| Development | Significance |
|---|---|
| Citrix NetScaler zero-days now confirmed... | Attribution points to a well-resourced, likely... |
| ShinyHunters/UNC6240 PeopleSoft campaign... | WAF-only mitigations are confirmed insufficient... |
| A new Entra ID attack technique called... | Captures plaintext credentials continuously as... |
| Infostealer malware is now a direct... | Actor JINX-0164 has used stolen credentials to... |
| APT15 (Vixen Panda/Ke3chang/NICKEL) has... | China-nexus group with documented government... |
| CISA and FBI published joint guidance on... | Directly relevant to state water, transportation... |
| Date | Event | Severity |
|---|---|---|
| Early–Mid Sep 2026 | Nation-state actors begin exploiting Citrix... | CRITICAL |
| 24 Sep 2026 | Webshell deployment attempts against SharePoint... | HIGH |
| 25 Sep 2026 | CISA adds SharePoint CVE-2026-65660 to KEV... | HIGH |
| 25 Sep 2026 | CISA adds WordPress CVE-2026-87902 to KEV catalog | HIGH |
| 26 Sep 2026 | watchTowr confirms two unpatched Citrix NetScaler... | CRITICAL |
| 27 Sep 2026 | Citrix discloses 8 CVEs (CVE-2026-88771 through... | CRITICAL |
| 27–28 Sep 2026 | APT15/Mirage family SHA-256 hashes targeting US... | HIGH |
| 28 Sep 2026 | Google/Mandiant confirms UNC6240 PeopleSoft... | CRITICAL |
| 28 Sep 2026 | Varonis discloses TrustSink technique for... | HIGH |
| 28 Sep 2026 | Wiz/NordStellar publish infostealer-to-cloud-crede... | HIGH |
| 23 Sep 2026 (collected 28 Sep) | CISA/FBI publish joint guidance on third-party... | MODERATE |
CVE-2026-88771 enables unauthenticated command execution; CVE-2026-88772 enables RCE/DoS via memory overflow on DTLS-enabled VPN virtual servers - enabled by default. Six additional CVEs address request smuggling and policy bypass. Nation-state actors have been exploiting these throughout September, planting webshells and deleting forensic...
CVE-2026-35273 exploitation has matured from opportunistic scanning to targeted government operations via a trivial WAF bypass (/%50SEMHUB/hub). Attack chain: JSP webshells for persistence, the SIDEEYE backdoor (trojanized media player installer) for C2, MeshAgent and Neo-reGeorg for tunneling, then Microsoft-themed phishing for...
Unlike traditional AiTM phishing requiring attacker infrastructure, TrustSink operates entirely within the legitimate Microsoft sign-in experience. An attacker with Global Admin access registers a rogue OIDC provider as an External Authentication Method, inserting a fake password prompt that captures plaintext credentials continuously...
Lumma, RedLine, and Vidar (85.7% of detected incidents) target developer workstations for cloud CLI credentials, CI/CD tokens, Kubernetes secrets, and AI API keys. Actor JINX-0164 has used stolen credentials to modify internal code repositories - turning credential theft into supply chain compromise. Separately, malicious code (Miasma) was...
Fresh high-confidence APT15 (Vixen Panda/Ke3chang/NICKEL) malware samples ingested Sep 27-28 - a China-nexus group with well-documented government espionage history, despite current samples tagged to retail.
Separately, CISA/FBI's Sep 23 guidance on third-party ICS integrators highlights the trusted-relationship vector (T1199) for water...
| Scenario | Probability | Timeframe | Basis |
|---|---|---|---|
| Ransomware groups weaponize Citrix... | >75% (HIGH) | 1–3 weeks | Follows the established nation-state-to-ransomware... |
| Additional government PeopleSoft victims... | 50–75% (MODERATE) | 1–2 weeks | Campaign is actively expanding sectors; WAF... |
| TrustSink technique adopted by credential-theft-as... | 50–75% (MODERATE) | Within 30 days | Low barrier to implementation; high value for... |
| Citrix zero-day exploitation discovered in state... | 50–75% (MODERATE) | Upon investigation | Attacks have been ongoing throughout September... |
| Kiteworks MFT vulnerability details emerge... | 25–50% (LOW-MODERATE) | 2–4 weeks | Suspected zero-day triggered emergency vendor... |
| Infostealer-harvested cloud credentials used in... | 25–50% (LOW-MODERATE) | 1–3 months | Pipeline is documented and maturing; npm... |
Hunt hypothesis: Attackers have...
Hunt hypothesis: UNC6240 is...
Hunt hypothesis: If any state...
T1555.003 (Credentials from Web...
T1059 (Command and Scripting...
Additional IOCs for the campaigns discussed in...
| Threat | ATT&CK |
|---|---|
| Citrix NetScaler Exploitation (CRITICAL — deploy... | T1190 T1505.003... |
| PeopleSoft Exploitation (CRITICAL — deploy... | T1190 T1505.003... |
| Entra ID TrustSink Detection (HIGH — deploy... | T1556.006 T1078.004... |
| Infostealer and Cloud Credential Theft (HIGH —... | T1555.003 T1528... |
| APT15/Mirage Detection (HIGH — deploy within 24... | T1059 |
Block the above at perimeter firewalls, proxies...
- Patch PeopleSoft immediately, do not rely on WAF rules; rotate cloud CLI credentials for finance IT staff
- Treat Citrix-to-OT VPN access as a Tier 1 emergency; implement the CISA/FBI ICS integrator guidance
- Patch PeopleSoft and hunt for webshells immediately; enforce hardware-bound MFA for cloud admin access
- Verify election systems are segmented from Citrix/PeopleSoft-accessible networks; patch WordPress citizen-facing sites
- Apply ICS integrator guidance to all transportation SCADA vendors; patch or take offline Citrix VPN to OT networks
State government IT leadership faces a convergence of active threats unusual in both breadth and severity. Three distinct exploitation campaigns are running simultaneously against technologies foundational to state operations: Citrix NetScaler for remote access, Oracle PeopleSoft for HR/finance, and Microsoft Entra ID for identity. A fourth threat - the maturing infostealer-to-cloud-credential pipeline - is eroding the boundary between endpoint compromise and cloud breach. The Citrix patching...