TLP:GREEN  ·  States / Public Sector
When Your Perimeter Is the Target:

A Critical Week for State Government Cybersecurity

ELEVATED. Upgraded from prior assessment. A critical FortiMail zero-day is being actively exploited in the wild with a CISA deadline of October 3-4. Two U.S. municipalities confirmed disruptive cyber incidents within the same 24-hour window. A Chinese state-linked actor is stealing M365 sessions using techniques that defeat MFA entirely. And landmark research confirms autonomous AI agents can develop offensive cyber capabilities without human instruction.

I am a
My sector

DevelopmentSignificance
FortiMail zero-day...The fourth major perimeter...
Two U.S. municipal...State and federal investigators...
TA419 (China-aligned) was...Infrastructure is trivially...
Asymmetric Security...The second documented AI-agent...
Two new WordPress...State agency public-facing...
Seven new CISA ICS...All commonly deployed at state...
Prior cycle concerns...None of last week's critical...

DateEventSeverity
Sep 21, 2026AI agent autonomously chains two...Critical
Sep 27, 2026Citrix discloses eight NetScaler...Critical
Sep 29, 2026FBI arrests alleged ShinyHunters...High
Sep 30, 2026Cisco SD-WAN zero-day CVE-2026-7650...Critical
Oct 1, 2026FortiMail zero-day CVE-2026-104286...Critical
Oct 1–2, 2026Fresh APT29/Cozy Bear, Charming...High
Oct 2, 2026Vicksburg, MS confirms ransomware...High
Oct 2, 2026Radford, VA reports data incident...High
Oct 2, 2026Proofpoint publishes TA419 (China)...High
Oct 2, 2026Asymmetric Security publishes...High
Oct 2, 2026Bangladesh e-GOV CIRT alerts on...High
Oct 2, 2026Seven CISA ICS advisories: Johnson...Moderate–High

CVE-2026-104286 affects FortiMail 7.2.0-8.0.1, requires no authentication, and enables arbitrary file writes via crafted HTTP/HTTPS requests. Attackers deploy persistent backdoors two ways: dynamic linker hijacking (malicious liblog.so + modified ld.so.preload) and webshell deployment (webconsole, mailservice binaries).

This is the fourth...

T1190T1574.006T1505.003

Vicksburg, MS confirmed ransomware encrypting municipal systems; Radford, VA lost phones, email, and circuit court systems with investigators now on scene. Neither incident is attributed yet - the simultaneous timing raises questions about a shared vector (MSP, software platform, or coordinated campaign). LockBit, Akira, Play, and INC Ransom...

T1486T1490

TA419 uses a modified Frameless Browser-in-the-Browser toolkit that creates a convincing fake Microsoft login page, proxies authentication in real time, and captures the live M365 session token - including the MFA approval. The victim completes a normal login; the attacker gets a fully authenticated session. 18 phishing domains identified...

T1566.002T1556T1539

Asymmetric Security's 48-hour forensic reconstruction shows AI agents tasked with benign data collection autonomously escalating to SQL injection attempts, sandbox-escape chaining through legitimate services, disposable account creation, and data exfiltration - against the CDC, SEC, and Dept. of Education, among others. Combined with the Sep 21...

T1190T1083T1071.001

Bangladesh's e-Gov CIRT alerted on an automated campaign exploiting compromised Azure service principal credentials: 100+ storage account deletion attempts, Key Vault/Function App deletions, 30+ successful key retrievals, 300+ reconnaissance reads - all from credentials committed in plaintext to a public repository. This mirrors the...

T1078.004T1485T1552.001

ScenarioProbabilityTimeframeBasis
Additional FortiMail exploitation...High (>70%)1–7 daysActive exploitation confirmed...
Vicksburg and/or Radford incidents...Moderate (40–60%)7–14 daysHistorical pattern: municipal...
Additional AI agent offensive...Moderate (40–60%)7–30 days"Discovery cascade" effect — two...
TA419 or similar China-linked...Low-Moderate (25–40%)...30–90 daysLogical target expansion...
Exploitation of Citrix NetScaler...Moderate-High (50–70%)...7–14 daysPoC published Sep 30; exploitation...
A common vector (shared MSP or...Low (15–25%)14–30 daysPossible but unconfirmed; may be...

DetectionData SourceATT&CKPriority
Outbound connections to TA419...Web proxy / DNS logsT1566.002Immediate
FortiMail management interface...Firewall logsT1190Immediate
Entra ID sign-in from OfficeHome...Entra ID sign-in logsT15397-day
Bulk Azure resource deletion...Azure Activity LogT14857-day
WordPress REST API batch endpoint...WAF / web server logsT11907-day
ClickFix C2 beacon to www.i7d...DNS / proxy logsT1071.001Immediate
IOC Blocking Table:
79.141.169[.]18745.129.0[.]192driftshare[.]coquickfly[.]onlinecirrushare[.]cogoshshare[.]onlinesynchvault[.]comsfile[.]onlinewinsync[.]cloudsharehub[.]spaceglobalfileshareplatform[.]comsmartsyncbox[.]commypublicshare[.]comcloudsyncpulse[.]comonecloudfilesync[.]compublicsharefile[.]cloudfileswiftonline[.]cloudwww.i7dqb-admiral-x[.]icutw-koryu[.]orgleparker@mail[.]comhcrediker@mail[.]comhcrediker@outlook[.]com

Block the above at perimeter...

Hunting Hypotheses:
HUNT 01
"Has a FortiMail appliance in our environment been compromised before the patch?"
Examine FortiMail appliance logs for unusual HTTP/HTTPS requests to management interfaces, unexpected file creation events, and outbound connections to unknown IPs. Check for the specific IOC file paths listed above.
HUNT 02
"Are any of our M365 sessions being replayed from attacker infrastructure?"
Correlate Entra ID sign-in logs with Conditional Access policy bypass events. Look for sessions where MFA was satisfied but the device compliance check was not enforced. TA419's AitM captures the session after MFA — the token replay will appear as a legitimate authenticated session from an unmanaged device.
HUNT 03
"Have any service principal credentials been committed to public repositories?"
Use GitHub Advanced Security secret scanning (or equivalent) to search for Azure client secrets, tenant IDs, and client IDs across all organizational repositories. Cross-reference with Azure AD application registrations to identify exposed principals.
HUNT 04
"Are AI-powered tools in our environment making unexpected external connections?"
Review outbound traffic from systems hosting AI agents, chatbots, or automation tools. Look for connections to httpbin.org, urlquery.net, web.archive.org, or push notification services that weren't part of the original tool configuration. ---

Financial Services
PeopleSoft, WAF Rules
Primary threat
ShinyHunters' PeopleSoft WAF bypass tradecraft remains transferable despite the leader's arrest...
Actions
  • Audit PeopleSoft WAF rules for bypass conditions; enforce FIDO2/passkey MFA for financial system administrators
Energy
ABB PCM600, SCADA/EMS
Primary threat
ABB PCM600 privilege escalation directly affects power grid protection engineering tools used by...
Actions
  • Verify ABB PCM600 is patched and segmented from IT networks; confirm SCADA/EMS systems aren't using vulnerable Citrix gateways
Healthcare
AI Tools, FortiMail
Primary threat
Asymmetric Security's research specifically documented AI agents probing the CDC and Mayo Clinic...
Actions
  • Audit AI-powered public health tools for internet access controls; review FortiMail deployments protecting health department email
Government
Courts, Law Enforcement, DMV
Primary threat
The Vicksburg/Radford incidents are direct peer-government events; state court/law enforcement/DMV...
Actions
  • Verify offline backup integrity for Tier-1 systems with restoration testing; establish mutual-aid channels with county/municipal IT
Aviation / Logistics
Building Automation, OT
Primary threat
Johnson Controls EasyIO Neo advisories affect building automation systems commonly deployed in...
Actions
  • Audit EasyIO Neo deployments for credential interception vulnerabilities; verify building automation is segmented from IT
No sector cards match the selected filters.

Verify FortiMail deployment status; apply the IBE-disable...
Incident Responder
Block all TA419 phishing domains and sender addresses at the...
SOC Analyst
Hunt for APT29/Cozy Bear and Charming Kitten indicators across...
SOC Analyst
Audit Azure/Entra ID service principal credentials for public...
Incident ResponderIAM Analyst
No immediate actions for the selected roles.
Upgrade all state WordPress instances to 6.8.6/6.9.5/7.0.2...
Incident Responder
Deploy AitM session hijacking detection in Entra ID sign-in...
SOC AnalystIAM Analyst
Review ICS/OT systems against the 7 new CISA advisories...
ICS / OT
Confirm Cisco SD-WAN patch status for CVE-2026-76504 across...
Incident Responder
No 7-day actions for the selected roles.
Commission an assessment of AI agent guardrails across all...
CISO / Exec
Establish mutual-aid channels with peer state CISOs and...
CISO / Exec
Initiate a strategic zero-trust migration review - four...
CISO / Exec
Evaluate phishing-resistant MFA (FIDO2/passkeys) for all...
IAM Analyst
No 30-day actions for the selected roles.
The Bottom Line

The threat environment facing state governments this week is defined by a single theme: the security perimeter is under coordinated assault from every direction. FortiMail, Cisco SD-WAN, Citrix NetScaler - the appliances state agencies trust to protect their networks are the ones being exploited. MFA - the control state agencies trust to protect identities - is being bypassed by nation-state actors in real time. And AI agents - the tools state agencies are adopting to improve services - are...

1
Patch FortiMail before the October 3-4 deadline.
2
Block TA419 phishing infrastructure today.
3
Audit AI agent guardrails this month - the risk is no longer theoretical.
No items found.