| Development | Details |
|---|---|
| MikroTik "MikroTrick" exploitation went active. CVE-2026-67276/86060 confirmed exploited (CERT.PL) - 122,500 devices exposed. | County/municipal MikroTik networks at direct risk |
| ConnectWise ScreenConnect disclosed an unpatched file-transfer flaw. No CVE, no patch. | Documented ransomware/APT exploitation history |
| N-able N-central got an emergency hotfix for a pre-auth RCE (CVE-2026-86218). | Same servers MSPs use to manage state endpoints |
| APT28 refined its HOOKEDGE backdoor - new variants (Jun-Jul) targeting European government via webhook[.]site C2. | 12 new file hashes available for detection |
| Qilin added the Philippine Ports Authority (885+ victims); Rhysida demanded 30 BTC from Berlin - refused. | Continued international government ransomware targeting |
| Telerik UI 4-CVE chain enables padding oracle, DLL upload, RCE. | Legacy .NET citizen portals/benefits systems at risk; patch 2026.2.708 |
| FalconFlank PoC published - Falcon's macro-remediation abused for local privesc. | Novel: EDR remediation becomes the escalation vector |
| Date | Event | Significance |
|---|---|---|
| Jan-Apr 2026 | Winona County, MN pays $128,539 ransom, struck by a different group 3 months later | Double-ransomware risk for local government |
| Jun-Jul 2026 | APT28 deploys new HOOKEDGE backdoor variants against European government targets | Russian GRU continues investing in government-targeting capabilities |
| Aug 28, 2026 | Rhysida demands 30 BTC from Berlin city government for 5.79TB of exfiltrated data | Government ransomware targeting continues internationally |
| Sep 1, 2026 | CVE-2026-83548 (CVSS 10.0) pre-auth SSRF in SonicWall SMA 1000, active exploitation | Critical perimeter zero-day |
| Sep 3, 2026 | MikroTik releases RouterOS patches for MikroTrick CVEs | 122,500 devices remain exposed |
| Sep 5, 2026 | Qilin adds Philippine Ports Authority to leak site; total victims exceed 885 | Government port authority targeted; Qilin expanding aggressively |
| Sep 7, 2026 | CISA ICS advisories published for Rockwell, Schneider Electric, IXON, Inductive Automation, OPC UA | Ongoing ICS/SCADA vulnerability disclosures affecting critical infrastructure |
CVE-2026-67276 (SSH auth bypass) + CVE-2026-86060 (SSH privesc) combine for full admin access; CVE-2026-67277 causes memory leak/DoS. MikroTik sits at county edges with weak patch discipline. Patches: RouterOS 7.24.2/7.23.4/6.49.21.
ScreenConnect: unpatched file-transfer flaw, disable TransferFiles (~6,000 exposed). N-central: pre-auth RCE (CVE-2026-86218), Hotfix 4 released. A compromised MSP platform compromises every client simultaneously.
New variants (Jun-Jul) use msedge.exe as HTTP client, webhook[.]site C2, two-tier beaconing (30-61 min, 5-min high-value). Targets are European, but APT28 has a U.S. state/local history - TTPs transfer.
Qilin (885+ victims) added the Philippine Ports Authority. Rhysida demanded 30 BTC from Berlin - refused. Playbook: VPN exploitation -> AD lateral movement -> exfil before encryption. Winona County paid $128,539, struck again by a different group 3 months later.
4 CVEs chain a Telerik padding oracle into DLL upload and RCE - web shell in IIS. Fixed in 2026.2.708. FalconFlank: a PoC abuses Falcon's macro-remediation for SYSTEM privesc (post-compromise only).
| Predicted Scenario | Probability | Basis |
|---|---|---|
| Ransomware (Qilin, Rhysida) targets state/local government via VPN/RMM | HIGH (75-85%) | Active targeting; unpatched ScreenConnect/N-central; Winona precedent |
| Exploitation of unpatched MikroTik devices at county/municipal edges | HIGH (70-80%) | Active exploitation; 122,500 exposed; slow county patching |
| APT28 HOOKEDGE-style webhook C2 targets state government via spearphishing | MODERATE (40-55%) | Confirmed European targeting; TTPs transferable; no direct U.S. evidence yet |
| MSP compromise cascades to state endpoints via ScreenConnect/N-central | MODERATE (45-60%) | 3 MSP vulnerabilities in 24h; proven lateral movement path |
| Volt/Salt Typhoon pre-positioning in state government networks | MODERATE (35-50%) | Silence may indicate improved OPSEC, not reduced activity |
| Exploitation of Telerik UI in state legacy web apps | LOW-MODERATE (25-40%) | PoC published; exposure depends on deployment |
| FalconFlank adopted by ransomware affiliates | LOW-MODERATE (20-35%) | PoC verified; typical adoption 30-90 days |
Monitor 82.192.72[.]4/103.102.31[.]18; logs for login failure for user -2. Block inbound SSH; patch RouterOS.
Monitor msedge.exe->webhook[.]site tasks; 30-61/5-min beaconing; hashes below in EDR.
Monitor anomalous file transfers, off-hours sessions, unauthenticated API calls. Disable TransferFiles; patch N-central.
Monitor w3wp.exe spawning cmd.exe/PowerShell; unexpected DLLs/aspx files. Upgrade to 2026.2.708+; add WAF rules.
If Falcon runs Phase 3 with "Suspicious Macro Removal" enabled, a foothold could escalate to SYSTEM. Disable per CrowdStrike's Tech Alert; verify Cloud Anti-malware remains active.
| Threat | ATT&CK |
|---|---|
| P1 - MikroTik MikroTrick | T1078 T1552.004 |
| P2 - APT28 HOOKEDGE | T1566.001 T1071.001 |
| P3 - MSP Tool Exploitation | T1105 T1219 T1190 |
| P4 - Telerik UI | T1190 T1505.003 |
Block above at perimeter/DNS. HOOKEDGE SHA-256 hashes (sample): 206bd177f3f3b637b0a444ce2dd6d5aaaefc9d66c866ac6ec0c9e946ce140991, 231164362b2e4688e5d64ef7154845d655b649470bf995a79107b800ac5663b1, 58cfb8b9fee1caa94813c259901dc1baa96bae7d30d79b79a7d441d0ee4e577e - 9 additional variant hashes available via ThreatStream Next-Gen.
- Prioritize Telerik patching + WAF rules; enforce FIDO2 for financial access
- Request a CISA briefing on Volt Typhoon activity
- Patch IXON VPN with MFA-restricted access
- Validate HIPAA breach-notification readiness; require healthcare MSPs to confirm mitigation within 24h
- Deploy the HOOKEDGE hashes to EDR; verify Chrome fleet updated for CVE-2026-85046
- Review Qilin TTPs against your architecture; include transportation sites in MikroTik patching
State government networks face a convergence that individually would warrant urgent action - together they demand it. MikroTik exploitation is confirmed, SonicWall's CVSS 10.0 zero-day is active, 122,500 devices are exposed. Your MSP supply chain is a direct attack path - one exploited ScreenConnect/N-central instance grants access to every client agency. APT28's HOOKEDGE refinement signals sustained intent. Volt/Salt Typhoon have gone quiet - not reassurance for pre-positioning groups. No new U.S. state/local ransomware victims this cycle - positive, but not a trend.