| Development | Why It Matters for State Government |
|---|---|
| Spring Ring Campaign — Teams-based vishing with PowerShell RAT and NTLM relay escalation against domain controllers | State agencies running Microsoft 365 with unrestricted external Teams access are directly exposed. Attackers impersonate IT help desks, escalate to voice calls, then deploy remote access tools and attempt PetitPotam-based NTLM relay attacks to compromise Active Directory. |
| 153M Driver's License Breach (IDScan.net) — "Nexus" dark web service offering stolen identity documents | State DMVs issue the very documents now circulating on the dark web. Whether or not your state contracts with IDScan.net, your residents' licenses are almost certainly in this dataset. The FBI has opened an investigation. |
| 6 Rockwell Automation ICS Advisories (ICSA-26-244-01 through -06) | ControlLogix, CompactLogix, GuardLogix, RSLinx Classic, FactoryTalk, and Historian ME — the backbone of state water/wastewater and transportation SCADA — all received new vulnerability advisories from CISA on September 1. |
| 9 CISA KEV Additions in 3 Days | Active exploitation is accelerating. Seven new CVEs added September 2, on top of two added August 31 (including CVE-2026-81578, the PaperCut MF/NG CVSS 9.8 flaw with a public Metasploit module). Federal remediation deadline for PaperCut: September 14. |
| CVE-2026-19949 — WordPress All-in-One WP Migration Plugin (CVSS 8.8) | SQL injection to remote code execution affecting 5 million+ installations. Only 35% have patched, leaving ~3.2 million sites vulnerable — including state agency public websites using this popular backup/migration plugin. |
| UNC6924 — New ClickFix Actor Targeting State Government | A newly profiled threat group using blockchain-based C2 obfuscation ("etherhiding") and legitimate Node.js binaries to evade detection. Google Threat Intelligence confirms explicit targeting of federal and state government. |
| GoTo RAT + ConnectWise RAT Phishing Campaign | Active phishing campaign using document-themed lures to deploy dual remote access tools via AWS S3-hosted VBS droppers. Directly relevant to agencies that allowlist AWS domains for GovCloud traffic. |
| Nation-State Actor Profile Updates (Kimsuky, TEMP.Isotope, APT28) | Kimsuky and TEMP.Isotope/Dragonfly IOCs refreshed September 2 with active government-targeting indicators. APT28 HOOKEDGE backdoor activity confirmed against government targets. Multiple actors updated within a single 48-hour window signals a coordinated intelligence collection surge. |
| Ransomware Retooling — VICE SPIDER and PUNK SPIDER | VICE SPIDER (Rhysida/Interlock) and PUNK SPIDER (Akira) profiles updated September 3 with new zero-day local privilege escalation staging and AI-generated attack scripts. Actor retooling at this scale typically precedes new campaign waves against high-value targets including state government. |
| Date | Event | Relevance to State Government |
|---|---|---|
| Jul 27, 2026 → | FBI/EPA confirm AI-assisted attacks on water utility SCADA across 7+ U.S. states targeting Rockwell MicroLogix controllers | Direct OT threat to state water/wastewater infrastructure |
| Aug 18, 2026 | CVE-2026-18963 published — Keycloak SSO authentication bypass (CVSS 9.1) | Agencies using Keycloak for federated identity are exposed to unauthenticated account takeover |
| Aug 20, 2026 | UNC6924 threat group profiled — targets federal/state government with blockchain-based C2 | Novel actor with confirmed state government targeting |
| Aug 31, 2026 | CISA adds CVE-2026-81578 (PaperCut MF/NG, CVSS 9.8) to KEV catalog; Metasploit module public | Agencies running PaperCut face active exploitation; federal remediation deadline Sep 14 |
| Sep 1, 2026 | CISA publishes 6 Rockwell Automation ICS advisories (ICSA-26-244-01 through -06) | ControlLogix, CompactLogix, GuardLogix, RSLinx, FactoryTalk, Historian ME — core state OT platforms |
| Sep 2, 2026 | CISA adds 7 additional CVEs to KEV catalog (9 total in 3 days) | Acceleration in active exploitation across multiple product categories |
| Sep 2, 2026 | Full proof-of-concept released for CVE-2026-18963 (Keycloak bypass) | Lowers exploitation barrier from skilled attacker to script-level |
| Sep 2, 2026 | Kimsuky and TEMP.Isotope/Dragonfly IOCs refreshed with active government-targeting indicators | Active espionage and energy/government targeting; updated blocklist required |
| Sep 3, 2026 | Unit 42 publishes Spring Ring campaign — Teams vishing + NTLM relay targeting 150+ employees across 10+ organizations | M365 Teams external access is the new open SMTP relay for social engineering |
| Sep 3, 2026 | IDScan.net breach disclosed — 153M+ driver's license images on dark web "Nexus" platform | State-issued identity documents compromised at vendor level; FBI investigating |
| Sep 3, 2026 | CVE-2026-19949 disclosed — WordPress plugin SQLi→RCE (CVSS 8.8), 3.2M sites unpatched | State agency WordPress sites using All-in-One WP Migration are vulnerable |
| Sep 3, 2026 | Cofense publishes active threat reports on GoTo RAT + ConnectWise RAT phishing via AWS S3 | Dual-RMM deployment chain bypasses agencies that allowlist AWS domains |
| Sep 3, 2026 | VICE SPIDER and PUNK SPIDER profiles updated — zero-day LPE staging and AI-generated attack scripts | Ransomware actor retooling precedes new campaign waves; state government remains a high-value target |
The Spring Ring campaign, documented by Palo Alto Unit 42, represents a structural shift in social engineering tactics. Between January and April 2026, attackers used 26 distinct external identities on attacker-controlled .onmicrosoft[.]com tenants to impersonate corporate IT help desks via Microsoft Teams. After establishing trust through chat, they escalated to voice calls (vishing), convinced targets to grant remote access via Quick Assist or other RMM tools, deployed PowerShell-based remote access trojans, and then attempted PetitPotam-based NTLM relay attacks against domain controllers.
The campaign hit 150+ employees across 10+ organizations. The NTLM relay escalation path — from a single compromised workstation to domain controller compromise — is directly applicable to state Active Directory environments.
Key takeaway: Microsoft Teams with unrestricted external access is the 2026 equivalent of an open email relay. Policy changes — not just detection rules — are required.
A threat actor launched "Nexus," a dark web service offering 153 million+ U.S. and Canadian driver's license scans, 10 million+ ID cards, 3 million+ travel documents, and 580,000 medical cards. Investigative journalist Brian Krebs traced the data to IDScan.net, an identity verification firm serving clients across automotive, banking, gaming, education, government, hospitality, law enforcement, retail, and transportation.
The FBI has opened an investigation. Some exfiltrated licenses belong to FBI agents. The Nexus platform was taken down after public reporting, but the data is now in circulation.
Why this matters for every state government: State DMVs issue driver's licenses. Even if your state does not contract with IDScan.net directly, the 153 million figure almost certainly includes licenses issued by your state — because IDScan's clients (banks, car dealerships, casinos, hotels) scan licenses from every jurisdiction. This exposes a supply chain risk that doesn't appear in traditional software bills of materials: the vendors that verify identities.
CISA published six Rockwell Automation ICS advisories on September 1, covering the platforms that form the backbone of state operational technology:
| Advisory | Product | Impact |
|---|---|---|
| ICSA-26-244-01 | RSLinx Classic | Programming/configuration tool for Rockwell PLCs |
| ICSA-26-244-02 | Redundancy Module Configuration Tool | High-availability configuration |
| ICSA-26-244-03 | Logix Platform | Core PLC firmware (ControlLogix, CompactLogix) |
| ICSA-26-244-04 | FactoryTalk Activation Manager | License/activation management |
| ICSA-26-244-05 | ControlLogix/CompactLogix/GuardLogix | Primary PLCs in water/wastewater and transportation |
| ICSA-26-244-06 | Historian ME | Operational data historian |
These advisories arrive in the context of ongoing AI-assisted attacks against water utility SCADA across at least seven U.S. states (confirmed by FBI and EPA since July 27), with IRGC-affiliated actors maintaining persistent targeting of U.S. water and wastewater infrastructure.
Multiple nation-state actors continue to target state government networks:
| Actor | Affiliation | Primary Concern |
|---|---|---|
| APT28 / GRU Unit 26165 | Russia | HOOKEDGE backdoor — espionage, pre-positioning |
| MuddyWater | Iran (MOIS) | Supply chain compromise for state network access |
| IRGC-affiliated actors | Iran (IRGC) | Persistent water/wastewater OT targeting |
| Volt Typhoon / Salt Typhoon | PRC | No new indicators — silence consistent with long-dwell pre-positioning |
| UNC6924 | Unattributed | "Etherhiding" blockchain C2 — evades domain-based detection |
| Kimsuky | North Korea (RGB) | Credential theft, espionage (IOCs refreshed Sep 2) |
| Famous Chollima | North Korea | Forged identities for remote hiring infiltration |
| TEMP.Isotope / Dragonfly | Russia | Energy sector and government espionage (updated Sep 2) |
| Stardust Chollima | North Korea | Poisoned 131 AI framework packages |
Critical absence note: Volt Typhoon and Salt Typhoon have been quiet for multiple intelligence cycles. Given their documented strategy of long-dwell, living-off-the-land operations, silence does not indicate cessation.
No new ransomware incidents against state or local government were confirmed this cycle. However, the quiet is deceptive: VICE SPIDER (Rhysida/Interlock) — profile updated September 3 with zero-day local privilege escalation staging and AI-generated attack scripts; PUNK SPIDER (Akira) — profile updated September 3; Qilin — actor intelligence refreshed September 2; SafePay — remains active in tracking. Actor retooling — particularly VICE SPIDER's zero-day LPE staging — typically precedes new campaign waves.
Separately, today's intelligence collection surfaced multiple very-high-severity malicious domains hosted on legitimate cloud infrastructure — Azure Front Door, Azure Blob Storage, and AWS S3 buckets. State agencies that allowlist *.azurefd.net, *.web.core.windows.net, or *.s3.amazonaws.com for legitimate Microsoft 365 and AWS GovCloud traffic are creating detection blind spots that attackers are actively exploiting. Detection must shift from domain-based to behavior-based for cloud-hosted threats.
| Scenario | Probability | Basis |
|---|---|---|
| Additional CISA KEV additions as the September exploitation wave continues | 70% | 9 KEV additions in 3 days indicates an active exploitation surge; historical pattern shows clustering |
| Ransomware actors (VICE SPIDER/Rhysida, PUNK SPIDER/Akira) launch new campaigns against government targets | 60% | Actor profiles updated Sep 3 with new tooling (zero-day LPE staging, AI-generated scripts); retooling precedes campaigns |
| Spring Ring or similar Teams vishing campaign directly targets a state government agency | 50% | The TTP is proven, scalable, and requires minimal infrastructure; state agencies with open Teams external access are soft targets |
| CVE-2026-0257 (Palo Alto GlobalProtect) exploitation details emerge with China-nexus attribution | 40% | Campaign tracked in commercial feeds targeting government, energy, manufacturing; details pending |
| Exploitation of CVE-2026-19949 (WordPress plugin) against state agency public websites | 40% | 3.2 million unpatched sites; state agencies commonly use WordPress; SQLi→RCE chain is straightforward |
| Secondary exploitation of IDScan breach data for targeted spearphishing against state employees | 35% | 153M license images provide high-quality identity data for social engineering; state employees are high-value targets |
| Volt Typhoon/Salt Typhoon activity surfaces in state government networks | 25% | Low probability of detection per cycle, but cumulative risk grows; pre-positioned access may activate during geopolitical escalation |
12 Spring Ring C2 IPs + PowerShell RAT C2 domain. Block at perimeter firewalls, proxies, and DNS.
S3-hosted VBS dropper/payload hosting, ConnectWise ScreenConnect C2 (relay.haybachdban.org uses port 8041), and GoTo RAT C2/API endpoints.
Malware hosting on Azure Front Door and Azure Blob Storage (do not blanket-block *.azurefd.net or *.web.core.windows.net — implement behavioral/entropy-based detection instead per the 7-day recommendation); bot C2 and malware distribution domains.
Typosquatted domains impersonating legitimate software vendors (Microsoft Edge, Baidu, Calibre, Draw.io, Sogou, Kaspersky, MindMaster, oCam, Razer, Sejda PDF, SteelSeries, Youdao, DiskGenius).
File hashes — GoTo RAT / ConnectWise RAT Campaign (MD5): db70d4853c4281e403ae149e33a6a283 (Klean Corp phishing .docx), 1f39eb1cb0bae66197a586176b8d8114 (Klean Corp phishing .pdf), a4c7abbe460af3fe33b26bd4abf7c450 (Adobe_Reader_Installer_File.vbs dropper), a7f62ab54b9807deffb0739087e022a2 (LogMeInResolve_Unattended.msi — GoTo RAT), 9bbab8e6740d6e551cb68d011e9216c6 (ScreenConnect.ClientSetup.msi — ConnectWise RAT). File hashes — Nation-State / APT (SHA-256): b4bd3c50a5d7a7102a7e723f4b742f556a1ab93e3f5d4a36567a651109c4dfd9 (Kimsuky, government targeting, confidence 80), 5dfd79503b19b67052ec060d74e1f2a9a5ee34de74d578c5b4499468bad8f1cb (APT-associated, high confidence), 8075aac45cdbf0aae6572d8039978c587715d33d6b330539092189c91804f031 (APT-associated, high confidence). Additional IOCs available via Anomali ThreatStream Next-Gen and partner feeds.
.onmicrosoft[.]com tenants not in your approved federation list, especially when followed by voice/video calls within 5 minutes Detect: T1566.003 — Alert on Quick Assist (quickassist.exe), AnyDesk, or other RMM tool execution within 15 minutes of a Teams voice call Detect: T1059.001 — PowerShell execution spawned by RMM processes; look for encoded commands, download cradles, or connections to san-sid[.]com Detect: T1557.001 — PetitPotam/NTLM relay indicators: anomalous EFS RPC calls to domain controllers, unexpected NTLM authentication from workstations to ADCS servers Block: The 12 Spring Ring C2 IPs listed in the IOC table belowcscript.exe or wscript.exe executing .vbs files downloaded from S3 buckets Detect: T1219 — Simultaneous presence of GoTo Resolve (gotoresolve.com connections) AND ConnectWise ScreenConnect on the same endpoint is a strong indicator of compromise Detect: T1105 — msiexec.exe fetching MSI installers from non-standard domains (e.g., haybachdban[.]org, randomized S3 bucket names) Block: Cofense ATR IOCs — domains and hashes listed in the IOC table belowNode.js (node.exe) or Update.js from user-writable directories (AppData, Temp, Downloads) — UNC6924's "Bring Your Own Interpreter" technique Detect: Fake browser update pages ("ClickFix" lures) — monitor for browser processes spawning PowerShell or cmd.exe with download commands*.azurefd.net) and Azure Blob Storage (*.web.core.windows.net) subdomains with high-entropy or randomized names Detect: File downloads from S3 buckets with randomized names (e.g., erqnkg584rn, ejfqe38459trebj, gsre56e7dty) — legitimate S3 usage typically has human-readable bucket names Action: Move from domain allowlisting to behavioral analysis for cloud-hosted content; implement URL filtering that inspects the full path, not just the domain/wp-content/plugins/all-in-one-wp-migration/ paths Detect: T1505.003 — New files appearing in WordPress mu-plugins directory (must-use plugins) — this is the RCE delivery mechanism for CVE-2026-19949 Action: Inventory all agency WordPress installations and plugin versions immediately- Restrict Teams external access to pre-approved domains
- Implement out-of-band verification for any IT support request received via Teams or phone
- Review identity verification vendor contracts for breach notification clauses
- Immediately audit Rockwell controller inventory against the six CISA advisories
- Prioritize ControlLogix/CompactLogix/GuardLogix (ICSA-26-244-05) and Logix Platform (ICSA-26-244-03) patches
- Verify OT network segmentation — no direct internet exposure for PLCs
- Implement monitoring for anomalous Ethernet/IP (CIP) traffic on OT segments
- Ensure offline backup integrity for Medicaid enrollment systems and electronic health records
- Validate that ransomware playbooks include clinical system isolation procedures
- Audit identity verification vendors used for Medicaid enrollment or provider credentialing
- Implement the full Spring Ring IOC blocklist
- Restrict Teams external access
- Audit Keycloak and PaperCut deployments
- Begin NTLM relay hardening on domain controllers (EPA, SMB signing)
- Audit Rockwell controller deployments in transportation infrastructure
- Review MSP access controls — ensure MFA on all remote management sessions and restrict MSP network access to specific segments
- Monitor for anomalous remote access tool installations (GoTo, ConnectWise, AnyDesk) on transportation OT-adjacent systems
san-sid[.]com at perimeter firewalls and add to SIEM watchlist. Deploy detection for PowerShell execution spawned by RMM tools.haybachdban[.]org and associated S3 bucket domains. Add the 5 MD5 hashes to EDR blocklist. Alert on cscript.exe/wscript.exe executing VBS files downloaded from S3.*.azurefd.net and *.web.core.windows.net creates a detection blind spot.Three structural shifts define this week's threat landscape for state government. Microsoft Teams is the new phishing vector — the Spring Ring campaign proves collaboration platforms have replaced email as the primary social engineering channel for sophisticated attackers. Restricting Teams external access is not a convenience decision — it is a security control equivalent to email gateway filtering. Identity verification is a supply chain you're not tracking — the IDScan breach exposes a vendor dependency that doesn't appear in any software inventory or SBOM. Your DMV, HR department, licensing boards, and law enforcement agencies all feed identity documents into third-party verification platforms. Cloud allowlists are becoming attack surfaces — attackers are hosting malware on the same domains your agencies allowlist for Microsoft 365 and AWS GovCloud. Domain-based trust is no longer sufficient.