenue agencies handle high-value financial transactions and are prime targets for social engineering that escalates to wire fraud or account manipulation.
Secondary threat
State retirement systems and revenue agencies using identity verification for account access or tax filing may have resident data in the IDScan-compromised dataset.
Actions
  • Restrict Teams external access to pre-approved domains
  • Implement out-of-band verification for any IT support request received via Teams or phone
  • Review identity verification vendor contracts for breach notification clauses
Energy
State Utility Commissions, State-Operated Power/Water
Primary threat
Rockwell Automation ICS vulnerabilities (ICSA-26-244-01 through -06) and ongoing IRGC-affiliated targeting of water/wastewater infrastructure. TEMP.Isotope/Dragonfly (Russia) continues targeting energy and government utilities.
Actions
  • Immediately audit Rockwell controller inventory against the six CISA advisories
  • Prioritize ControlLogix/CompactLogix/GuardLogix (ICSA-26-244-05) and Logix Platform (ICSA-26-244-03) patches
  • Verify OT network segmentation — no direct internet exposure for PLCs
  • Implement monitoring for anomalous Ethernet/IP (CIP) traffic on OT segments
Healthcare
State Medicaid, Public Health, State Hospitals
Primary threats
Ransomware (Rhysida, Akira, Qilin) — healthcare remains the highest-value ransomware target. The IDScan breach also exposed 580,000 medical cards.
Actions
  • Ensure offline backup integrity for Medicaid enrollment systems and electronic health records
  • Validate that ransomware playbooks include clinical system isolation procedures
  • Audit identity verification vendors used for Medicaid enrollment or provider credentialing
Government
All Executive Branch Agencies
Primary threats
Multi-vector — Spring Ring (credential theft via Teams), UNC6924 (ClickFix with blockchain C2), Kimsuky (espionage), Volt Typhoon (pre-positioning). The IDScan breach affects every agency that issues or verifies identity documents.
Secondary threat
CVE-2026-18963 (Keycloak) requires immediate patching where used for SSO; CVE-2026-81578 (PaperCut) federal remediation deadline is September 14.
Actions
  • Implement the full Spring Ring IOC blocklist
  • Restrict Teams external access
  • Audit Keycloak and PaperCut deployments
  • Begin NTLM relay hardening on domain controllers (EPA, SMB signing)
Aviation / Logistics
State DOT, Airports, Port Authorities
Primary threats
Rockwell Automation ICS vulnerabilities affecting transportation SCADA (traffic management, tunnel ventilation, bridge controls). Supply chain compromise via managed service providers.
Actions
  • Audit Rockwell controller deployments in transportation infrastructure
  • Review MSP access controls — ensure MFA on all remote management sessions and restrict MSP network access to specific segments
  • Monitor for anomalous remote access tool installations (GoTo, ConnectWise, AnyDesk) on transportation OT-adjacent systems
No sector cards match the selected filters.

Block the 12 Spring Ring C2 IPs and domain san-sid[.]com at perimeter firewalls and add to SIEM watchlist. Deploy detection for PowerShell execution spawned by RMM tools.
SOC Analyst
Block Cofense ATR phishing IOCshaybachdban[.]org and associated S3 bucket domains. Add the 5 MD5 hashes to EDR blocklist. Alert on cscript.exe/wscript.exe executing VBS files downloaded from S3.
SOC Analyst
Restrict Microsoft Teams external access to approved federation domains only. If business requires open external chat, enable alerting on external-to-internal chat creation followed by voice calls within 5 minutes.
IAM Analyst
Verify all 6 Rockwell Automation ICS advisories (ICSA-26-244-01 through -06) against state OT asset inventory. Prioritize ControlLogix/CompactLogix/GuardLogix and Logix Platform patches.
ICS / OT
Add Kimsuky and all APT-associated hashes from the IOC table to EDR watchlists.
SOC Analyst
No immediate actions for the selected roles.
Audit all agency WordPress installations for the All-in-One WP Migration and Backup plugin. Update to version 7.110+ immediately — any instance at ≤7.109 is vulnerable to CVE-2026-19949 (SQLi→RCE).
Incident Responder
Create detection rules for Azure Front Door and Azure Blob Storage domains with high-entropy or randomized subdomain patterns. Current allowlisting of *.azurefd.net and *.web.core.windows.net creates a detection blind spot.
SOC Analyst
Determine whether any state agency uses IDScan.net or similar identity verification vendors. Regardless of vendor relationship, assume state-issued driver's licenses are in the 153M compromised dataset and prepare resident notification contingency.
CISO / Exec
Confirm CVE-2026-81578 (PaperCut) and CVE-2026-18963 (Keycloak) are patched across all agencies ahead of the September 14 federal remediation deadline.
Incident Responder
Develop detection for UNC6924's "etherhiding" technique — monitor for outbound connections to Polygon blockchain RPC endpoints from non-development systems.
SOC Analyst
No 7-day actions for the selected roles.
Implement NTLM relay protections on all domain controllers: enable Extended Protection for Authentication (EPA) on AD CS, disable NTLM where feasible, enforce SMB signing.
IAM Analyst
Commission a review of all third-party identity verification vendors used across state agencies (DMV, HR, licensing boards, law enforcement). Establish breach notification requirements and data retention limits in vendor contracts.
CISO / Exec
Develop a resident notification contingency plan for the IDScan breach.
CISO / Exec
Resolve the OSINT intelligence collection gap — the state's threat intelligence capability has operated without open-source intelligence for 199 consecutive cycles. Approve emergency procurement of an alternative OSINT source.
CISO / Exec
Conduct a tabletop exercise simulating a Teams-based vishing attack that escalates to NTLM relay and domain controller compromise.
CISO / ExecIncident Responder
No 30-day actions for the selected roles.
The Bottom Line

Three structural shifts define this week's threat landscape for state government. Microsoft Teams is the new phishing vector — the Spring Ring campaign proves collaboration platforms have replaced email as the primary social engineering channel for sophisticated attackers. Restricting Teams external access is not a convenience decision — it is a security control equivalent to email gateway filtering. Identity verification is a supply chain you're not tracking — the IDScan breach exposes a vendor dependency that doesn't appear in any software inventory or SBOM. Your DMV, HR department, licensing boards, and law enforcement agencies all feed identity documents into third-party verification platforms. Cloud allowlists are becoming attack surfaces — attackers are hosting malware on the same domains your agencies allowlist for Microsoft 365 and AWS GovCloud. Domain-based trust is no longer sufficient.

1
Restricting Teams external access is a security control equivalent to email gateway filtering.
2
You need to know which identity verification vendors your agencies use, and you need breach notification clauses in those contracts.
3
Your SOC must shift to behavioral detection for cloud-hosted content. The threat level remains ELEVATED. The window to act is now.
No items found.