TLP:GREEN  ·  States / Public Sector
Your Network's Front Door Is Unlocked:

Critical Network Access Vulnerability Demands Immediate Action

ELEVATED. Maintained from prior cycle, reinforced by active exploitation of a CVSS 10.0 vulnerability in Cisco Identity Services Engine - the network access control backbone for many state agencies - with no available workaround beyond emergency patching. A tracked threat actor launched 8 campaigns deploying backdoors against government worldwide, a Chinese espionage group debuted new tradecraft against Latin American governments, and 14 vulnerabilities in BIND DNS servers threaten state DNS integrity.

I am a
My sector

DevelopmentSignificance
Cisco ISE CVE-2026-76460 (CVSS 10.0) added to CISA...Top priority for any state using ISE for wired/wireless/VPN access...
UNC6394 launched eight simultaneous campaigns deploying the...No confirmed US state victims yet, but volume and targeting profile...
ISC released BIND 9.20.29 patching fourteen security...No workarounds exist for either flaw
ESET published research on FamousSparrow's new SparroWocky...Techniques likely to propagate to other China-nexus actors targeting...

DateEventSeverityRelevance to State Government
Sep 11CISA adds ConnectWise ScreenConnect CVE-2026-84869 (CVSS 9.9) to KEV...CRITICALMSP remote management tool used by state IT vendors
Sep 14CISA adds Cisco Secure Email Gateway CVE-2026-76461 (CVSS 9.8) to KEVCRITICALUnauthenticated root-level RCE on email security appliances
Sep 15Sophos confirms active exploitation of CVE-2026-76461HIGHExploitation confirmed in the wild
Sep 15APT44/Sandworm FEEDUPDATE phishing campaign confirmed targeting...HIGHRussian GRU unit actively targeting government networks
Sep 16Cisco discloses CVE-2026-76460 (CVSS 10.0) in ISE; CISA adds to KEV...CRITICALState network access control system under active attack
Sep 16ISC releases BIND 9.20.29 fixing 14 vulnerabilities including DNSSEC...HIGHState DNS infrastructure directly exposed
Sep 16Qilin/REVENANT SPIDER adds 4 new ransomware victims in a single dayHIGHMost active ransomware operator this quarter; government targeting...
Sep 16CISA publishes cyber decoy deployment guidance for LOTL threat...MEDIUMStrategic guidance for detecting nation-state pre-positioning
Sep 17UNC6394 launches 8 POUNDFALL backdoor campaigns targeting government...HIGHMulti-sector government targeting across 15 countries
Sep 17ESET publishes FamousSparrow SparroWocky backdoor researchMEDIUMChina-aligned espionage tradecraft with government focus
Sep 17Fresh REvil/PINCHY SPIDER and PrivateLoader/HERMIT SPIDER IOCs...HIGHActive ransomware and loader infrastructure confirmed operational

Cisco ISE controls who and what gets on your network. An unauthenticated attacker can exploit an ISE API endpoint for root-level command execution - then delete the logs that would reveal their presence. No workarounds exist; Cisco recommends infrastructure ACLs restricting management API access as an interim measure.

If ISE is...

T1190T1078T1070

Eight distinct campaigns deploying POUNDFALL (also tracked as Evilai/Tamperedchef), a full-featured backdoor providing persistent access, command execution, and exfiltration. Three campaigns explicitly target government; overall targeting spans government, education, healthcare, financial services, telecom, and construction across fifteen...

T1059T1547.001T1071T1041

FamousSparrow deployed a new modular C++ backdoor, SparroWocky, against government organizations in 8 Latin American countries (~90% of targets are government). The tradecraft - DLL side-loading chains, memory-resident execution, Beacon Object File loading, call-stack spoofing - represents the cutting edge of Chinese APT evasion and is likely...

T1574.002T1055T1573.001

BIND 9.20.29 patches 14 flaws - several directly undermine the DNSSEC trust model. CVE-2026-77119 enables cache poisoning via cross-zone NSEC3 acceptance; CVE-2026-19668 allows CPU exhaustion via malicious DNSSEC records. No workarounds exist for either. Cache poisoning could redirect state employees and citizens to attacker infrastructure...

REvil/PINCHY SPIDER infrastructure remains operational with new samples. PrivateLoader (HERMIT SPIDER) continues as an upstream ransomware delivery mechanism - a loader-to-ransomware kill chain, not isolated threats. Qilin/REVENANT SPIDER added 4 new victims in a single day (Ireland, Australia, Belgium), maintaining its position as the most...

T1105T1014T1490T1486

ScenarioProbabilityBasis
Additional Cisco product advisories and exploitation attempts against...HIGH (70%)The coordinated release of ISE, FTD, ASA, and Nexus Dashboard...
UNC6394 POUNDFALL campaigns expand to U.S. government targets within...MODERATE (50%)The actor's 15-country footprint and explicit government focus...
Qilin/REVENANT SPIDER claims a U.S. public sector victim within 7 daysMODERATE (40%)Four victims in a single day demonstrates sustained operational...
Exploitation of BIND DNSSEC bypass vulnerabilities observed in the...MODERATE (35%)Cache poisoning is a high-value capability for both espionage and...
China-nexus actors adopt SparroWocky evasion techniques (DLL...MODERATE (40%)Tradecraft sharing among Chinese APT groups is well-documented. Volt...

Priority 1 — Cisco ISE Compromise Detection:

Hunt hypothesis: An attacker has exploited...

Priority 2 — POUNDFALL Backdoor Activity:

Hunt hypothesis: UNC6394 has established POUNDFALL...

Priority 3 — Living-off-the-Land (Volt Typhoon / Salt Typhoon):

Hunt hypothesis: A nation-state actor has...

Priority 4 — Ransomware Kill Chain:

Hunt hypothesis: PrivateLoader has delivered a REvil...

ThreatATT&CK
Priority 1 — Cisco ISE Compromise DetectionT1190 T1071 T1070...
Priority 2 — POUNDFALL Backdoor ActivityT1547.001 T1059 T1071...
Priority 3 — Living-off-the-Land (Volt Typhoon / Salt Typhoon)T1059.001 T1003.003 T1021...
Priority 4 — Ransomware Kill ChainT1105 T1014 T1490...
IOC Blocking Table:
38.54.57[.]1738.60.197[.]5538.60.209[.]106

Block the above at perimeter firewalls, proxies, and DNS. Additional...

Hunting Hypotheses:
HUNT 01
Priority 1 — Cisco ISE Compromise Detection
An attacker has exploited CVE-2026-76460 to gain root access to an ISE node and is using it as a pivot point for network access manipulation.
HUNT 02
Priority 2 — POUNDFALL Backdoor Activity
UNC6394 has established POUNDFALL persistence on a state endpoint via phishing or exploitation.
HUNT 03
Priority 3 — Living-off-the-Land (Volt Typhoon / Salt Typhoon)
A nation-state actor has pre-positioned on state infrastructure using legitimate tools and is maintaining persistent access without deploying custom malware.
HUNT 04
Priority 4 — Ransomware Kill Chain
PrivateLoader has delivered a REvil payload to a state endpoint, and the attacker is in the pre-encryption reconnaissance phase.

Financial Services
Treasury, Revenue, Pension
Primary threat
UNC6394's POUNDFALL explicitly targets financial services alongside government.
Actions
  • Enhanced logging for new service installations; implement NIST IR 8587 token protection
Energy
Water, Power, Transportation
Primary threat
CyberAv3ngers continues targeting water/wastewater ICS/OT; 5 new ICS advisories published this...
Actions
  • Review Siemens Reyrolle/mySCADA/Wartsila advisories; verify OT/IT segmentation given ISE's role in OT access
Healthcare
Public Health, Medicaid
Primary threat
UNC6394 POUNDFALL targets healthcare alongside government; PHI-processing systems are high-value...
Actions
  • Retrieve REvil/PrivateLoader hashes from ThreatStream; verify EHR backup restoration within RTO
Government
State, County, Municipal
Primary threat
Primary target across multiple vectors this cycle. Cisco ISE is the top priority - treat...
Actions
  • Deploy AD honeytokens per CISA guidance; verify offline backups and IR retainer status
Aviation / Logistics
DOT, Airports, Ports
Primary threats
Broader Cisco infrastructure vulnerabilities (ISE, FTD, ASA) and DNS threats affect transportation...
Actions
  • Inventory Cisco products in transportation networks; verify ScreenConnect patched against CVE-2026-84869
No sector cards match the selected filters.

Patch Cisco ISE for CVE-2026-76460; deploy iACLs restricting...
Incident Responder
Ingest IOC blocklists into EDR and firewalls - FamousSparrow...
SOC Analyst
Create a Cisco ISE SIEM detection rule - alert on...
SOC Analyst
Verify IR readiness - confirm retainer is active and provider...
CISO / Exec
No immediate actions for the selected roles.
Upgrade BIND DNS servers to 9.20.29+; prioritize...
Incident Responder
Apply Cisco FTD, ASA, and Nexus Dashboard patches disclosed...
Incident Responder
Deploy CISA cyber decoys - decoy AD accounts, canary file...
SOC Analyst
Assess Linux fleet for Open vSwitch/Fragnesia exposure; patch...
Incident Responder
No 7-day actions for the selected roles.
Implement NIST IR 8587 token protection for M365/Azure AD...
IAM Analyst
Conduct an architectural review of Cisco ISE deployment...
CISO / Exec
Establish redundant intelligence collection sources to avoid...
CISO / Exec
Formalize a cyber deception program expanding honeytokens...
CISO / Exec
No 30-day actions for the selected roles.
The Bottom Line

The combination of a CVSS 10.0 actively exploited vulnerability in network access control, a multi-campaign government-targeted backdoor operation, and fourteen DNS vulnerabilities with no workarounds demands immediate executive attention. Three decisions cannot wait: approve emergency Cisco ISE patching or authorize iACL deployment within 24 hours; direct your SOC to deploy Active Directory honeytokens this week, since nation-state actors using living-off-the-land techniques evade traditional...

1
Approve emergency Cisco ISE patching within 24 hours.
2
Deploy Active Directory honeytokens this week.
3
Verify incident response readiness today.
No items found.