| Development | Why It Matters for State Government |
|---|---|
| Cisco ISE CVE-2026-76460... | ISE is the identity and network... |
| Google Pixel CVE-2026-58704... | Zero-click means no phishing link... |
| DPRK IT worker proxy... | Successfully placed workers gain... |
| Orkes Conductor... | Unauthenticated remote code... |
| 8 CISA ICS advisories... | State agencies operating water... |
| Grafana unpatched RCE... | Grafana is widely used for... |
| Microsoft patches 18... | Azure/M365 cloud fixes are... |
| UNC6394 POUNDFALL backdoor... | Continued expansion of a... |
| Nation-state campaigns... | Government officials, researchers... |
| Ransomware pressure... | Government and manufacturing-adjace... |
| WeaselBiscuit npm supply... | State agencies with Node.js... |
| Date | Event | Severity |
|---|---|---|
| Aug 21, 2026 | Orkes Conductor CVE-2026-58138... | HIGH |
| Sep 8–9, 2026 | Fortinet blocks ~1,300 Conductor... | HIGH |
| Sep 16, 2026 | CISA adds CVE-2026-76460 (Cisco... | CRITICAL |
| Sep 16, 2026 | CISA adds CVE-2026-58704 (Google... | HIGH |
| Sep 16, 2026 | ISC releases BIND 9.20.29 patching... | HIGH |
| Sep 16, 2026 | CISA publishes Cyber Decoys... | INFORMATIONAL |
| Sep 17, 2026 | CISA publishes 8 ICS advisories... | MODERATE–HIGH |
| Sep 17, 2026 | UNC6394 launches 8 simultaneous... | HIGH |
| Sep 18, 2026 | Silent Push documents expanded... | MODERATE–HIGH |
| Sep 18, 2026 | BSI (German CERT) publishes... | MODERATE–HIGH |
| Sep 18, 2026 | Zimperium publishes research on... | MODERATE |
| Sep 18, 2026 | Microsoft releases patches for 18... | MODERATE |
| Sep 19, 2026 | CISA KEV remediation... | DEADLINE |
Cisco ISE is the network access control platform determining who and what is allowed on your network. CVE-2026-76460 is an unauthenticated API auth bypass granting root-level command execution. A compromised ISE node can forge session trust, alter authorization policies, and grant access to every VLAN relying on ISE for admission control. Root...
A logic error in the Pixel cellular modem enables sandbox escape and privilege escalation with zero user interaction - no phishing link, no attachment, no notification. Google's "limited and targeted" language is the standard phrase used when commercial spyware vendors (historically NSO Group, Intellexa) deploy exploits against journalists...
| Actor | Activity |
|---|---|
| APT43 (DPRK) | Rapport-building email campaigns |
| APT42 (Iran/IRGC-IO) | Credential harvesting |
| Sandworm (Russia/GRU) | FEEDUPDATE phishing, Cyclops... |
DPRK operators now recruit foreign nationals to physically sit on camera during video interviews while the real operator remotely controls the computer, answers questions, and completes coding challenges. The persona "Tec Guru" offered a 35/65 revenue split to proxies. Tools: Google Meet, AnyDesk, TeamViewer, Astrill VPN.
Successfully...
Qilin leads ransomware with 178 confirmed H1 2026 victims (22% manufacturing). REvil remains active with fresh indicators. Orkes Conductor CVE-2026-58138 (CVSS 9.8): unauthenticated RCE via malicious workflow definitions, ~1,300 exploitation attempts in 2 days; the process often runs as root...
| Scenario | Probability | Timeframe | Rationale |
|---|---|---|---|
| Accelerated scanning and... | HIGH (75–85%) | 24–72 hours | The CISA KEV deadline (Sep 19)... |
| Grafana RCE receives CVE... | MODERATE-HIGH (60–70%)... | 7–14 days | BSI advisory is published... |
| DPRK IT worker proxy... | MODERATE (50–60%) | 30–60 days | The July 31 joint US/Japan/South... |
| Ransomware group (Qilin or... | MODERATE (45–55%) | 30 days | Government targeting is... |
| Volt Typhoon or Salt... | MODERATE (40–50%) | 14–30 days | Current absence from detection is... |
| Commercial spyware... | MODERATE (40–50%) | 30–60 days | Zero-click exploits historically... |
Hunt hypothesis:...
Hunt hypothesis:...
Hunt hypothesis:...
Hunt hypothesis:...
Hunt hypothesis:...
| Threat | ATT&CK |
|---|---|
| Priority 1 — Cisco ISE Compromise... | T1190 T1078... |
| Priority 2 — Orkes Conductor... | T1190 T1059.007... |
| Priority 3 — DPRK IT Worker... | T1219 T1078... |
| Priority 4 — Nation-State... | T1566.001... |
| Priority 5 — ICS/OT Monitoring | T0831 T0836... |
Block the above at perimeter...
- Audit Cisco ISE nodes controlling financial network segments; enforce phishing-resistant MFA for financial admins
- Review 8 CISA ICS advisories against OT inventory; verify no path from ISE-controlled segments to SCADA
- Confirm ISE patches on EHR/Medicaid network segments; push Pixel updates to field worker devices
- Push Pixel updates to leadership/legal/law enforcement devices; brief hiring managers on DPRK proxy TTPs
- Review Bransys ELD advisory applicability; audit MSP remote access tools for patch status
The convergence of a CVSS 10.0 actively exploited vulnerability in network access control, a zero-click mobile surveillance exploit targeting government officials, and expanding North Korean social engineering operations demands immediate action - not next sprint, not next quarter, today. The Cisco ISE deadline is tomorrow. The Pixel deadline is tomorrow. The adversaries documented in this report - APT43, APT42/IRGC-IO, Sandworm, CyberAv3ngers, Kimsuky, UNC6394, Qilin, REvil - are not waiting...