TLP:GREEN  ·  States / Public Sector
Your Network Trust Anchor Is Compromised:

Cisco ISE Under Active Attack, Pixel Zero-Click Exploit, and DPRK Infiltration Schemes

ELEVATED. Unchanged from prior cycle. Sustained by a maximum-severity actively exploited CVSS 10.0 vulnerability in Cisco ISE with a CISA KEV deadline arriving tomorrow, a zero-click Google Pixel exploit enabling surveillance of government officials without user interaction, and expanding North Korean IT-worker infiltration schemes now using real people as camera proxies during remote interviews. Nation-state campaigns from four adversary nations remain active.

I am a
My sector

DevelopmentWhy It Matters for State Government
Cisco ISE CVE-2026-76460...ISE is the identity and network...
Google Pixel CVE-2026-58704...Zero-click means no phishing link...
DPRK IT worker proxy...Successfully placed workers gain...
Orkes Conductor...Unauthenticated remote code...
8 CISA ICS advisories...State agencies operating water...
Grafana unpatched RCE...Grafana is widely used for...
Microsoft patches 18...Azure/M365 cloud fixes are...
UNC6394 POUNDFALL backdoor...Continued expansion of a...
Nation-state campaigns...Government officials, researchers...
Ransomware pressure...Government and manufacturing-adjace...
WeaselBiscuit npm supply...State agencies with Node.js...

DateEventSeverity
Aug 21, 2026Orkes Conductor CVE-2026-58138...HIGH
Sep 8–9, 2026Fortinet blocks ~1,300 Conductor...HIGH
Sep 16, 2026CISA adds CVE-2026-76460 (Cisco...CRITICAL
Sep 16, 2026CISA adds CVE-2026-58704 (Google...HIGH
Sep 16, 2026ISC releases BIND 9.20.29 patching...HIGH
Sep 16, 2026CISA publishes Cyber Decoys...INFORMATIONAL
Sep 17, 2026CISA publishes 8 ICS advisories...MODERATE–HIGH
Sep 17, 2026UNC6394 launches 8 simultaneous...HIGH
Sep 18, 2026Silent Push documents expanded...MODERATE–HIGH
Sep 18, 2026BSI (German CERT) publishes...MODERATE–HIGH
Sep 18, 2026Zimperium publishes research on...MODERATE
Sep 18, 2026Microsoft releases patches for 18...MODERATE
Sep 19, 2026CISA KEV remediation...DEADLINE

Cisco ISE is the network access control platform determining who and what is allowed on your network. CVE-2026-76460 is an unauthenticated API auth bypass granting root-level command execution. A compromised ISE node can forge session trust, alter authorization policies, and grant access to every VLAN relying on ISE for admission control. Root...

T1190T1078T1070.004

A logic error in the Pixel cellular modem enables sandbox escape and privilege escalation with zero user interaction - no phishing link, no attachment, no notification. Google's "limited and targeted" language is the standard phrase used when commercial spyware vendors (historically NSO Group, Intellexa) deploy exploits against journalists...

T1203T1068T1430
ActorActivity
APT43 (DPRK)Rapport-building email campaigns
APT42 (Iran/IRGC-IO)Credential harvesting
Sandworm (Russia/GRU)FEEDUPDATE phishing, Cyclops...

DPRK operators now recruit foreign nationals to physically sit on camera during video interviews while the real operator remotely controls the computer, answers questions, and completes coding challenges. The persona "Tec Guru" offered a 35/65 revenue split to proxies. Tools: Google Meet, AnyDesk, TeamViewer, Astrill VPN.

Successfully...

T1566.003T1078T1219T1530

Qilin leads ransomware with 178 confirmed H1 2026 victims (22% manufacturing). REvil remains active with fresh indicators. Orkes Conductor CVE-2026-58138 (CVSS 9.8): unauthenticated RCE via malicious workflow definitions, ~1,300 exploitation attempts in 2 days; the process often runs as root...

T1190T1059.007T1552.001

ScenarioProbabilityTimeframeRationale
Accelerated scanning and...HIGH (75–85%)24–72 hoursThe CISA KEV deadline (Sep 19)...
Grafana RCE receives CVE...MODERATE-HIGH (60–70%)...7–14 daysBSI advisory is published...
DPRK IT worker proxy...MODERATE (50–60%)30–60 daysThe July 31 joint US/Japan/South...
Ransomware group (Qilin or...MODERATE (45–55%)30 daysGovernment targeting is...
Volt Typhoon or Salt...MODERATE (40–50%)14–30 daysCurrent absence from detection is...
Commercial spyware...MODERATE (40–50%)30–60 daysZero-click exploits historically...

Priority 1 — Cisco ISE Compromise Detection:

Hunt hypothesis:...

Priority 2 — Orkes Conductor Exploitation:

Hunt hypothesis:...

Priority 3 — DPRK IT Worker Indicators:

Hunt hypothesis:...

Priority 4 — Nation-State Credential Harvesting:

Hunt hypothesis:...

Priority 5 — ICS/OT Monitoring:

Hunt hypothesis:...

ThreatATT&CK
Priority 1 — Cisco ISE Compromise...T1190 T1078...
Priority 2 — Orkes Conductor...T1190 T1059.007...
Priority 3 — DPRK IT Worker...T1219 T1078...
Priority 4 — Nation-State...T1566.001...
Priority 5 — ICS/OT MonitoringT0831 T0836...
IOC Blocking Table:
82.192.72[.]4103.102.31[.]18bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]mybpost[.]centerqr[.]paps[.]jp

Block the above at perimeter...

Hunting Hypotheses:
HUNT 01
Priority 1 — Cisco ISE Compromise Detection
An attacker has exploited CVE-2026-76460 to gain root access to an ISE node and is manipulating network access policies or deleting logs to cover lateral movement.
HUNT 02
Priority 2 — Orkes Conductor Exploitation
An attacker is submitting malicious workflow definitions to an exposed Conductor API to achieve remote code execution.
HUNT 03
Priority 3 — DPRK IT Worker Indicators
A recently hired remote IT worker is actually controlled by a DPRK operator using remote access tools.
HUNT 04
Priority 4 — Nation-State Credential Harvesting
APT42 (IRGC-IO) or APT43 is conducting credential harvesting against state government employees via rapport-building emails or fake login pages.
HUNT 05
Priority 5 — ICS/OT Monitoring
An attacker is exploiting vulnerabilities in Schneider Electric Modicon M340, Hitachi Energy FACTS, or ABB Edgenius to manipulate industrial control parameters.

Financial Services
Treasury, Revenue, Benefits
Primary threat
Prime targets for ransomware extortion and nation-state financial intelligence collection via...
Actions
  • Audit Cisco ISE nodes controlling financial network segments; enforce phishing-resistant MFA for financial admins
Energy
Water, Utility SCADA
Primary threat
CyberAv3ngers continues targeting water/wastewater ICS/OT; Modicon M340 and Hitachi FACTS...
Actions
  • Review 8 CISA ICS advisories against OT inventory; verify no path from ISE-controlled segments to SCADA
Healthcare
Medicaid, Public Health Labs
Primary threat
PHI-processing systems are high-urgency ransomware targets; mobile PHI exposure via Pixel...
Actions
  • Confirm ISE patches on EHR/Medicaid network segments; push Pixel updates to field worker devices
Government
Law Enforcement, Courts
Primary threat
Explicitly targeted by 4+ nation-state groups this cycle; UNC6394 POUNDFALL includes 3...
Actions
  • Push Pixel updates to leadership/legal/law enforcement devices; brief hiring managers on DPRK proxy TTPs
Aviation / Logistics
DOT, Port Authorities
Primary threat
OT systems for traffic/port/airport operations; Bransys ELD advisory directly relevant to fleet...
Actions
  • Review Bransys ELD advisory applicability; audit MSP remote access tools for patch status
No sector cards match the selected filters.

Patch ALL Cisco ISE nodes to first-fixed releases; apply iACLs...
Incident Responder
Push the September Pixel security update to state-managed...
Incident Responder
Deploy Orkes Conductor exploitation detection; verify all...
SOC Analyst
No immediate actions for the selected roles.
Inventory all Grafana instances; restrict admin access to...
Incident Responder
Brief IT hiring managers on DPRK proxy interview TTPs; require...
CISO / Exec
Apply the CVE-2026-85921 Windows patch via standard update...
Incident Responder
Enforce phishing-resistant MFA for all privileged accounts...
IAM Analyst
No 7-day actions for the selected roles.
Implement CISA Cyber Decoys guidance - honeypot AD accounts...
SOC Analyst
Resolve intelligence collection gaps - audit OSINT feed health...
CISO / Exec
Conduct a tabletop exercise simulating ransomware against a...
CISO / Exec
Commission an architecture review of Cisco ISE's role as a...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The convergence of a CVSS 10.0 actively exploited vulnerability in network access control, a zero-click mobile surveillance exploit targeting government officials, and expanding North Korean social engineering operations demands immediate action - not next sprint, not next quarter, today. The Cisco ISE deadline is tomorrow. The Pixel deadline is tomorrow. The adversaries documented in this report - APT43, APT42/IRGC-IO, Sandworm, CyberAv3ngers, Kimsuky, UNC6394, Qilin, REvil - are not waiting...

1
Patch Cisco ISE and update Pixel devices before tomorrow's deadline.
2
Brief hiring managers on DPRK proxy interview schemes this week.
3
The threats are specific. The deadlines are real. The actions are clear.
No items found.