TLP:GREEN  ·  States / Public Sector
When the Patch Deadline Is Today:

Four Critical Vulnerabilities, a Novel Fraud Technique, and the Ransomware Surge Bearing Down on State Government

ELEVATED. CISA added four vulnerabilities to its KEV catalog affecting products common across state agencies - one remediation deadline expires today. A breach at fintech firm Revolut exposed a dangerous new pattern: attackers impersonating government agencies to extract bulk citizen data. The ransomware ecosystem has grown to 146 active groups, with Qilin explicitly targeting U.S. critical infrastructure.

I am a
My sector

DevelopmentSignificance
CVE-2025-25249 (FortiOS, CVSS 8.1) added to KEV Sep 9 - linked to PivotC2 RAT.FortiGate is primary perimeter defense for most state networks
CVE-2026-67277 (MikroTik, CVSS 8.2) added to KEV Sep 10 - unauth memory leak/DoS.MikroTik deployed at branch/remote state offices
CVE-2026-85706 (GitLab CVSS 10.0) added to KEV Sep 11 with a 3-day BOD 26-04 deadline expiring today.State agencies running self-managed GitLab
Revolut breach via government-domain impersonation disclosed Sep 12 - attacker used a legitimate government domain to extract citizen data.State domains could be weaponized, or receive spoofed requests
China-nexus profiles refreshed Sep 13: UNC6201, APT41, TEMP.Avengers - U.S. gov targeting.Quiet does not mean safe for long-dwell actors
Qilin confirmed #1 ransomware group for the third month; Interlock adopts ClickFix.Government/critical infra are explicit Qilin targets

DateEventSeverityState Gov Relevance
Sep 9CVE-2025-25249 (FortiOS RCE) added to KEV; PivotC2 linkage publishedHIGHFortiGate is primary perimeter defense for most state networks
Sep 10CVE-2026-67277 (MikroTik) added to KEVHIGHMikroTik routers deployed at branch/remote state offices
Sep 11CVE-2026-85706 (GitLab CVSS 10.0) added to KEV, 3-day BOD 26-04 deadlineCRITICALState agencies running self-managed GitLab
Sep 12ZachXBT discloses Revolut breach via government domain impersonationMODERATEState domains could be weaponized or spoofed
Sep 13China-nexus profiles refreshed: UNC6201, APT41, TEMP.AvengersELEVATEDDocumented U.S. gov targeting
Sep 14Rapid7 confirms active exploitation; BOD 26-04 deadline expiresCRITICALDeadline is today - triage required

An improper path confinement flaw in GitLab's commits API allows unauthenticated file reads - credentials, tokens, CI/CD secrets. Exploitation confirmed. Same patch addresses CVE-2026-87719 (CVSS 9.9, Duo Chat/GraphQL theft).

Different: BOD 26-04 requires forensic triage, not just patching.

T1190T1552.001T1213

JFrog (8.1): token validation flaw lets an authenticated user escalate to admin, then plant backdoored packages poisoning builds. Chained exploitation confirmed. Fixed in 7.133.11+.

FortiOS (8.1): heap overflow enables RCE via crafted packets; linked to PivotC2. Siemens confirms water/energy/transportation utilities in scope.

T1195.002T1068T1190T1071.001

An attacker obtained Revolut customer data by submitting fraudulent requests using a legitimate government agency email domain - a process-layer attack exploiting trust in government comms.

Bidirectional risk: a compromised state email can extract bulk citizen data from banks/SaaS, or your agency could receive similarly spoofed requests. Most states lack standardized verification.

T1598.003T1586

Three China-nexus actors refreshed Sep 13: UNC6201 (state/local gov), APT41 (federal/state, healthcare), TEMP.Avengers (gov personnel data, healthcare). Also tracked: CyberAv3ngers, Void Blizzard, Famous Chollima.

No new Volt/Salt Typhoon indicators - not reassuring. Long-dwell tradecraft evades conventional detection; absence is expected, not reduced risk.

T1078T1592

Qilin held #1 victim-count 3 of 4 months, targeting U.S. critical infrastructure. 61 new groups entered the market, reaching 146 active. Interlock adopted ClickFix. REvil resurfaced Sep 12.

Implication: with 146 groups, per-operator detection doesn't scale - shift to TTP-based.

T1566.001T1059.001T1486

ScenarioProbabilityBasis
Additional compromise reports via CVE-2026-85706 within 7 daysHIGH (75-85%)Active exploitation confirmed; many will miss today's deadline
Interlock ClickFix expands to government within 14 daysMODERATE (50-65%)AA25-203A confirms relevance; low barrier
FortiOS PivotC2 deployment accelerates within 14 daysMODERATE (50-60%)KEV listing + RAT linkage + FortiGate prevalence as state perimeter defense
Government domain impersonation within 30 daysLOW-MODERATE (30-45%)Revolut provides proof-of-concept; minimal sophistication
Volt/Salt Typhoon activity on state infrastructure within 30 daysLOW-MODERATE (25-40%)Long-dwell tradecraft needs proactive hunting
Supply-chain compromise via poisoned Artifactory within 30 daysLOW-MODERATE (25-35%)Chained exploitation confirmed; needs authenticated access

Focus AreaATT&CK TechniqueDetection Approach
GitLab commits API abuseT1190, T1552.001Monitor unauthenticated requests to commits API with path traversal.
Artifactory token scope abuseT1068, T1078.003Audit for admin operations without role assignment.
FortiGate post-exploitation (PivotC2)T1071.001, T1059Monitor syslog for unexpected outbound connections, anomalous processes, uncorrelated config changes.
MikroTik btest exploitationT1498, T1040Alert on bandwidth-test connections from external IPs; uncorrelated reboots.
ClickFix delivery chainT1566.001, T1059.001Detect PowerShell from browsers with encoded args or download cradles. Monitor Startup folder.
Legal process fraud (inbound)T1598.003Flag bulk-PII requests failing DMARC/DKIM/SPF; alert on abnormal export volume.
AiTM/PhaaS proxy detectionT1557, T1539Baseline JA4/JA4S in Entra ID; alert on anomalies (low cipher count, missing SNI).
Living-off-the-land (nation-state)T1218, T1047, T1053Hunt LOLBin abuse on FortiGate/jump servers; correlate w/ Volt Typhoon.
IOC Reference:

Findings are primarily assessment-based (KEV additions, exploitation confirmations) rather than IOC-driven. Hashes: SHA-256 6a27ab1fbcf4224cc445ad1a6b7b8bc38b8462c4b252a67e165840ae76693f44 +9 more; SHA-1/MD5 available via Anomali ThreatStream Next-Gen.

Hunting Hypotheses:
HUNT 01 · T1190
GitLab exploited to exfiltrate CI/CD secrets
Query GitLab logs for commits API requests with path traversal; check access to /etc/passwd. Review logs for bulk cloning/token creation.
HUNT 02 · T1190
FortiGate compromised with PivotC2 running
Compare FortiGate firmware hashes against baselines; review management plane; check for unauthorized admin accounts.
HUNT 03 · T1566.001
Interlock ClickFix delivered access via fake update
Search EDR for PowerShell with parent msedge.exe/chrome.exe; check Startup folder entries and connections to new domains.
HUNT 04 · T1598.003
A state domain used for fraudulent data requests
Review outbound email for "subpoena," "court order"; cross-reference with authorized personnel.

Financial Services
Treasury, Revenue
Primary threat
The Revolut breach shows financial custodians are vulnerable to government-impersonation fraud. Treasury/revenue agencies send/receive legal process requests.
Actions
  • Implement callback verification for bulk-PII requests
Energy
Regulated Utilities
Primary threat
FortiOS and AVEVA create a dual threat to energy OT. CyberAv3ngers continues targeting ICS/SCADA.
Actions
  • Confirm FortiGate at OT/IT boundaries; patch to 7.6.4+
Healthcare
Medicaid, Hospitals
Primary threat
Interlock targets healthcare with ClickFix (AA25-203A applies). Orthanc/Mirth advisories affect imaging/integration.
Actions
  • Distribute AA25-203A indicators; patch Orthanc/Mirth
Government
Agencies, Courts
Primary threats
Primary target for nation-state pre-positioning, ransomware, and impersonation fraud. BOD 26-04 compliance is a direct obligation.
Actions
  • Confirm GitLab patch status by EOD
Aviation / Logistics
DOT, Airports
Primary threat
Transportation intersects nation-state pre-positioning and ransomware targeting. MikroTik at remote sites is vulnerable.
Actions
  • Patch MikroTik at transport facilities
No sector cards match the selected filters.

Patch GitLab CE/EE to 19.1.8/19.2.6/19.3.2 - BOD 26-04 deadline is today.
Incident Responder
Patch JFrog to 7.133.11+ - enables supply-chain poisoning.
Incident Responder
Patch FortiOS to 7.6.4+, FortiSwitchManager to 7.2.7+ - confirmed PivotC2.
Incident Responder
Update MikroTik to 6.49.21+ - prioritize branch offices.
Incident Responder
Initiate BOD 26-04 forensic triage on GitLab instances running 18.7-19.3.x.
CISO / ExecIncident Responder
No immediate actions for the selected roles.
Formalize verification procedures for legal process requests - require callback for bulk PII.
CISO / Exec
Implement JA4/JA4S baselining in Entra ID logs to detect AiTM tooling.
SOC Analyst
Confirm AVEVA use at utilities; coordinate patching.
ICS / OT
Audit DMARC/DKIM/SPF; enforce p=reject.
IAM Analyst
No 7-day actions for the selected roles.
Resolve the OSINT collection gap - sixth day of zero returns degrades detection.
CISO / Exec
Deploy ClickFix detection (AA25-203A); commission a Volt Typhoon LOLBin hunt.
SOC AnalystThreat Hunter
Update the IR playbook for BOD 26-04 triage; tabletop ransomware.
Incident ResponderCISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The threat picture facing state government IT is defined by convergence, not any single vulnerability or actor. Supply-chain flaws in GitLab and Artifactory converge with nation-state interest in government source code. Perimeter exploitation in FortiGate converges with purpose-built RATs and industrial targeting. Ransomware delivery techniques like ClickFix converge across operators, making actor-specific detection obsolete. And a novel process-layer attack - government domain impersonation - converges the trust model underpinning inter-agency cooperation with financially motivated social engineering. Four KEV vulnerabilities demand patching, one with a deadline expiring today. A ransomware ecosystem of 146 groups demands a shift from reactive IOC-based defense to proactive TTP-based detection.

1
Patch GitLab, Artifactory, FortiOS, and MikroTik today - the BOD 26-04 deadline has passed.
2
Formalize out-of-band verification for data requests before your agency becomes the next Revolut.
3
Shift from per-operator ransomware detection to TTP-based defense - 146 groups is too many to track individually.
No items found.