| Development | Significance |
|---|---|
| CVE-2025-25249 (FortiOS, CVSS 8.1) added to KEV Sep 9 - linked to PivotC2 RAT. | FortiGate is primary perimeter defense for most state networks |
| CVE-2026-67277 (MikroTik, CVSS 8.2) added to KEV Sep 10 - unauth memory leak/DoS. | MikroTik deployed at branch/remote state offices |
| CVE-2026-85706 (GitLab CVSS 10.0) added to KEV Sep 11 with a 3-day BOD 26-04 deadline expiring today. | State agencies running self-managed GitLab |
| Revolut breach via government-domain impersonation disclosed Sep 12 - attacker used a legitimate government domain to extract citizen data. | State domains could be weaponized, or receive spoofed requests |
| China-nexus profiles refreshed Sep 13: UNC6201, APT41, TEMP.Avengers - U.S. gov targeting. | Quiet does not mean safe for long-dwell actors |
| Qilin confirmed #1 ransomware group for the third month; Interlock adopts ClickFix. | Government/critical infra are explicit Qilin targets |
| Date | Event | Severity | State Gov Relevance |
|---|---|---|---|
| Sep 9 | CVE-2025-25249 (FortiOS RCE) added to KEV; PivotC2 linkage published | HIGH | FortiGate is primary perimeter defense for most state networks |
| Sep 10 | CVE-2026-67277 (MikroTik) added to KEV | HIGH | MikroTik routers deployed at branch/remote state offices |
| Sep 11 | CVE-2026-85706 (GitLab CVSS 10.0) added to KEV, 3-day BOD 26-04 deadline | CRITICAL | State agencies running self-managed GitLab |
| Sep 12 | ZachXBT discloses Revolut breach via government domain impersonation | MODERATE | State domains could be weaponized or spoofed |
| Sep 13 | China-nexus profiles refreshed: UNC6201, APT41, TEMP.Avengers | ELEVATED | Documented U.S. gov targeting |
| Sep 14 | Rapid7 confirms active exploitation; BOD 26-04 deadline expires | CRITICAL | Deadline is today - triage required |
An improper path confinement flaw in GitLab's commits API allows unauthenticated file reads - credentials, tokens, CI/CD secrets. Exploitation confirmed. Same patch addresses CVE-2026-87719 (CVSS 9.9, Duo Chat/GraphQL theft).
Different: BOD 26-04 requires forensic triage, not just patching.
JFrog (8.1): token validation flaw lets an authenticated user escalate to admin, then plant backdoored packages poisoning builds. Chained exploitation confirmed. Fixed in 7.133.11+.
FortiOS (8.1): heap overflow enables RCE via crafted packets; linked to PivotC2. Siemens confirms water/energy/transportation utilities in scope.
An attacker obtained Revolut customer data by submitting fraudulent requests using a legitimate government agency email domain - a process-layer attack exploiting trust in government comms.
Bidirectional risk: a compromised state email can extract bulk citizen data from banks/SaaS, or your agency could receive similarly spoofed requests. Most states lack standardized verification.
Three China-nexus actors refreshed Sep 13: UNC6201 (state/local gov), APT41 (federal/state, healthcare), TEMP.Avengers (gov personnel data, healthcare). Also tracked: CyberAv3ngers, Void Blizzard, Famous Chollima.
No new Volt/Salt Typhoon indicators - not reassuring. Long-dwell tradecraft evades conventional detection; absence is expected, not reduced risk.
Qilin held #1 victim-count 3 of 4 months, targeting U.S. critical infrastructure. 61 new groups entered the market, reaching 146 active. Interlock adopted ClickFix. REvil resurfaced Sep 12.
Implication: with 146 groups, per-operator detection doesn't scale - shift to TTP-based.
| Scenario | Probability | Basis |
|---|---|---|
| Additional compromise reports via CVE-2026-85706 within 7 days | HIGH (75-85%) | Active exploitation confirmed; many will miss today's deadline |
| Interlock ClickFix expands to government within 14 days | MODERATE (50-65%) | AA25-203A confirms relevance; low barrier |
| FortiOS PivotC2 deployment accelerates within 14 days | MODERATE (50-60%) | KEV listing + RAT linkage + FortiGate prevalence as state perimeter defense |
| Government domain impersonation within 30 days | LOW-MODERATE (30-45%) | Revolut provides proof-of-concept; minimal sophistication |
| Volt/Salt Typhoon activity on state infrastructure within 30 days | LOW-MODERATE (25-40%) | Long-dwell tradecraft needs proactive hunting |
| Supply-chain compromise via poisoned Artifactory within 30 days | LOW-MODERATE (25-35%) | Chained exploitation confirmed; needs authenticated access |
| Focus Area | ATT&CK Technique | Detection Approach |
|---|---|---|
| GitLab commits API abuse | T1190, T1552.001 | Monitor unauthenticated requests to commits API with path traversal. |
| Artifactory token scope abuse | T1068, T1078.003 | Audit for admin operations without role assignment. |
| FortiGate post-exploitation (PivotC2) | T1071.001, T1059 | Monitor syslog for unexpected outbound connections, anomalous processes, uncorrelated config changes. |
| MikroTik btest exploitation | T1498, T1040 | Alert on bandwidth-test connections from external IPs; uncorrelated reboots. |
| ClickFix delivery chain | T1566.001, T1059.001 | Detect PowerShell from browsers with encoded args or download cradles. Monitor Startup folder. |
| Legal process fraud (inbound) | T1598.003 | Flag bulk-PII requests failing DMARC/DKIM/SPF; alert on abnormal export volume. |
| AiTM/PhaaS proxy detection | T1557, T1539 | Baseline JA4/JA4S in Entra ID; alert on anomalies (low cipher count, missing SNI). |
| Living-off-the-land (nation-state) | T1218, T1047, T1053 | Hunt LOLBin abuse on FortiGate/jump servers; correlate w/ Volt Typhoon. |
Findings are primarily assessment-based (KEV additions, exploitation confirmations) rather than IOC-driven. Hashes: SHA-256 6a27ab1fbcf4224cc445ad1a6b7b8bc38b8462c4b252a67e165840ae76693f44 +9 more; SHA-1/MD5 available via Anomali ThreatStream Next-Gen.
/etc/passwd. Review logs for bulk cloning/token creation.- Implement callback verification for bulk-PII requests
- Confirm FortiGate at OT/IT boundaries; patch to 7.6.4+
- Distribute AA25-203A indicators; patch Orthanc/Mirth
- Confirm GitLab patch status by EOD
- Patch MikroTik at transport facilities
The threat picture facing state government IT is defined by convergence, not any single vulnerability or actor. Supply-chain flaws in GitLab and Artifactory converge with nation-state interest in government source code. Perimeter exploitation in FortiGate converges with purpose-built RATs and industrial targeting. Ransomware delivery techniques like ClickFix converge across operators, making actor-specific detection obsolete. And a novel process-layer attack - government domain impersonation - converges the trust model underpinning inter-agency cooperation with financially motivated social engineering. Four KEV vulnerabilities demand patching, one with a deadline expiring today. A ransomware ecosystem of 146 groups demands a shift from reactive IOC-based defense to proactive TTP-based detection.