TLP:GREEN  ·  States / Public Sector
When the Perimeter Falls:

Three Active Exploitation Campaigns Targeting Government Infrastructure Demand Immediate Action

HIGH. Escalated from ELEVATED. CISA-confirmed active exploitation of Citrix NetScaler zero-days carries a 48-hour federal patching deadline. ShinyHunters/UNC6240 has expanded PeopleSoft targeting into government. And a novel Microsoft Entra ID credential theft technique operates inside legitimate sign-in flows. State agencies running any combination of Citrix NetScaler, Oracle PeopleSoft, or Microsoft Entra ID - which describes most state government environments - face simultaneous, active threats across perimeter, applications, and identity.

I am a
My sector

DevelopmentSignificance
Citrix NetScaler zero-days now confirmed...Attribution points to a well-resourced, likely...
ShinyHunters/UNC6240 PeopleSoft campaign...WAF-only mitigations are confirmed insufficient...
A new Entra ID attack technique called...Captures plaintext credentials continuously as...
Infostealer malware is now a direct...Actor JINX-0164 has used stolen credentials to...
APT15 (Vixen Panda/Ke3chang/NICKEL) has...China-nexus group with documented government...
CISA and FBI published joint guidance on...Directly relevant to state water, transportation...

DateEventSeverity
Early–Mid Sep 2026Nation-state actors begin exploiting Citrix...CRITICAL
24 Sep 2026Webshell deployment attempts against SharePoint...HIGH
25 Sep 2026CISA adds SharePoint CVE-2026-65660 to KEV...HIGH
25 Sep 2026CISA adds WordPress CVE-2026-87902 to KEV catalogHIGH
26 Sep 2026watchTowr confirms two unpatched Citrix NetScaler...CRITICAL
27 Sep 2026Citrix discloses 8 CVEs (CVE-2026-88771 through...CRITICAL
27–28 Sep 2026APT15/Mirage family SHA-256 hashes targeting US...HIGH
28 Sep 2026Google/Mandiant confirms UNC6240 PeopleSoft...CRITICAL
28 Sep 2026Varonis discloses TrustSink technique for...HIGH
28 Sep 2026Wiz/NordStellar publish infostealer-to-cloud-crede...HIGH
23 Sep 2026 (collected 28 Sep)CISA/FBI publish joint guidance on third-party...MODERATE

CVE-2026-88771 enables unauthenticated command execution; CVE-2026-88772 enables RCE/DoS via memory overflow on DTLS-enabled VPN virtual servers - enabled by default. Six additional CVEs address request smuggling and policy bypass. Nation-state actors have been exploiting these throughout September, planting webshells and deleting forensic...

T1190T1505.003T1070.004

CVE-2026-35273 exploitation has matured from opportunistic scanning to targeted government operations via a trivial WAF bypass (/%50SEMHUB/hub). Attack chain: JSP webshells for persistence, the SIDEEYE backdoor (trojanized media player installer) for C2, MeshAgent and Neo-reGeorg for tunneling, then Microsoft-themed phishing for...

T1190T1505.003T1572

Unlike traditional AiTM phishing requiring attacker infrastructure, TrustSink operates entirely within the legitimate Microsoft sign-in experience. An attacker with Global Admin access registers a rogue OIDC provider as an External Authentication Method, inserting a fake password prompt that captures plaintext credentials continuously...

T1556T1078.004

Lumma, RedLine, and Vidar (85.7% of detected incidents) target developer workstations for cloud CLI credentials, CI/CD tokens, Kubernetes secrets, and AI API keys. Actor JINX-0164 has used stolen credentials to modify internal code repositories - turning credential theft into supply chain compromise. Separately, malicious code (Miasma) was...

T1552.001T1195.002

Fresh high-confidence APT15 (Vixen Panda/Ke3chang/NICKEL) malware samples ingested Sep 27-28 - a China-nexus group with well-documented government espionage history, despite current samples tagged to retail.

Separately, CISA/FBI's Sep 23 guidance on third-party ICS integrators highlights the trusted-relationship vector (T1199) for water...

T1059T1199

ScenarioProbabilityTimeframeBasis
Ransomware groups weaponize Citrix...>75% (HIGH)1–3 weeksFollows the established nation-state-to-ransomware...
Additional government PeopleSoft victims...50–75% (MODERATE)1–2 weeksCampaign is actively expanding sectors; WAF...
TrustSink technique adopted by credential-theft-as...50–75% (MODERATE)Within 30 daysLow barrier to implementation; high value for...
Citrix zero-day exploitation discovered in state...50–75% (MODERATE)Upon investigationAttacks have been ongoing throughout September...
Kiteworks MFT vulnerability details emerge...25–50% (LOW-MODERATE)2–4 weeksSuspected zero-day triggered emergency vendor...
Infostealer-harvested cloud credentials used in...25–50% (LOW-MODERATE)1–3 monthsPipeline is documented and maturing; npm...

Citrix NetScaler Exploitation (CRITICAL — deploy immediately):

Hunt hypothesis: Attackers have...

PeopleSoft Exploitation (CRITICAL — deploy immediately):

Hunt hypothesis: UNC6240 is...

Entra ID TrustSink Detection (HIGH — deploy within 24 hours):

Hunt hypothesis: If any state...

Infostealer and Cloud Credential Theft (HIGH — deploy within 7 days):

T1555.003 (Credentials from Web...

APT15/Mirage Detection (HIGH — deploy within 24 hours):

T1059 (Command and Scripting...

IOC Blocking Table:

Additional IOCs for the campaigns discussed in...

ThreatATT&CK
Citrix NetScaler Exploitation (CRITICAL — deploy...T1190 T1505.003...
PeopleSoft Exploitation (CRITICAL — deploy...T1190 T1505.003...
Entra ID TrustSink Detection (HIGH — deploy...T1556.006 T1078.004...
Infostealer and Cloud Credential Theft (HIGH —...T1555.003 T1528...
APT15/Mirage Detection (HIGH — deploy within 24...T1059
IOC Blocking Table:
5.199.162[.]157104.219.234[.]138162.219.30[.]165winmanage-me[.]networkazurenetfiles[.]netmicrosoft-entra[.]netazuredevice[.]cloud

Block the above at perimeter firewalls, proxies...

Hunting Hypotheses:
HUNT 01
Citrix NetScaler Exploitation (CRITICAL — deploy immediately)
Attackers have already compromised NetScaler appliances and planted webshells during September. Assume breach until forensic review is complete.
HUNT 02
PeopleSoft Exploitation (CRITICAL — deploy immediately)
UNC6240 is scanning and exploiting government PeopleSoft instances now. Any internet-facing PeopleSoft Environment Management Hub is a target.
HUNT 03
Entra ID TrustSink Detection (HIGH — deploy within 24 hours)
If any state Entra tenant has been compromised at the Global Admin level (including through prior infostealer compromise), a rogue External Authentication Method may already be registered.

Financial Services
Treasury, PeopleSoft HR/Finance
Primary threat
PeopleSoft HR/Finance is the highest-risk application this week; infostealer-to-cloud pipeline...
Actions
  • Patch PeopleSoft immediately, do not rely on WAF rules; rotate cloud CLI credentials for finance IT staff
Energy
SCADA/OT, Citrix VPN
Primary threat
A compromised NetScaler providing OT VPN access is a Tier 1 emergency - the exact IT-to-OT bridge...
Actions
  • Treat Citrix-to-OT VPN access as a Tier 1 emergency; implement the CISA/FBI ICS integrator guidance
Healthcare
Medicaid, PeopleSoft Systems
Primary threat
Explicitly confirmed in UNC6240's expanded targeting; TrustSink is particularly dangerous given...
Actions
  • Patch PeopleSoft and hunt for webshells immediately; enforce hardware-bound MFA for cloud admin access
Government
Law Enforcement, Elections
Primary threat
Primary target audience for every threat this cycle; fresh APT15 indicators should trigger...
Actions
  • Verify election systems are segmented from Citrix/PeopleSoft-accessible networks; patch WordPress citizen-facing sites
Aviation / Logistics
DOT, Transportation SCADA
Primary threat
Transportation is now a confirmed UNC6240 target sector; shares the same ICS integrator risk as...
Actions
  • Apply ICS integrator guidance to all transportation SCADA vendors; patch or take offline Citrix VPN to OT networks
No sector cards match the selected filters.

Authorize emergency Citrix NetScaler patching to...
Incident Responder
Confirm PeopleSoft patch status; apply Oracle's update...
Incident Responder
Block confirmed UNC6240 indicators at perimeter firewalls and...
SOC Analyst
Audit all External Authentication Methods in every state Entra...
IAM Analyst
No immediate actions for the selected roles.
Audit developer workstations for infostealer indicators...
Incident Responder
Verify WordPress patch status for CVE-2026-87902 across all...
Incident Responder
Deploy PeopleSoft webshell detection: monitor...
SOC Analyst
Review 90 days of Entra ID sign-in logs for suspicious MFA...
SOC AnalystIAM Analyst
No 7-day actions for the selected roles.
Commission a review of third-party ICS integrator access per...
ICS / OT
Initiate a zero-trust architecture assessment to reduce...
CISO / Exec
Elevate Entra ID admin roles to Tier 0 asset classification...
CISO / ExecIAM Analyst
Restore commercial OSINT feed capability to close the current...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

State government IT leadership faces a convergence of active threats unusual in both breadth and severity. Three distinct exploitation campaigns are running simultaneously against technologies foundational to state operations: Citrix NetScaler for remote access, Oracle PeopleSoft for HR/finance, and Microsoft Entra ID for identity. A fourth threat - the maturing infostealer-to-cloud-credential pipeline - is eroding the boundary between endpoint compromise and cloud breach. The Citrix patching...

1
Patch Citrix NetScaler before September 30.
2
Hunt for PeopleSoft webshells today.
3
Audit Entra ID External Authentication Methods this week.
No items found.