News

CI Bulletin Vol 2, Issue 11 – July 16, 2026

Florida Critical Infrastructure Cybersecurity Intelligence

This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.

Situational Awareness Bulletin
Cyber Threat Outlook

Florida’s critical infrastructure operators continue to face a threat environment driven by three trends: (1) attackers moving fast on newly disclosed and known-exploited vulnerabilities, (2) cloud identity systems (Microsoft 365, Azure, Entra) becoming a primary target, and (3) AI tools being used on both sides — attackers using AI to write malware and phishing lures faster, and AI development platforms themselves becoming new, unpatched attack surfaces. Over the next six to nine months, expect continued exploitation of CISA-listed vulnerabilities within days of disclosure, more credential-theft campaigns aimed at cloud accounts (including voice-phishing calls that trick employees into approving account changes), and more attacks that target software supply chains — the vendors, code repositories, and AI coding tools organizations rely on rather than the organizations themselves. Because Florida’s critical infrastructure sectors share cloud platforms, collaboration tools, and vendor relationships, the most effective near-term defenses remain the fundamentals: patch known-exploited vulnerabilities quickly, require multi-factor authentication everywhere (configured to cover every login method, not just the main portal), and verify that vendors and subsidiaries are not the weak link.

Confidence Assessment: High

Executive Summary
  • All Sectors: Cyber threat actors relied on three main entry points this period: exploiting internet-facing software before organizations could patch it, reusing stolen administrator passwords from earlier breaches, and tricking employees into running malicious commands through fake error messages or “verify yourself” prompts (a technique called ClickFix, now confirmed spreading to Mac computers as well as Windows). Automated password-guessing attacks against cloud accounts, phone-based social engineering, and destructive malware designed to permanently wipe systems all remained active threats across sectors.
  • Commercial Facilities: Hospitality organizations were targeted with remote-access malware hidden in fake guest-complaint emails, using blockchain infrastructure to keep its control servers moving and hard to block. Separately, the vendor Ubiquiti patched seven critical flaws in its UniFi building-management software — including one with a perfect severity score that lets an attacker on the network take over connected smart lighting and EV-charging systems — so facilities running any UniFi product should update the full lineup, not just one component.
  • Communications: Cisco confirmed that an unauthenticated attacker — someone with no valid login at all — can remotely trigger a flaw in Unified Communications Manager that writes files to the server and can lead to full administrative control. The vulnerability is now on CISA’s list of confirmed exploited vulnerabilities. Because this platform runs voice systems for emergency services, public safety agencies, and healthcare providers, it should be treated as an urgent patch; where immediate patching isn’t possible, disabling the affected WebDialer feature blocks the attack path.
  • Defense Industrial Base: A suspected China-linked group broke into university physics and engineering department mail servers by exploiting known, already-patched flaws in Roundcube webmail software that the schools simply hadn’t updated — a reminder that email servers need the same patching discipline as VPNs and firewalls. Separately, attackers exploited abandoned GitHub developer accounts to clone private code repositories, and researchers disclosed a new way to trick AI coding assistants connected to GitHub into leaking private source code just by asking nicely.
  • Energy: Two unrelated nation-state-linked groups targeted the energy sector using different methods. One group used legitimate cloud storage services (like Zoho WorkDrive) to disguise its malware traffic as normal file-sharing activity. A separate, newly identified group used a Windows shortcut-file vulnerability that Microsoft patched in November 2025 — meaning any organization still exposed to it has gone eight months without applying an available fix.
  • Financial Services: A ransomware attack against a parent company’s network spread into a subsidiary lender’s systems, showing how shared corporate infrastructure can turn one breach into several. Separately, a new low-cost “malware rental” service is letting less-skilled criminals run Android banking malware that steals one-time passcodes and bypasses two-factor authentication on mobile banking apps.
  • Government Services and Facilities: Attackers used firewall administrator credentials stolen in a previous, unrelated breach to break into government network perimeters months later — proof that a credential leak isn’t a closed issue once it’s discovered elsewhere. Because Fortinet firewalls are widely deployed across Florida state and local government, this is a reminder to rotate credentials on a schedule rather than only after a known incident.
  • Information Technology: Attackers moved fast on newly disclosed vulnerabilities in widely used remote-access and web-hosting software, while a separate and growing set of stories involved weaknesses in AI platforms themselves — AI coding assistants tricked into running unauthorized commands, an AI writing platform patched after a flaw let one company’s employee take over another company’s account through a shared preview link, and AI chatbot platforms with gaps that could expose customer data. Software supply-chain attacks — poisoned open-source code packages and hijacked developer accounts — also continued to be a common way in.
  • Transportation Systems: Maritime shipping and logistics organizations were targeted by phishing and business-email-compromise schemes aimed at stealing login credentials. Separately, the U.S. Coast Guard’s annual report found that off-the-shelf AI security tools often failed to catch simulated attacks unless specifically configured for a port’s own network traffic, and flagged unmonitored “dark fleet” vessels using spoofable tracking systems as a growing risk to Florida’s ports.
All Sectors

CISA Adds One Known Exploited Vulnerability to Catalog CISA added CVE-2026-45659, a Microsoft SharePoint Server deserialization-of-untrusted-data vulnerability, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. This vulnerability type is a frequent vector for full server compromise. Florida organizations running on-premises SharePoint Server should apply Microsoft’s patch immediately, and per CISA’s BOD 26-04, should treat internet-facing SharePoint instances as high-priority remediation targets.

FortiBleed Credential Theft Campaign Linked to Lynx Ransomware Cyber threat actors are actively leveraging previously stolen Fortinet administrative credentials to facilitate ransomware intrusions associated with the Lynx operation. Rather than exploiting newly disclosed vulnerabilities, the campaign demonstrates how historical credential theft continues to provide persistent access into enterprise networks months after the initial compromise. Researchers linked stolen credentials from an estimated 430,000 compromised FortiGate firewalls — captured via a custom credential-sniffing tool — to both the INC Ransom and Lynx ransomware operations. Because Fortinet firewalls and Virtual Private Network (VPN) gateways remain widely deployed across Florida government agencies and critical infrastructure sectors, organizations should check FortiGate devices for a local account named ‘adminin,’ a known indicator of compromise, in addition to rotating credentials and enforcing MFA.

Veil#Drop Uses Google Blogspot to Deliver PureLog Stealer Researchers identified Veil#Drop, a fileless malware delivery framework that abuses Google Blogspot pages to deploy the PureLog credential stealer entirely in memory. The campaign minimizes traditional malware artifacts by relying on malicious JavaScript and PowerShell execution to harvest credentials and evade conventional antivirus detection. Because credential theft campaigns affect every critical infrastructure sector, Florida organizations should strengthen endpoint detection capabilities, monitor for anomalous browser and PowerShell activity, and restrict execution of untrusted scripts to reduce enterprise risk.

ClickFix Becomes Cybercriminals’ Favorite Initial Access Technique Cyber threat actors continue adopting the ClickFix social engineering technique to trick users into manually executing malicious commands that bypass traditional endpoint protections. Rather than exploiting software vulnerabilities, the campaign relies on user interaction through trusted operating system interfaces to initiate compromise. ReliaQuest specifically notes that ClickFix has expanded to macOS for the first time via a fake Script Editor prompt, and states plainly that “macOS must no longer be treated as lower risk. Because this technique targets human behavior rather than technical weaknesses, Florida CI organizations should extend ClickFix user-awareness training and command-line monitoring to macOS endpoints, not just Windows.

GigaWiper Combines Multiple Malware Families for System-Level Sabotage Researchers identified GigaWiper, a destructive malware platform that combines backdoor functionality with data-wiping capabilities to maximize operational disruption following a successful compromise. Unlike traditional ransomware, destructive malware seeks to permanently disable systems and hinder recovery efforts rather than generate financial gain. Because destructive malware poses a severe threat to government, energy, manufacturing, and other critical infrastructure sectors in Florida, organizations should validate offline backups, strengthen endpoint protections, and routinely exercise business continuity and disaster recovery procedures.

BlueHammer Vulnerability Exploited in Ransomware Attacks Microsoft Defender vulnerability CVE-2026-33825, known as BlueHammer, has been exploited in ransomware attacks after initially being used as a zero-day before Microsoft released patches. The authenticated privilege-escalation flaw was publicly disclosed on April 02, 2026, patched on April 14, 2026, and later added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities Catalog. Although the specific ransomware group remains unidentified, successful exploitation could allow an attacker with existing access to obtain elevated privileges and advance an intrusion. Florida critical infrastructure operators using Microsoft Defender should verify that April 2026 security updates were deployed and investigate endpoints for evidence of prior compromise.

Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts Between June 12 and June 26, 2026, an automated password-spraying campaign generated more than 81 million login attempts against Microsoft’s Azure Command-Line Interface (CLI), compromising at least 78 accounts across 64 organizations. The campaign used previously breached credentials and a deprecated OAuth authentication flow to bypass inadequately configured Conditional Access and multifactor authentication policies. Because Microsoft cloud services support organizations across every critical infrastructure sector in Florida, operators should enforce multifactor authentication for all users, applications, and client types, restrict unnecessary Azure CLI access, rotate exposed credentials, and monitor activity originating from the identified LSHIY LLC IPv6 range.

GodDamn Ransomware Uses PoisonX Driver to Disable EDR Before Encryption Cybersecurity researchers identified a new ransomware variant, known as GodDamn, that employs the PoisonX kernel driver to disable endpoint detection and response (EDR) solutions before encrypting victim systems. By abusing a signed kernel-mode driver, the malware can bypass security controls, terminate defensive processes, and significantly reduce an organization’s ability to detect or stop ransomware activity during the early stages of an attack. This technique demonstrates the continued evolution of ransomware groups toward more sophisticated defense-evasion capabilities targeting enterprise environments. Because organizations across all Florida critical infrastructure sectors rely on EDR platforms to detect and respond to cyber threats, defenders should validate kernel driver integrity, monitor for unauthorized driver loading, implement tamper protection for security software, and investigate attempts to disable endpoint protection prior to ransomware deployment.

Entra Passkey Enrollment Vishing Targets Microsoft 365 Users Researchers identified an active voice-phishing (vishing) campaign, tracked as O-UNC-066 (‘Pink’), targeting Microsoft 365 users since April 2026. Attackers impersonate IT support and direct victims to a fake Entra passkey-enrollment site, using the enrollment process itself as a distraction while registering an attacker-controlled passkey on the victim’s real account. Florida organizations should strengthen help desk identity verification procedures and deny access requests from locations where the organization does not operate. Because Okta reports that this actor moves quickly to exfiltrate data from SharePoint and OneDrive after account takeover, organizations should also review SharePoint and OneDrive access logs for unusual activity following any suspected passkey enrollment incident.UNK

Writer AI Flaw Could Let Agent Previews Take Over Enterprise AI Platforms Security researchers disclosed a critical vulnerability known as WriteOut affecting the Writer enterprise artificial intelligence (AI) platform. The flaw could allow attackers to exploit agent preview functionality to execute unauthorized actions, compromise cross-tenant environments, and potentially gain control of organizational AI workspaces. The research highlights the growing security risks associated with enterprise AI platforms as organizations increasingly integrate generative AI into business operations. Because Writer has already deployed a fix, Florida organizations using the Writer AI platform should confirm with their account team that the patch is applied to their tenant, review AI platform session and access logs for the period before disclosure, and audit AI agent permission models generally, since this is the second cross-tenant AI-platform flaw reported this cycle.

Foxit Patches PDF Reader/Editor Vulnerabilities Foxit released security updates addressing multiple vulnerabilities affecting Foxit PDF Reader and Foxit PDF Editor, including flaws that could allow remote code execution, information disclosure, and application crashes if a user opens a specially crafted PDF document. Successful exploitation could enable attackers to execute arbitrary code with the logged-in user’s privileges, making malicious PDF files an effective delivery mechanism for malware and other cyber threats. Because PDF documents remain one of the most common file formats exchanged across government, healthcare, financial services, education, and private industry, unpatched vulnerabilities present a broad risk to organizations across all critical infrastructure sectors. Florida organizations should promptly apply Foxit security updates, restrict the execution of untrusted PDF files, educate users on the risks of opening unsolicited email attachments, and monitor endpoints for suspicious activity associated with malicious document exploitation.

CISA Adds Three Known Exploited Vulnerabilities to Catalog The Cybersecurity and Infrastructure Security Agency (CISA) added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, including flaws affecting JoomShaper, Langflow, and other internet-facing technologies used in government and commercial environments. CISA directed organizations to prioritize remediation of CVE-2026-48908, CVE-2026-55255, and CVE-2026-56290, emphasizing that confirmed in-the-wild exploitation significantly increases the risk of remote system compromise. The advisory reinforces the importance of prioritizing vulnerability management based on active exploitation rather than severity scores alone. Because organizations across all Florida critical infrastructure sectors rely on internet-facing web applications and artificial intelligence development platforms, administrators should immediately apply vendor patches, review exposed systems for indicators of compromise, and prioritize remediation of all vulnerabilities listed in the CISA KEV Catalog.

New Oracle E-Business Suite Flaw Now Exploited in Attacks Researchers warned that cyber threat actors are actively exploiting a newly disclosed vulnerability affecting Oracle E-Business Suite, specifically the Oracle Payments component. The unauthenticated flaw, tracked as CVE-2026-46817, could allow remote attackers to compromise exposed systems by exploiting the file-transmission component over Hypertext Transfer Protocol (HTTP), potentially resulting in unauthorized access to enterprise financial and business operations. Because Oracle E-Business Suite supports finance, procurement, and business management functions across government agencies and private-sector organizations, successful exploitation could significantly disrupt critical business processes. Florida organizations using Oracle E-Business Suite should immediately apply Oracle’s security updates, restrict external access to vulnerable services, review Oracle Payments environments for signs of compromise, and continuously monitor application logs for unauthorized activity.

Multiple Cyberattacks Disrupt Major Japanese Critical Infrastructure Organizations Multiple major Japanese organizations spanning the financial services, communications, critical manufacturing, and food and agriculture sectors experienced significant cyber incidents during the reporting period, including ransomware attacks, data breaches, and operational disruptions affecting Aflac, KDDI, Nidec, and Sapporo. The campaign includes a confirmed ransomware/extortion attack on Nidec’s Taiwanese subsidiary (BlackField group, approximately $2 million demanded), a third-party software vulnerability at KDDI that exposed email accounts for five partner internet service providers, and suspected unauthorized access incidents at Aflac Japan and Sapporo’s overseas subsidiaries. Collectively, the incidents demonstrate how attacks against third-party software, enterprise networks, and shared technology platforms can simultaneously affect multiple critical infrastructure sectors. The concentration of high-profile compromises underscores the continued threat posed by ransomware groups, software supply chain weaknesses, and interconnected business systems supporting essential services. Because Florida critical infrastructure operators maintain similar interdependent technology environments and third-party relationships, organizations should strengthen supply chain risk management, validate ransomware recovery capabilities, monitor vendors for security incidents, and continuously assess interconnected business systems for potential cascading cyber risks.

CrownX Ransomware Uses Avalon Malware Framework to Target Enterprise Networks Cybersecurity researchers identified a new ransomware operation that uses the Avalon malware framework to deploy the CrownX ransomware payload through a sophisticated multi-stage infection chain. The campaign relies on phishing emails disguised as legal or business-related documents to deliver modular malware capable of establishing persistence, evading detection, and ultimately encrypting victim systems. Avalon specifically searches for and targets backup and recovery infrastructure (Veeam, Acronis, NetApp, Synology, Hyper-V, vCenter) before deploying ransomware, and disables Windows Volume Shadow Copy to prevent recovery. Researchers observed fileless execution techniques and staged payload delivery designed to complicate detection and incident response. Because phishing remains one of the primary initial access vectors across every critical infrastructure sector, Florida organizations should strengthen email security controls, educate employees to recognize legal-themed phishing lures, monitor for suspicious PowerShell and script execution, and ensure backup infrastructure is on a segmented network with credentials that are not reusable from the general Windows domain.

Kazuar Backdoor Uses DLL Side-Loading to Evade Detection Cybersecurity researchers observed the Turla advanced persistent threat (APT) group reviving its Kazuar backdoor through a sophisticated DLL side-loading technique that enables malware to execute within trusted Windows processes while evading traditional security controls. The campaign also leverages PowerShell-based execution and trusted host processes to establish persistence and reduce the likelihood of detection during post-compromise operations. The renewed use of Kazuar demonstrates the continued evolution of nation-state tradecraft targeting enterprise and government networks through stealthy, persistent mechanisms. Because state-sponsored actors routinely target organizations across Florida’s critical infrastructure sectors, defenders should monitor for unauthorized DLL side-loading activity, investigate anomalous PowerShell execution, validate application integrity, and strengthen endpoint detection capabilities to identify advanced persistence techniques before attackers can establish long-term access.

Phishing Poses as Big Brand Job Interview to Steal Google Accounts Cybersecurity researchers identified a widespread phishing campaign that impersonates well-known companies through fraudulent job interview invitations to steal Google account credentials. The attackers abuse trusted cloud services, including PeopleForce and Salesforce Marketing Cloud, to distribute convincing phishing emails that bypass traditional email filtering and create a false sense of legitimacy. Victims who follow the embedded links are directed to counterfeit authentication pages designed to harvest Google account credentials and facilitate account takeover. Because organizations across Florida’s critical infrastructure sectors rely extensively on cloud-based productivity and collaboration platforms, organizations should strengthen phishing awareness training, verify the legitimacy of unsolicited employment-related communications, enforce phishing-resistant multi-factor authentication (MFA), and continuously monitor authentication logs for suspicious login attempts and unauthorized account activity.

China-Linked UAT-7810 Expands ORB Network Using SHORTLEASH Malware Cybersecurity researchers identified an active campaign by the China-linked threat group UAT-7810 to expand operational relay box (ORB) networks using custom malware known as SHORTLEASH. By compromising internet-facing systems and converting them into proxy infrastructure, the group can conceal the origin of later espionage operations and route malicious traffic through seemingly legitimate organizations. This activity increases the risk that compromised infrastructure will be used to support secondary attacks against government, defense, and other critical targets. Florida critical infrastructure operators should patch internet-facing systems promptly, monitor for SHORTLEASH indicators and unexplained proxy traffic, investigate unusual outbound connections, and prevent compromised devices from being used as relay infrastructure for nation-state operations.

All Sectors Recommendations:

  • Apply vendor security patches for known exploited vulnerabilities and enterprise web software immediately.
  • Enforce phishing-resistant multi-factor authentication across all cloud, single sign-on, and remote management portals.
  • Verify the behavioral integrity of endpoint processes and restrict command-line execution for unprivileged accounts.
  • Validate immutable offline configuration backups to guarantee operational resilience against destructive data-wiping malware.
Chemical Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

Commercial Facilities Sector

Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails Beginning in late May 2026, cyber threat actors targeted Booking.com partner hotels in Japan with phishing emails that impersonated guest complaints and review requests. The messages directed employees to download a ZIP file containing a malicious shortcut that launched a multi-stage PowerShell infection and installed the Node.js-based TONResolver remote access trojan. TONResolver uses the Open Network blockchain to retrieve changing command-and-control infrastructure, enabling remote command execution, persistence, and follow-on credential theft. Because Florida’s hospitality sector relies heavily on online booking platforms, operators should treat unexpected guest-complaint links as high risk, restrict unauthorized execution of PowerShell and Node.js, and monitor endpoints for suspicious LNK files, WebSocket traffic, and blockchain-related communications.

Ubiquiti Warns of New Max Severity UniFi OS Vulnerability On July 8, 2026, Ubiquiti released security updates addressing seven critical vulnerabilities in UniFi OS, including CVE-2026-50746, a maximum-severity command-injection flaw affecting UniFi Connect Application versions 3.4.16 and earlier. Ubiquiti also patched six additional critical-severity flaws (CVSS 9.0–9.9) affecting UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS Server; commercial facilities running any UniFi product line should update the full stack, not just UniFi Connect. The UniFi Connect software is used to manage commercial building operations such as smart lighting and electric vehicle chargers, and exploitation requires network access to the affected environment. Ubiquiti advised customers to update UniFi Connect to version 3.4.20 or later. Because Florida commercial facilities increasingly rely on connected building management systems, operators should identify affected deployments, apply the update, restrict management access, and monitor for unauthorized configuration changes.

Commercial Facilities Sector Recommendations:

  • Train hospitality staff to verify unsolicited guest complaints before opening attachments or compressed shortcuts.
  • Apply the July 2026 security updates to UniFi Connect applications to remediate command injection flaws.
  • Isolate connected building automation systems and smart charging networks behind segmented firewall boundaries.
Communications Sector

Cisco Confirms In-the-Wild Exploitation of Unified CM Vulnerability Cisco confirmed that cyber threat actors are actively exploiting CVE-2026-20230, a high-severity server-side request forgery (SSRF) vulnerability (CVSS 8.6) in Cisco Unified Communications Manager. An unauthenticated, remote attacker can send a crafted request to write files to the underlying operating system, which can then be used to escalate to root-level access. The flaw has been added to CISA’s Known Exploited Vulnerabilities Catalog. Exploitation requires the WebDialer service to be enabled (disabled by default); operators unable to patch immediately should disable WebDialer as an interim mitigation.

Communications Sector Recommendations:

  • Patch Cisco Unified Communications Manager environments immediately to address active, high-severity command execution flaws.
  • Audit gateway event logs to detect unauthorized system modifications or atypical terminal connection requests.
  • Incorporate critical emergency communication infrastructure and voice network dependencies into organizational continuity testing.
Critical Manufacturing Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

Dams Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

Defense Industrial Base Sector

One Email Closer to the Edge: UNK_MassTraction Targets Academic Research Networks Proofpoint identified a suspected China-aligned threat cluster, tracked as UNK_MassTraction, exploiting known, already-patched vulnerabilities in Roundcube webmail software (CVE-2024-42009, CVE-2025-49113) to compromise mail servers at U.S. and Canadian university physics and engineering departments since May 2026, focused on institutions with national-security-relevant or astrophysics/particle-physics research. Attackers steal credentials and deploy a web shell or the VShell backdoor. Because Florida’s universities, aerospace companies, and defense contractors collaborate extensively on federally funded research and national security programs, Defense Industrial Base organizations should patch Roundcube webmail servers to the latest version and remove legacy installations immediately — this is the confirmed entry point in this campaign.

Indra Group Ransomware Attack Puts Sensitive Data at Risk Spanish defense contractor Indra Group disclosed a ransomware attack attributed to the Gentlemen ransomware group, which claimed to have exfiltrated sensitive corporate data and threatened to publish the information if ransom demands were not met. Although the incident did not reveal novel exploitation techniques, it highlights the ongoing targeting of major defense contractors by ransomware and data extortion operations. The compromise underscores the importance of protecting sensitive defense-related information and maintaining resilient business operations against increasingly sophisticated cybercriminal groups. Because Florida hosts a significant concentration of defense, aerospace, and military contractors, organizations should validate ransomware recovery plans, strengthen network segmentation, monitor for unauthorized data exfiltration, and assess third-party supply chain security to reduce operational and national security risks.

Dormant GitHub Accounts Help Attackers Clone Private Repositories Researchers identified a campaign in which cyber threat actors exploited dormant GitHub accounts to gain unauthorized access to private repositories and organizational development environments. By leveraging inactive or abandoned accounts, attackers were able to enumerate repositories, clone proprietary source code, and collect sensitive development data without immediately attracting attention. The campaign highlights the importance of identity governance within software development platforms, particularly where inactive accounts retain unnecessary access privileges. Because Florida’s defense, aerospace, and technology organizations rely heavily on GitHub for collaborative software development, organizations should regularly audit dormant accounts, enforce least-privilege access controls, require multi-factor authentication, and monitor repository activity for unauthorized cloning or anomalous access patterns.

GitHub AI Agent Leaks Private Repositories When Asked Nicely (GitLost) Security researchers disclosed a prompt-injection vulnerability known as GitLost, which could allow untrusted content in GitHub issues or comments to manipulate artificial intelligence agents connected to private repositories. An attacker could use crafted instructions to cause an overly privileged AI agent to retrieve and expose proprietary source code or other sensitive repository information without directly compromising a developer account. The finding demonstrates how AI agents integrated into software development and continuous integration/continuous deployment environments can create new paths for the software supply chain and intellectual property theft. Florida defense contractors and aerospace organizations should enforce least-privilege permissions for AI agents, sanitize untrusted issue and comment content, restrict agent access to private repositories, and monitor repositories for unauthorized cloning, data retrieval, or disclosure activity.

China-Nexus Actor Spies on US Researchers Undetected for a Year The Google Threat Intelligence Group (GTIG) disclosed that UNC6508, a China-nexus cyber threat actor, conducted a year-long cyber espionage campaign against North American medical and military research institutions. The attackers exploited externally facing Research Electronic Data Capture (REDCap) servers to deploy custom malware named INFINITERED. This malware captured credentials, enabling lateral movement and the covert exfiltration of advanced defense technology and medical data. Furthermore, attackers are spoofing recruitment portals for targeted social engineering. This sustained espionage campaign directly threatens Florida’s extensive defense industrial base and academic medical centers, highlighting the critical exposure of vulnerable research applications.

Defense Industrial Base Sector Recommendations:

  • Revoke inactive development profiles and continuously monitor source code repositories for automated access anomalies.
  • Restrict connected generative artificial intelligence assistants to low-privilege environments and sanitize untrusted user comments.
  • Audit public-facing research application servers for web shells and enforce code provenance checks across pipelines.
Emergency Services Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

Energy Sector

Mustang Panda Targets India’s Government and Energy Sectors Researchers identified a cyber espionage campaign by the China-linked cyber threat group Mustang Panda targeting government agencies and energy organizations in India. The campaign employed SHARDLOADER to establish initial access and MINIRECON to conduct reconnaissance while abusing legitimate cloud services, including Zoho WorkDrive, to stage malicious payloads and obscure command-and-control communications. The use of trusted cloud platforms demonstrates the continued evolution of state-sponsored tradecraft designed to evade traditional security controls. Because Florida’s electric utilities and energy operators rely on cloud-based collaboration and administrative services, organizations should monitor for unauthorized use of trusted cloud platforms, strengthen endpoint detection capabilities, and review network activity for indicators of reconnaissance or persistence associated with advanced persistent threat (APT) operations.

New APT Group Targets Power Grids in Three Countries With AI-Crafted Malware Researchers identified a newly tracked advanced persistent threat (APT) group, Armored Likho, conducting cyber espionage operations against electric power providers and government organizations in multiple countries. The campaign deployed the AI-assisted BusySnake information-stealing malware while exploiting CVE-2025-9491 to gain initial access and establish persistence within targeted environments. The activity demonstrates the continued evolution of nation-state tradecraft targeting critical energy infrastructure through advanced malware and stealthy persistence mechanisms. Because Florida’s electric utilities and energy providers operate essential infrastructure that supports public safety and economic stability, organizations should promptly remediate known vulnerabilities, monitor scheduled tasks and endpoint activity for indicators of compromise, and strengthen detection capabilities to detect advanced persistent threat activity targeting operational and enterprise networks.

Energy Sector Recommendations:

  • Harden perimeter gateways against advanced persistent threat actors targeting power grid routing infrastructure.
  • Monitor commercial cloud synchronization utilities for anomalous data collection patterns or payload staging attempts.
  • Isolate internal energy management operations from administrative corporate networks using strict network segmentation rules.
Financial Services Sector

Billion-Dollar Lender Suffers Data Breach, Warns Unauthorized Threat Actor Launched Ransomware Attack A U.S. financial institution disclosed that an unauthorized cyber threat actor launched a ransomware attack against its parent company’s network, potentially exposing sensitive customer information and disrupting business operations. Although investigators continue assessing the full scope of the incident, the breach highlights how compromises affecting parent organizations can cascade into subsidiary financial institutions through shared infrastructure and interconnected business systems. Because Florida’s financial institutions frequently rely on centralized corporate networks and shared technology services, organizations should review network segmentation between parent and subsidiary environments, strengthen ransomware preparedness, and continuously monitor for unauthorized access and potential data exfiltration across interconnected systems.

RedWing MaaS Packages Android Banking Trojan With 2FA Interception Security researchers identified RedWing, a new Android Malware-as-a-Service (MaaS) platform that enables cybercriminals to deploy banking malware capable of credential theft, intercepting one-time passwords (OTPs), and bypassing two-factor authentication (2FA). By lowering the technical barrier to entry, the service allows less-skilled cyber threat actors to conduct sophisticated financial fraud campaigns against mobile banking users. The malware also supports remote device control and credential harvesting, increasing the likelihood of account compromise. Because financial institutions and their customers increasingly rely on mobile banking applications, Florida organizations should strengthen mobile device management (MDM) policies, educate users about the risks of sideloading applications, monitor for suspicious authentication activity, and encourage the use of phishing-resistant authentication methods where available.

Financial Services Sector Recommendations:

  • Review network segmentation points connecting parent architectures to local financial infrastructure to prevent cascading compromises.
  • Enforce robust mobile device management settings to block untrusted application sideloading on corporate hardware.
  • Audit single sign-on logs for anomalous session tracking markers indicating multi-factor authentication bypass attempts.
Food and Agriculture Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

Government Services and Facilities Sector

Hackers Breach Foreign Office Systems Using Stolen Fortinet Credentials The United Kingdom’s Foreign, Commonwealth & Development Office and multiple local government organizations experienced unauthorized access after cyber threat actors used previously stolen Fortinet firewall credentials to compromise government systems. The incident demonstrates how administrative credentials stolen during earlier campaigns can continue to provide attackers with access to sensitive government networks long after the initial compromise. Because Fortinet appliances are widely deployed across Florida state agencies and local governments, organizations should immediately audit firewall administrative accounts, rotate exposed or legacy credentials, enforce multi-factor authentication (MFA), and monitor for unauthorized remote access attempts associated with compromised perimeter devices.

Government Services and Facilities Sector Recommendations:

  • Rotate perimeter firewall administrative credentials immediately to mitigate exposure from legacy data leaks.
  • Enforce multi-factor authentication requirements strictly across all privileged remote access and virtual private networks.
  • Review security logs for unauthorized configuration adjustments on edge defense appliances or internet-facing gateways.
Healthcare and Public Health Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

Information Technology Sector

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer Cybersecurity researchers identified two hijacked npm packages and 16 compromised Go packages designed to infect Windows, Linux, and macOS developer systems. The malware hides execution inside a Microsoft Visual Studio Code task that activates when a trusted project folder is opened, retrieves encrypted JavaScript through blockchain transaction data, establishes a Socket.io backdoor, and deploys a Python information stealer. The campaign targets browser credentials, password managers, cloud tokens, GitHub data, cryptocurrency wallets, and developer artifacts. Florida organizations should remove affected packages, inspect developer systems for hidden folder-open tasks, and rotate potentially exposed credentials, tokens, application programming interface keys, and cloud secrets.

Critical Dell Wyse Management Suite Vulnerabilities Could Let Attackers Compromise Systems Multiple critical vulnerabilities were identified in Dell Wyse Management Suite (WMS) that could allow attackers to compromise enterprise thin-client management environments through remote exploitation. The flaws affect the software used to administer Dell thin clients centrally and, if left unpatched, could grant attackers elevated privileges and unauthorized control over managed endpoints. Because Wyse Management Suite is commonly deployed to manage enterprise endpoint infrastructure across government, healthcare, education, and commercial environments, successful exploitation could disrupt centralized device management and expose sensitive enterprise systems. Florida organizations using Dell Wyse Management Suite should immediately apply the latest security updates, restrict administrative access to management servers, monitor for unauthorized administrative activity, and review endpoint management systems for indicators of compromise.

Critical SimpleHelp Vulnerability Exploited for Malware Delivery Security researchers confirmed that cyber threat actors are actively exploiting CVE-2026-48558, a critical authentication-bypass vulnerability affecting SimpleHelp Remote Monitoring and Management (RMM) software, to deliver the Djinn Stealer malware. Successful exploitation allows attackers to forge OpenID Connect identity tokens, bypass authentication, and compromise managed systems through trusted remote administration infrastructure. Because SimpleHelp and similar RMM platforms are widely used by managed service providers supporting critical infrastructure, a successful compromise can provide attackers with broad access across multiple client environments. Florida organizations should immediately apply vendor security updates, monitor RMM servers for unauthorized authentication events, investigate suspicious OpenID Connect token activity, and review managed endpoints for indicators of Djinn Stealer infection.

Adobe Patches Seven Max-Severity ColdFusion Vulnerabilities Adobe released security updates addressing seven maximum-severity vulnerabilities affecting ColdFusion and Adobe Campaign Classic, including flaws that could allow pre-authentication remote code execution with minimal attacker interaction. Researchers observed active threat interest in these vulnerabilities, prompting Adobe to recommend Priority 1 patching within 72 hours for affected systems. Because ColdFusion continues to support enterprise web applications across government, education, healthcare, and commercial organizations, exploitation could provide attackers with an initial foothold into critical business environments. Florida organizations should immediately apply Adobe security updates, identify internet-facing ColdFusion servers, restrict unnecessary external access, and monitor web application logs for indicators of attempted exploitation.

Progress Kemp LoadMaster Flaw Could Let Attackers Execute Commands Remotely Researchers warned that cyber threat actors are actively exploiting CVE-2026-8037, a pre-authentication command injection vulnerability affecting Progress Kemp LoadMaster load balancers following the public release of proof-of-concept exploit code. Successful exploitation could enable attackers to execute arbitrary commands on vulnerable devices, granting unauthorized access to enterprise network infrastructure at the perimeter of critical environments. Because LoadMaster appliances are widely deployed to manage traffic across enterprise applications and critical infrastructure services, Florida organizations should immediately apply vendor security updates, restrict access to management interfaces, review administrative logs for suspicious requests, and continuously monitor perimeter devices for indicators of compromise.

Phantom Squatting: Hallucinated Web Domains Target AI-Assisted Developers Palo Alto Networks Unit 42 researchers identified a new supply chain threat known as Phantom Squatting, in which cyber threat actors register internet domains generated by artificial intelligence (AI) hallucinations to deceive developers using AI coding assistants. When AI tools reference nonexistent software packages, repositories, or websites, attackers can register those domains and distribute malicious code or phishing content to unsuspecting users. The technique exploits trust in AI-generated recommendations rather than software vulnerabilities, creating a new attack vector against software development environments. Because Florida government agencies, defense contractors, and technology organizations increasingly rely on AI-assisted development tools, they should validate AI-generated package references, verify repository authenticity before downloading software, monitor newly registered domains that resemble development resources, and implement software supply chain verification practices throughout development pipelines.

JADEPUFFER: First Agentic Ransomware Operation Targets Langflow AI Servers Security researchers identified JADEPUFFER, the first documented autonomous, agentic ransomware operation capable of conducting multiple stages of an attack with minimal human intervention. The campaign targets internet-exposed Langflow artificial intelligence middleware, allowing attackers to gain initial access, automate reconnaissance, execute malicious actions, and deploy ransomware through AI-assisted workflows. The emergence of autonomous ransomware represents a significant evolution in cyber threat capabilities by reducing attacker workload and accelerating intrusion timelines. Because Florida organizations are increasingly integrating AI development platforms into enterprise environments, they should identify and secure exposed Langflow instances, promptly apply vendor security updates, restrict unnecessary internet exposure, and continuously monitor AI infrastructure for indicators of unauthorized access and malicious automation activity.

New ChocoPoC RAT Targets Vulnerability Researchers Through Fake GitHub Exploits Cybersecurity researchers identified a new remote access trojan (RAT) known as ChocoPoC, which targets security researchers, vulnerability analysts, and DevSecOps personnel by embedding malware within fraudulent GitHub proof-of-concept repositories. Rather than exploiting software vulnerabilities directly, attackers rely on trusted research workflows to convince users to execute malicious code disguised as legitimate exploit demonstrations. Once installed, the malware enables credential theft, remote access to systems, and delivery of additional payloads while compromising systems used for vulnerability research. Because Florida government agencies, managed service providers, defense contractors, and enterprise security teams routinely evaluate proof-of-concept exploit code, organizations should isolate malware testing environments, verify repository authenticity before execution, restrict the use of untrusted code on production systems, and monitor developer workstations for suspicious outbound connections and unauthorized access to credentials.

Citrix Patches NetScaler Vulnerabilities Including New HTTP/2 Bomb Attack Citrix released security updates addressing multiple high-severity vulnerabilities affecting NetScaler ADC and NetScaler Gateway, including protections against the newly identified HTTP/2 Bomb denial-of-service attack. The vulnerabilities, including CVE-2026-10816 and CVE-2026-8451, could allow attackers to exhaust system resources, disrupt remote access services, or trigger memory-related failures in internet-facing appliances. Because NetScaler products are widely deployed to provide secure remote access across government agencies, healthcare organizations, educational institutions, and commercial enterprises, successful exploitation could significantly impact critical business operations. Florida organizations should immediately apply Citrix security updates, review internet-facing NetScaler deployments, monitor gateway logs for unusual HTTP/2 traffic and denial-of-service activity, and validate remote access resilience as part of business continuity planning.

FBI Warns TeamPCP Targets Software Supply Chains and Cloud Secrets The Federal Bureau of Investigation (FBI) issued a FLASH advisory warning that the TeamPCP cybercriminal group is conducting large-scale software supply chain attacks targeting developers and organizations supporting critical infrastructure. The campaign focuses on stealing cloud access tokens, Secure Shell (SSH) keys, Kubernetes secrets, and application programming interface (API) credentials to compromise development environments and enable lateral movement across enterprise cloud infrastructure. By targeting trusted software development and continuous integration/continuous deployment (CI/CD) pipelines, TeamPCP increases the risk of downstream compromises affecting multiple organizations. Because Florida’s defense contractors, government agencies, and technology providers rely heavily on cloud-native development environments, organizations should secure cloud credentials, rotate exposed access tokens and SSH keys, implement least-privilege access controls, and continuously monitor CI/CD pipelines for unauthorized access to credentials and suspicious repository activity.

Cavern Manticore: Exposing an Iran-Linked Modular C2 Framework Check Point Research identified Cavern Manticore, an Iran-linked advanced persistent threat (APT) campaign employing a highly modular command-and-control (C2) framework designed to target information technology providers and government networks. The operation incorporates mixed-mode C++/CLI and .NET Native AOT compilation techniques to improve stealth, evade traditional detection methods, and maintain persistent access within compromised environments. Researchers observed sophisticated modular tooling that enables flexible payload deployment and long-term espionage operations against enterprise networks. Because information technology providers frequently serve as trusted partners supporting Florida government agencies and critical infrastructure organizations, defenders should monitor for anomalous compilation artifacts, reconstruct metadata during malware analysis, strengthen endpoint detection capabilities, and investigate suspicious command-and-control communications indicative of state-sponsored activity.

Hackers Can Use 9 of the Most Popular AI Tools to Assemble Massive Botnets Security researchers demonstrated a new attack technique known as HalluSquatting, in which cyber threat actors exploit hallucinations generated by artificial intelligence (AI) coding assistants to distribute malicious software and assemble large-scale botnets. By exploiting AI-generated references to nonexistent software packages and repositories, attackers can register fraudulent resources that developers may unknowingly trust and install. The research highlights how AI-assisted development workflows can introduce software supply chain risks without exploiting traditional software vulnerabilities. Because Florida government agencies, defense contractors, and technology organizations are increasingly integrating AI-assisted development tools into their software engineering processes, organizations should validate AI-generated package references, verify repository authenticity before installation, implement software supply chain controls, and require human review of AI-generated code recommendations.

Dialogflow CX Rogue Agent Flaw Enabled AI Chatbot Data Theft Security researchers disclosed a critical “Rogue Agent” vulnerability affecting Google Dialogflow CX, demonstrating how improperly secured AI chatbot environments could be manipulated to execute unauthorized code, maintain persistence, and facilitate data theft. The flaw exploits weaknesses in permission boundaries and conversational AI workflows, allowing attackers to inject malicious logic into enterprise chatbot environments and potentially access sensitive organizational information. As AI-powered customer service and automated business applications become more common, weaknesses in conversational AI platforms present an expanding enterprise attack surface. Because Florida government agencies, healthcare organizations, financial institutions, and private-sector critical infrastructure operators increasingly rely on AI-driven customer interaction platforms, organizations should review Dialogflow CX deployments, validate permission boundaries, implement strict input validation, and continuously monitor AI agents for unauthorized code execution and abnormal data access.

Critical Gitea Flaw Under Active Exploitation, Researchers Warn Security researchers warned that cyber threat actors are actively exploiting CVE-2026-20896, a critical vulnerability (CVSS 9.8) affecting Gitea, a widely used self-hosted Git repository management platform. Successful exploitation could enable attackers to remotely compromise vulnerable Gitea instances, granting unauthorized access to source code repositories and the development infrastructure that supports enterprise software development and CI/CD operations. Because many organizations rely on self-hosted code repositories to manage proprietary software and operational technology projects, exploitation could lead to intellectual property theft and compromise of the software supply chain. Florida organizations using Gitea should immediately apply the latest security updates, restrict administrative access through source IP allowlisting, review repository activity for unauthorized access, and monitor development infrastructure for indicators of compromise.

AI Coding Tools Tricked into Hacking Developer Machine via Decades-Old Technique Security researchers demonstrated a new attack technique known as GhostApproval, showing how widely used AI coding assistants—including Claude, Cursor, and Amazon Q Developer—can be manipulated through a long-standing symbolic link (symlink) vulnerability to perform unauthorized actions on a developer’s workstation. By exploiting weaknesses in file approval workflows, attackers can deceive AI coding tools into modifying or accessing unintended files, potentially leading to remote code execution and compromise of development environments. The research highlights emerging risks associated with integrating AI assistants into software development workflows without sufficient security controls. Because Florida’s technology companies, government agencies, and defense contractors increasingly rely on AI-assisted software development, organizations should promptly apply vendor security updates, audit AI coding assistant permissions, strengthen sandbox protections, and require human validation of file operations initiated by AI development tools.

Threat Actor Uses Agentic AI to Compromise AWS Cloud in 72 Hours Security researchers analyzed a real-world attack in which a single cyber threat actor used agentic artificial intelligence (AI) tools to compromise an Amazon Web Services (AWS) cloud environment in approximately 72 hours. The incident demonstrated how AI-assisted automation can dramatically accelerate reconnaissance, privilege escalation, and lateral movement within cloud infrastructures, reducing the time required to compromise enterprise environments. Researchers noted that the attack highlighted the growing capability of AI to enhance offensive cyber operations rather than introducing new software vulnerabilities. Because Florida government agencies, critical infrastructure operators, and private-sector organizations increasingly rely on AWS cloud services, organizations should strengthen identity and access management (IAM), enforce least-privilege permissions, continuously monitor cloud activity for automated privilege escalation, and update incident response procedures to address AI-assisted attack techniques.

Large-Scale Exploitation Campaign Targeting Website Content Management Systems (CMS) The Australian Cyber Security Centre (ACSC) warned of a large-scale campaign targeting vulnerable content management systems (CMS) through unauthenticated file upload and deserialization vulnerabilities. Cyber threat actors have been exploiting internet-facing CMS platforms to deploy web shells, establish persistent access, and facilitate follow-on ransomware and data extortion operations. Researchers observed attackers leveraging these techniques to compromise publicly accessible websites that support government, commercial, and critical infrastructure organizations. Because Florida organizations rely extensively on CMS platforms to host public-facing services and operational websites, administrators should immediately apply security updates, review web servers for unauthorized file uploads and web shells, restrict unnecessary administrative access, and continuously monitor web application logs for indicators of exploitation.

AI Gateways Are the Keys to the Kingdom Security researchers highlighted the growing security risks associated with artificial intelligence (AI) gateways, demonstrating how a real-world compromise of an enterprise AI gateway enabled attackers to gain unauthorized access to cloud-hosted AI infrastructure and consume cloud computing resources. The research emphasizes that AI gateways have become high-value targets because they broker authentication, application programming interface (API) requests, and communications between enterprise applications and large language models (LLMs). A successful compromise could enable attackers to carry out lateral movement, access unauthorized data, and abuse cloud-based AI services. Because Florida government agencies, healthcare organizations, financial institutions, and critical infrastructure operators are rapidly adopting enterprise AI platforms, organizations should strengthen identity and access management (IAM) controls around AI gateways, continuously monitor AI service activity for anomalous API usage, restrict unnecessary permissions, and regularly audit AI infrastructure for unauthorized access.

Information Technology Sector Recommendations:

  • Patch internet-facing applications, remote management platforms, and enterprise technologies to remediate actively exploited vulnerabilities.
  • Verify software packages and code repositories to reduce supply chain risks from malicious dependencies.
  • Rotate exposed cloud credentials and application programming interface keys to secure development infrastructure.
  • Restrict permissions for generative artificial intelligence assistants and validate all automated code recommendations.
  • Enhance endpoint detection capabilities to identify command-and-control communications, unauthorized authentication, and credential theft.
Nuclear Reactors, Materials, and Waste Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

Transportation Systems Sector

Maritime Phishing Campaign Targets South Korean Shipping and Logistics Organizations Researchers identified a cyber campaign targeting South Korean maritime organizations through phishing emails and business email compromise (BEC) infrastructure designed to steal credentials and gain unauthorized access to shipping and logistics networks. The operation leveraged the RedLine Stealer malware and supporting command-and-control infrastructure to compromise organizations involved in maritime transportation and global supply chain operations. The campaign demonstrates the continued targeting of shipping organizations as high-value entry points into international logistics networks supporting critical infrastructure. Because Florida’s seaports and maritime transportation systems play a vital role in domestic and international commerce, transportation organizations should strengthen phishing awareness training, implement multi-factor authentication (MFA) for business email accounts, monitor for unauthorized credential use, and continuously review network activity for indicators associated with RedLine Stealer and business email compromise campaigns.

2025 CTIME Report Highlights Growing Maritime Cyber Threats The U.S. Coast Guard released its 2025 Cyber Trends and Insights in the Marine Environment (CTIME) report, revealing a 17% year-over-year increase in maritime cyber incidents. Phishing drove 43% of initial access events, representing an 18-point rise. The Coast Guard also warned that out-of-the-box artificial intelligence cybersecurity platforms failed to detect simulated attacks unless explicitly tuned for the operating environment. Additionally, “Dark Fleet” vessels presented severe network risks, including unattended remote access tools and hardware designed for Automatic Identification System (AIS) spoofing. These vulnerabilities present a severe, escalating risk to Florida’s massive commercial port and maritime logistics network.

Transportation Systems Sector Recommendations:

  • Train maritime logistics personnel to isolate unverified freight communications and prevent credential harvesting schemes.
  • Tune cloud-hosted artificial intelligence security monitoring platforms specifically to match local port infrastructure traffic baselines.
  • Establish redundant, out-of-band communication workflows to protect local delivery tracking fleets from tracking vulnerabilities.
Water and Wastewater Systems Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.

 

 

Supplement:

Adversary Watch (Early July 2026)

This is a periodic operational intelligence analytic product for Florida’s Critical Infrastructure (CI) Managers, Planners, and CISOs to provide an integrated synthesis of recent CI-focused Threat Actor Campaigns, IT/OT TTPs, and Defensive Posturing. This issue covers trends in the period July 1-July 14 2026

1. Threat Actor & Campaign Matrix

Russia-Nexus (FSB Centre 16 / Turla, NoName, Armored Likho)

• Strategic Intentions: Espionage and prepositioning for CI sabotage. Operations specifically target power grids to disrupt communications between renewable energy assets and central power distribution networks. The GRU and Russian military are also actively testing CI response times via drone incursions and projecting continental-scale electronic warfare (GPS/PNT jamming).

• Sustained Capabilities: FSB Centre 16 exploits poorly configured edge routing devices, IP cameras, and legacy management protocols (SNMP) to monitor physical logistics and establish footholds. Armored Likho utilizes the evasive, Python-based BusySnake Stealer to target electric power operators.

• Targeted CISA Sectors: Energy, Water/Wastewater, Transportation Systems (Maritime), and Government Facilities.

China-Nexus (PLA/MSS / Salt Typhoon, UAT-7810)

• Strategic Intentions: Expanding Military-Civil Fusion doctrine to embed stealthy intelligence collection within global telecommunications and edge hardware for potential wartime disruption. Operations also heavily target the U.S. innovation base to steal AI product roadmaps.

• Sustained Capabilities: UAT-7810 relies heavily on custom malware (“SHORTLEASH”) to convert unpatched enterprise edge devices and network-attached storage into Operational Relay Box (ORB) networks, enabling obfuscated secondary attacks.

• Targeted CISA Sectors: Telecommunications, Defense Industrial Base (DIB), Energy, and Information Technology.

Autonomous AI & High-Tier Cybercriminals (JADEPUFFER, The Gentlemen, Hyadina, TeamPCP)

• Strategic Intentions: Rapid scaling of extortion, data theft, and supply chain compromise.

• Sustained Capabilities: JADEPUFFER represents a severe escalation: an “agentic” LLM actor autonomously navigating the kill chain from initial access to destructive database encryption without human operators. The Gentlemen have rapidly scaled to account for 17% of global ransomware attacks. Hyadina neutralizes EDR via kernel drivers, while TeamPCP extracts cloud access tokens and Kubernetes secrets via supply chain compromises.

• Targeted CISA Sectors: Cross-sector (heavy focus on Healthcare, IT, and Commercial Facilities).

2. Integrated TTP & Vulnerability Analysis

Primary Initial Access Vectors

• Edge Device & Perimeter Exploitation: Edge infrastructure remains the primary ingress vector. Threat actors are actively exploiting Citrix NetScaler SAML identity providers (CVE-2026-8451), Gitea reverse-proxy authentication (CVE-2026-20896), and Ubiquiti UniFi OS command injection (CVE-2026-50746). The “FortiBleed” campaign harvested configurations from over 73,000 Fortinet devices, currently facilitating INC and Lynx ransomware deployments.

• Supply Chain Poisoning: Lazarus Group and APT37 are compromising legitimate developer accounts to inject obfuscated loaders into open-source ecosystems (npm, Packagist).

Specific IT-to-OT Pivot Techniques

• Centralized Platform Hijacking: Threat actors are breaching IT/OT boundaries by compromising centralized management and middleware. Active exploitation of SimpleHelp RMM (CVE-2026-48558) grants administrative control over OT networks. Similarly, exploitation of Oracle E-Business Suite (CVE-2026-46817) and SharePoint (CVE-2026-45659) directly threatens logistics and DIB supply chains.

• Embedded Local Exploitation: Vulnerabilities in the FatFs filesystem library (embedded in millions of industrial controllers) allow threat actors with physical access to execute arbitrary code on OT assets via compromised USB/SD media.

• EDR Blinding: The Hyadina ransomware operation uses the PoisonX kernel driver to neutralize conventional endpoint detection mechanisms prior to execution.

3. Cross-Source Trends

• Convergence of Cyber and Physical Threats: Ransomware affiliates are escalating digital extortion by issuing credible threats of physical violence against organizational leadership and their families. Simultaneously, the maritime sector is experiencing a resurgence in physical piracy and drone incursions layered with tailored RedLine infostealer/BEC campaigns against logistics providers.

• Widespread PNT/GPS Degradation: Geopolitical electronic warfare (primarily Russian-led) is causing severe positioning, navigation, and timing (PNT) failures on a continental scale, resulting in critical dependencies for commercial aviation and maritime networks.

• IoT Botnets Threatening Adjacent OT: The rapid proliferation of Golang-based malware (Apex2, c2c/meow) targeting exposed Linux and IoT devices for DDoS botnets presents a high spillover risk to physically adjacent OT environments across Water and Agricultural sectors.

4. Defensive Implications

Immediate Prioritized Defensive Controls

• Edge & Middleware Triage: Florida CI operators must immediately patch or isolate Citrix NetScaler, Gitea instances, Oracle E-Business Suite, and SimpleHelp RMM interfaces.

• Fortinet Credential Rotation: Operators utilizing Fortinet firewalls must assume compromise if historical patching was delayed; CISOs must mandate absolute credential rotation and audit VPN configurations for unauthorized persistence.

• Disable Vulnerable On-Premises File Sharing: Isolate or completely disable on-premises Progress ShareFile Storage Zone Controllers facing active exploitation.

CI/OT Tailored Mitigation & Detection

• Zero-Trust for Distributed OT: Florida energy planners must mandate strict zero-trust segmentation between central distribution networks and remote renewable generation hardware (e.g., solar arrays) to block Russian FSB sabotage efforts.

• PNT Resilience: Florida maritime ports and aerospace corridors must immediately audit backup navigation mechanisms and implement resilient, non-GPS-dependent timing synchronization protocols.

• IoT Air-Gapping: Sectors relying on distributed sensors must strictly isolate IoT networks from core OT environments, disabling public-facing administrative ports and enforcing strict egress filtering.

• Physical Media Policies: Disable AutoRun and ban unvetted USB/SD cards near industrial controllers to mitigate the unpatched FatFs library vulnerabilities.

5. Intelligence Gaps

• Unverified Physical OT Manipulation: The Russian-linked hacktivist group NoName publicly claims they breached a Quebec water treatment plant with the capability to covertly manipulate physical OT assets (pumps, chlorine dosing). However, precise telemetry confirming successful physical manipulation downstream remains unverified.

• Decentralized Cybercriminal Infrastructure: While a key member of Scattered Spider was arrested, the collective has shifted to a decentralized model. The operational readiness, command structure, and remaining shared infrastructure of these independent clusters lack clear definition.

• Initial Intrusion Vectors: The specific vulnerability exploited by the “Breach Boyz” to steal sensitive PII at the Rogers County Jail remains unconfirmed by third-party auditors, limiting the ability to establish preventative indicators for other emergency services facilities.

CI Bulletin Vol 2, Issue 11 – July 16, 20262026-07-16T15:01:30-04:00

CI Bulletin Vol 2, Issue 10 July 7 2026

Florida Critical Infrastructure Cybersecurity Intelligence

This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.

Situational Awareness Bulletin
Cyber Threat Outlook

Florida’s critical infrastructure operators face an accelerating wave of attacks against the software and network equipment that connects their organizations to the internet, with attackers exploiting newly disclosed flaws within days of disclosure and, in several cases, before a fix even exists. Over the next six to nine months, three patterns will likely dominate the threat landscape: mass-exploitation campaigns against widely used enterprise software, illustrated by the Oracle PeopleSoft vulnerability behind the ShinyHunters extortion campaign that has already struck a national insurance regulator; continued compromise of network perimeter devices, including firewalls, virtual private networks (VPNs, which let remote users connect securely to a private network), and routers that organizations rely on for both security and connectivity; and the abuse of trusted third-party cloud integrations, where attackers steal credentials from one vendor to reach every customer connected to it. Nation-state actors, particularly those linked to Iran and Russia, continue probing government and public safety systems abroad for techniques that could migrate to U.S. targets. For Florida operators, the most effective defenses remain unglamorous but proven: patch internet-facing systems quickly, require multifactor authentication everywhere it is available, and rehearse manual backup procedures so operations can continue if digital systems fail.

Confidence Assessment – High

Executive Summary

All Sectors: Prioritize risk-based vulnerability management across all sectors as automated exploitation of internet-facing vulnerabilities has surpassed credential theft as the leading initial access method for cyber intrusions. Iran-linked threat groups continue demonstrating the ability to disrupt public-safety alerting and operational technology (OT) systems abroad, most recently by silencing emergency sirens in Israel through a known firmware flaw in widely deployed alerting hardware — a technique that could be replicated against the same hardware wherever it is deployed, including in Florida. Florida organizations should accelerate remediation of actively exploited vulnerabilities, inventory any of the affected alerting hardware in their environment, and strengthen identity-centric security controls.

Commercial Facilities: Isolate internet-connected surveillance systems and third-party business platforms, as newly disclosed, high-severity H.VIEW camera vulnerabilities (CVSS 7.2 and 8.6) and recent extortion campaigns demonstrate these technologies remain attractive attack vectors. No vendor patch is currently available for the camera flaws, so isolation is the primary defense. Organizations should rotate privileged credentials, segment backup infrastructure, and monitor for unauthorized administrative activity.

Communications: Strengthen communications infrastructure security as Cisco Secure Digital Wide Area Network (SD-WAN) zero-day exploitation and new Federal Communications Commission (FCC) emergency communications security requirements highlight increasing operational risks. Florida communications providers should prioritize patching, review administrative access controls, and validate continuity procedures supporting emergency communications.

Critical Manufacturing: Apply firmware and software updates rapidly as active exploitation of Ubiquiti UniFi and PTC Windchill platforms continues to threaten manufacturing environments and industrial supply chains. Organizations should restrict access to management interfaces and strengthen segmentation between operational technology and enterprise networks.

Financial Services: Review third-party platform security following the National Association of Insurance Commissioners (NAIC) breach, which was caused by the same Oracle PeopleSoft zero-day vulnerability (CVE-2026-35273) covered under All Sectors above, and demonstrates continuing risks associated with financial reporting and regulatory operations. Financial institutions running Oracle PeopleSoft should treat patching that vulnerability as a financial-sector priority, not only a general IT task, and should enforce least-privilege principles, strengthen authentication controls, and monitor for unauthorized access to sensitive financial data.

Government Services and Facilities: Increase behavioral monitoring, drawing on newly published research showing how the Russian Advanced Persistent Threat (APT) group Gamaredon evolved its PowerShell-based malware and command-and-control tradecraft in 2025. Gamaredon’s documented campaigns remain focused on Ukrainian government and military targets, but its techniques — including abuse of legitimate cloud and tunneling services to hide infrastructure — illustrate broader nation-state tradecraft worth incorporating into defensive planning. Government organizations should validate endpoint detection capabilities and conduct recurring integrity reviews of administrative workstations and privileged accounts.

Healthcare and Public Health: Strengthen third-party access controls as CyberAv3ngers continues targeting public-safety communications while ransomware operators maintain pressure on healthcare providers through data theft and extortion. Healthcare organizations should validate backup and recovery procedures, monitor for data leakage, and ensure continuity plans support uninterrupted patient care.

Information Technology: Remediate Known Exploited Vulnerabilities affecting internet-facing enterprise infrastructure as active exploitation of Palo Alto GlobalProtect, LiteSpeed cPanel, and Joomla vulnerabilities continues to increase operational risk. Organizations should restrict administrative privileges, strengthen endpoint monitoring, and review browser extension security policies.

Water and Wastewater Systems: Enhance remote-access security as recent federal guidance regarding last-mile funding and National Institute of Standards and Technology (NIST) remote-access security reinforces the need for resilient operational technology architectures. Utilities should implement continuous operational technology integrity monitoring and validate manual fallback procedures to maintain essential services during cyber incidents.

All Sectors

Securing The Nation Against Advanced Cryptographic Attacks On June 22, 2026, President Trump signed an Executive Order directing the accelerated transition to Post-Quantum Cryptography (PQC) across federal systems to address emerging “harvest now, decrypt later” threats. Adversaries are increasingly collecting encrypted information with the expectation that future quantum computing capabilities will enable decryption of sensitive data. While the directive establishes federal migration timelines through 2031, Florida critical infrastructure owners and operators should begin identifying cryptographic dependencies, inventorying high-value assets, and coordinating with their Sector Risk Management Agencies (SRMAs) to support long-term cryptographic modernization and reduce future operational risk.

ShinyHunters Hacked Hundreds Leveraging Oracle Bug Throughout June 2026, the ShinyHunters cybercrime group conducted coordinated attacks by exploiting vulnerabilities in widely deployed enterprise platforms, including Oracle PeopleSoft, to compromise organizations across multiple sectors. The campaign exploited CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution flaw in the PeopleSoft Environment Management Hub component, between May 27 and June 9, 2026, before Oracle issued mitigation guidance on June 10. Rather than targeting a single organization, the campaign focused on shared enterprise infrastructure to steal personally identifiable information (PII), financial records, and proprietary business data for extortion. While the campaign affected organizations across government, healthcare, financial services, and other sectors, Google Mandiant’s investigation found that 68 percent of identified targets were in higher education, making it the sector hit hardest by this specific campaign. Because Oracle enterprise resource planning solutions are widely used across government, healthcare, financial services, and commercial organizations, Florida critical infrastructure operators should immediately assess internet-facing Oracle environments, validate backup integrity, and monitor for indicators of unauthorized access.

Cybercriminals Allegedly Hacked Tens of Thousands of Fortinet Firewalls Used by Major Companies All Over the World A large-scale credential exposure campaign compromised administrative and Secure Sockets Layer Virtual Private Network (SSL VPN) credentials associated with more than 73,000 Fortinet FortiGate appliances worldwide. The exposed credentials could enable cyber threat actors to bypass network perimeters, modify firewall configurations, establish persistent access, and conduct lateral movement within enterprise environments. Fortinet characterized the activity as “a resharing of data from previous incidents, as well as bruteforcing of credentials, and is not related to any recent incident or advisory.” Given the widespread deployment of Fortinet technologies throughout Florida government agencies and critical infrastructure sectors, organizations should immediately validate administrative credentials, review firewall configurations, rotate compromised credentials, and prioritize risk-based remediation to prevent unauthorized network access.

North Korean Hiring Fraud Runs on AI and US Laptop Farms Research released in June 2026 identified a sophisticated North Korean employment fraud campaign that combines stolen identities, artificial intelligence-assisted interviews, and U.S.-based laptop farms to infiltrate technology companies. One documented case, publicized in June 2026 but originating from a June 2025 job application, involved an individual posing as a Florida-based artificial intelligence architect who applied for a position at risk-intelligence firm Nisos. Nisos identified the deception during its interview process before extending an offer, then used the engagement to gather intelligence on the broader fraud operation. This activity demonstrates the growing insider threat posed by fraudulent remote hiring schemes. Florida organizations should strengthen identity verification procedures, validate candidate credentials, monitor for anomalous endpoint activity during onboarding, and incorporate insider-threat detection into hiring and human resources security processes. Two technical indicators thsat may be useful for detection are: (a) the use of PiKVM hardware to allow remote, hard-to-detect control of ‘laptop farm’ devices, and (b) the use of Astrill VPN, a service frequently associated with North Korean IT-worker operations, as a connection pattern.

All Sectors Recommendations:

• Inventory cryptographic assets and develop a phased migration strategy for Post-Quantum Cryptography (PQC) in coordination with applicable Sector Risk Management Agencies (SRMAs).

• Audit internet-facing enterprise applications and external gateways to identify vulnerabilities, unauthorized access, and indicators of compromise before they are exploited.

• Enforce phishing-resistant multi-factor authentication, rotate privileged credentials regularly, and continuously monitor remote access infrastructure for unauthorized administrative activity.

• Strengthen hiring and insider-threat detection processes by validating candidate identities, monitoring endpoint activity during onboarding, and identifying indicators associated with fraudulent remote employment campaigns.

• Conduct recurring tabletop exercises and business continuity drills to validate incident response, backup recovery, and operational resilience across all critical infrastructure sectors.

Chemical Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Commercial Facilities Sector

CISA Warns H.VIEW HV-500S6 Cameras: Command Injection & Malicious File Upload Risk On June 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) released advisory ICSA-26-176-05 identifying high-severity vulnerabilities affecting H.VIEW HV-500S6 Internet Protocol (IP) cameras running firmware version IPCAM_V4.06.88.251229. The vulnerabilities, tracked as Common Vulnerabilities and Exposures (CVE)-2026-55975 and CVE-2026-56414, allow authenticated attackers to execute operating system commands and upload malicious files capable of establishing persistent access. Because these cameras are commonly deployed within commercial facilities, retail environments, warehouses, and public venues, successful exploitation could provide cyber threat actors with an initial foothold into enterprise networks. Florida commercial facility operators should prioritize firmware updates, isolate surveillance devices from critical business networks, and continuously monitor camera management interfaces for unauthorized activity.

Commercial Facilities Sector Recommendations:

• Identify all deployed H.VIEW HV-500S6 devices and verify whether vulnerable firmware versions remain in operation.

• Because H.View did not respond to CISA’s coordination request, and no vendor patch is currently available, CI operators should prioritize network isolation or removal of affected devices, while organizations attempt direct outreach to the vendor. Apply vendor firmware updates and remove unsupported devices from production environments whenever possible.

• Restrict camera management interfaces from direct internet exposure by implementing network segmentation and firewall protections.

• Rotate administrative credentials, disable unnecessary accounts, and continuously monitor surveillance systems for unauthorized configuration changes or suspicious activity.

• Validate incident response procedures for physical security systems to ensure surveillance infrastructure can be restored quickly following a cyber incident.

Communications Sector

Malicious Hackers Exploit Cisco Zero-Day for Highest Access Level at Communications Service Provider Mandiant disclosed on June 24, 2026, that attackers had exploited a Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) Manager zero-day vulnerability (CVE-2026-20245) months earlier, escalating from administrative access first obtained in late 2025 to full root-level control by March 2026. While the attackers established unauthorized peering connections and created root-level privilege escalation, each component exploited separate vulnerabilities: CVE-2026-20127 or CVE-2026-20182 for initial access; CVE-2026-20245 for privilege escalation to root. This is the seventh actively exploited Cisco SD-WAN zero-day disclosed in 2026, indicating a sustained, not isolated, attacker focus on this product line. Because Cisco SD-WAN technologies are widely deployed across government agencies, telecommunications providers, utilities, and other Florida critical infrastructure sectors, exploitation of this vulnerability could enable unauthorized network access, service disruption, and lateral movement across enterprise environments. Florida organizations should prioritize patching, review administrative accounts, and continuously monitor SD-WAN infrastructure for signs of compromise.

FCC Passes New Cybersecurity Rules for Emergency Systems, Undersea Cables On June 25, 2026, the Federal Communications Commission (FCC) adopted new cybersecurity requirements to strengthen the security of the Emergency Alert System (EAS), Wireless Emergency Alerts (WEA), and undersea cable infrastructure. The updated submarine cable rules tighten some cybersecurity and equipment-sourcing requirements while also streamlining the national-security review process for cable operators that self-certify to high security standards, in a trade-off intended to accelerate buildout. Because Florida relies heavily on undersea cable networks and statewide emergency communications to support public safety and disaster response, compliance with these requirements will strengthen operational resilience and reduce the risk of service disruption during cyber incidents.

Communications Sector Recommendations:

• Patch Cisco Catalyst Software-Defined Wide Area Network (SD-WAN) infrastructure immediately to remediate known vulnerabilities and reduce the risk of unauthorized administrative access.

• Audit privileged accounts and configuration changes regularly to identify unauthorized users, rogue administrative accounts, or suspicious modifications.

• Implement the Federal Communications Commission’s (FCC) cybersecurity requirements for the Emergency Alert System (EAS) and Wireless Emergency Alerts (WEA), including strong authentication and timely patch management.

• Review business continuity and disaster recovery procedures supporting communications infrastructure to ensure essential services remain available during cyber incidents.

• Monitor network traffic and system logs continuously for indicators of compromise affecting routing infrastructure, emergency communications systems, and undersea cable connectivity.

Critical Manufacturing Sector

CISA Warns of Max Severity Ubiquiti Flaws Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) added multiple high-severity vulnerabilities affecting Ubiquiti UniFi Operating System (OS) devices to the Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. The vulnerabilities (CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910) allow unauthenticated attackers to bypass security controls and gain unauthorized access to affected systems. Because Ubiquiti networking equipment is widely deployed across manufacturing facilities, distribution centers, and industrial operations, exploitation could disrupt production networks and enable lateral movement into operational technology environments. Florida critical manufacturing organizations should prioritize firmware updates, restrict internet exposure of management interfaces, and continuously monitor network infrastructure for indicators of compromise.

First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild Cyber threat actors are actively exploiting a critical remote code execution vulnerability (CVE-2026-12569) affecting PTC Windchill and FlexPLM Product Lifecycle Management (PLM) platforms. The vulnerability results from improper input validation and allows unauthenticated attackers to execute arbitrary code with system-level privileges. Following confirmed exploitation, CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV) and directed organizations to remediate affected systems by June 28, 2026. This is the first PTC product vulnerability ever added to CISA’s KEV catalog, signaling new attacker interest in a previously untargeted vendor. Because Product Lifecycle Management platforms support engineering design, manufacturing operations, and supply chain coordination, successful exploitation could disrupt production processes, expose proprietary engineering data, and impact critical manufacturing operations across Florida.

Critical Manufacturing Sector Recommendations:

• Apply vendor firmware and software updates (UniFi OS Server 5.0.8, released in May 2026) immediately to all affected Ubiquiti UniFi Operating System and PTC Windchill platforms.

• Restrict public access to management interfaces by implementing network segmentation, virtual private networks, and firewall protections.

• Monitor network traffic, authentication logs, and administrative activity for indicators of compromise or unauthorized configuration changes.

• Validate backup and recovery procedures for engineering, manufacturing, and Product Lifecycle Management systems to minimize operational disruption following a cyber incident.

• Conduct regular vulnerability assessments of industrial control and supporting enterprise systems to identify and remediate emerging risks before exploitation occurs.

Dams Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Defense Industrial Base Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Emergency Services Sector

Team82 Documents Iran-Linked CyberAv3ngers Escalating Cyber-Psychological Warfare Against Civilian Alert Systems Claroty’s Team82 documented CyberAv3ngers exploiting a known firmware vulnerability (CVE-2024-41700) in Barix audio-over-IP devices to silence Israeli emergency sirens and manipulate public alerts. Rather than focusing solely on system disruption, the group seeks to manipulate emergency alerts to create confusion, erode public trust, and disrupt emergency response operations. Barix has released a patch, though it must be applied manually. Because the same vulnerable Barix hardware is also deployed in U.S. public safety and emergency alerting infrastructure, including in Florida, municipalities should treat this as a warning to inventory and patch any Barix devices in their environment rather than evidence of direct targeting.

Emergency Services Sector Recommendations:

• Isolate public safety communication systems and critical alerting infrastructure from internet-facing networks whenever operationally feasible.

• Conduct tabletop exercises involving ransomware, cyber-physical attacks, and emergency communications disruptions to improve organizational preparedness.

Energy Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Financial Services Sector

NAIC Confirms June Data Breach The National Association of Insurance Commissioners (NAIC) confirmed a data breach involving unauthorized access to its PeopleSoft financial reporting environment on or about June 11, 2026. This breach was caused by the same Oracle PeopleSoft zero-day (CVE-2026-35273) already covered as a separate item under All Sectors earlier in the bulletin. Cyber threat actors temporarily accessed sensitive data repositories before the activity was identified, contained, and remediated. The scope of the breach is disputed: the attacker has published a large volume of data, while NAIC maintains the group is unlikely to hold the full scope of regulatory data it has claimed, and confirms no personally identifiable information or payment data was accessed. Nevertheless, the incident highlights the continued risk posed by third-party platforms supporting regulatory reporting and financial operations. Because Florida insurers and the Florida Office of Insurance Regulation rely on similar enterprise systems to exchange regulatory information, organizations should strengthen third-party risk management, continuously monitor privileged access, and validate security controls protecting financial reporting environments.

Financial Services Sector Recommendations:

• Conduct recurring third-party risk assessments of regulatory reporting platforms and financial service providers to identify authentication, access control, and configuration weaknesses.

• Enforce least-privilege access controls and multifactor authentication for users with access to sensitive financial reporting systems.

• Monitor authentication logs, privileged account activity, and data access events continuously for indicators of unauthorized access or credential misuse.

• Review business continuity and incident response procedures to ensure regulatory reporting operations can continue during third-party cybersecurity incidents.

• Coordinate with third-party vendors to validate incident notification procedures and recovery responsibilities following security events.

Food and Agriculture Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Government Services and Facilities Sector

Russia APT ‘Gamaredon’ Upgrades Arsenal, Requiring New Defenses The Russian state-sponsored Advanced Persistent Threat (APT) group Gamaredon, also known as Aqua Blizzard, has expanded its malware toolkit by deploying more sophisticated PowerShell-based downloaders and enhanced command-and-control evasion techniques. These updates improve the group’s ability to maintain persistent access while avoiding traditional signature-based detection methods. ESET’s research documents that Gamaredon’s 2025 campaigns exclusively targeted Ukrainian government and military institutions. There is currently no evidence the group is specifically targeting U.S. or Florida government entities directly. The group’s evolving techniques, however — including new PowerShell-based downloaders and abuse of legitimate cloud and tunneling services to conceal command-and-control infrastructure — reflect broader nation-state tradecraft trends that Florida government organizations should incorporate into defensive planning. Florida state and local government organizations should consider proactive measures to strengthen behavioral monitoring, restrict unauthorized PowerShell execution, and continuously monitor outbound network communications for indicators of malicious activity associated with advanced persistent threats.

Government Services and Facilities Sector Recommendations:

• Implement PowerShell execution controls, including Constrained Language Mode, to reduce the risk of unauthorized script execution.

• Monitor endpoint and network telemetry continuously for anomalous PowerShell activity and command-and-control communications.

• Conduct recurring integrity reviews of administrative workstations and privileged accounts to identify persistence mechanisms or unauthorized system modifications.

• Strengthen endpoint detection and response capabilities to improve visibility into advanced persistent threat activity.

• Exercise incident response procedures focused on nation-state cyber threats targeting government networks and essential public services.

Healthcare and Public Health Sector

H-ISAC TLP Green: Ransomware Data Leak Sites Report The Health Information Sharing and Analysis Center (H-ISAC) Traffic Light Protocol (TLP): Green Ransomware Data Leak Sites Report provides healthcare organizations with timely visibility into ransomware groups actively publishing victim data on extortion sites. By monitoring these disclosures, organizations can identify emerging ransomware campaigns, validate potential compromises, and prioritize defensive actions before operational impacts escalate. Because healthcare providers remain frequent ransomware targets, Florida hospitals, clinics, and public health organizations should integrate external threat intelligence with internal security monitoring, continuously assess third-party vendor risk, and validate backup recovery capabilities to support uninterrupted patient care during cyber incidents.

Healthcare and Public Health Sector Recommendations:

• Validate backup integrity and routinely exercise disaster recovery procedures to maintain continuity of patient care during ransomware incidents.

• Monitor ransomware data leak sites continuously and correlate external reporting with internal security logs to identify potential compromises.

• Strengthen third-party vendor risk management programs and validate security controls protecting healthcare information systems.

Information Technology Sector

Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw Cyber threat actors are actively exploiting an authentication bypass vulnerability (CVE-2026-0257, CVSS 7.8) affecting Palo Alto Networks GlobalProtect Virtual Private Network (VPN) gateways. The flaw allows attackers to forge authentication cookies and establish unauthorized VPN sessions; Palo Alto Networks reports no evidence of subsequent code execution or lateral movement in confirmed cases. The vulnerability only affects devices with authentication override cookies enabled and a certificate shared with another feature, not all GlobalProtect deployments. Because GlobalProtect appliances are widely deployed across government, healthcare, financial services, and other Florida critical infrastructure sectors, exploitation could enable unauthorized network access, operational disruption, and lateral movement throughout enterprise environments. Organizations should immediately apply vendor updates, restrict exposure of management interfaces, and continuously monitor authentication activity for indicators of compromise.

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-54420 to the Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation affecting LiteSpeed cPanel Plugin deployments. The vulnerability allows attackers with limited access to escalate privileges and potentially obtain administrative control of shared hosting environments. Because shared hosting platforms support many municipal governments, educational institutions, and small businesses throughout Florida, organizations should promptly update affected systems, review administrative privileges, and monitor hosting environments for unauthorized activity.

CISA Orders Feds to Patch Max Severity Joomla Plugin Flaw CISA directed federal agencies to remediate a critical vulnerability (CVE-2026-48907) affecting the Joomla Content Editor (JCE) plugin after adding it to the Known Exploited Vulnerabilities (KEV) Catalog. The vulnerability allows unauthenticated attackers to upload malicious PHP files and execute arbitrary code on vulnerable web servers. It is important to note that patching alone does not remove a web shell that attackers may have already planted on a compromised site before the update was applied, so defenders will need to hunt for Indicators of Compromise (IOCs) to detect them. Because Joomla is widely used to host public-facing government and organizational websites, exploitation could result in website defacement, unauthorized data access, or disruption of public services. Florida organizations should prioritize remediation, review web application security controls, and continuously monitor internet-facing websites for suspicious activity.

Google Vertex AI SDK Flaw Enables Cross-Tenant Model Hijacking Researchers disclosed a critical design flaw affecting the Google Cloud Vertex Artificial Intelligence (AI) Software Development Kit (SDK) for Python that could allow attackers to hijack machine learning model deployments across cloud environments. By exploiting predictable storage bucket naming, attackers may replace legitimate models with malicious versions capable of executing unauthorized code. Because the flaw was responsibly disclosed in March 2026 and fully patched by April 15, 2026 (SDK version 1.148.0), any actively maintained Vertex AI deployment running a current SDK should already be protected. As artificial intelligence adoption continues to expand across government and private industry, Florida organizations using Google Cloud should upgrade affected SDK versions, validate cloud storage configurations, and review software development security practices to reduce supply chain risk.

Salesforce Disables Klue Battlecards Integration Following OAuth Token Theft Cyber threat actors compromised the Klue Battlecards integration platform to steal Open Authorization (OAuth) tokens and access customer information through trusted third-party integrations, including Salesforce environments. The initial entry point was a long-dormant but still-active legacy credential, originally created for an abandoned third-party integration prototype. The incident highlights the growing cybersecurity risks associated with interconnected cloud services and software supply chain dependencies. Florida organizations should review third-party integration permissions, monitor application programming interface (API) activity for anomalous behavior, and regularly revoke unnecessary authorization tokens to reduce the likelihood of unauthorized access.

Malicious Edge Extension Abuses Native Messaging as Bridge to Malware Cyber threat actors are distributing a malicious Microsoft Edge browser extension that abuses the Chrome Native Messaging protocol to bypass browser security controls and execute malicious code on endpoint systems. This technique enables attackers to launch native processes, compromise connected applications, and establish persistent access while avoiding traditional browser protections. The campaign, dubbed ‘Edgecution,’ is linked to an initial access broker associated with the Payouts Kings ransomware operation. It originated with attackers impersonating IT support staff on Microsoft Teams and directing employees to a fraudulent ‘Outlook Updates Management Console’ page under the pretense of a spam-filter update. Because browser extensions are commonly used across enterprise and government environments, Florida organizations should restrict extension installations, monitor endpoint activity for unauthorized native messaging, and educate users on the risks associated with unapproved browser add-ons and the hazards of attackers impersonating IT staff.

Information Technology Sector Recommendations:

• Apply vendor patches immediately for Palo Alto GlobalProtect, LiteSpeed cPanel Plugin, Joomla Content Editor, and other products identified in the Known Exploited Vulnerabilities (KEV) Catalog.

• Check for existing IOCs, which have been published by the JCE security team and independent researchers, to detect existing Joomla plugin flaws.

• Review internet-facing systems routinely to identify exposed services, vulnerable applications, and unauthorized administrative interfaces.

• Strengthen cloud security by validating third-party integrations, restricting Open Authorization (OAuth) permissions, and monitoring application programming interface (API) activity for suspicious behavior.

• Upgrade Google Cloud Vertex Artificial Intelligence (AI) Software Development Kit (SDK) deployments to supported versions and implement secure software development practices for artificial intelligence environments.

• Restrict browser extension installations through enterprise policies and continuously monitor endpoints for unauthorized native messaging activity or other indicators of compromise.

• Conduct continuous vulnerability assessments and threat hunting activities to identify emerging risks before they affect business operations.

Nuclear Reactors, Materials, and Waste Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Transportation Systems Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Water and Wastewater Systems Sector

Last Mile Cybersecurity On June 22, 2026, the Institute for Security and Technology (IST) released a policy memorandum addressing cybersecurity gaps in federally funded infrastructure projects, particularly the lack of cybersecurity requirements tied to grant funding. The guidance emphasizes incorporating cybersecurity planning, risk assessments, and dedicated funding into infrastructure modernization efforts rather than treating cybersecurity as a separate initiative. Policy memoranda notwithstanding, Section 40126 of the Bipartisan Infrastructure Law already requires the Department of Energy to mandate cybersecurity plans for its grant recipients. Because many Florida water and wastewater utilities rely on federal funding while operating with limited cybersecurity resources, integrating security requirements into infrastructure projects will improve operational resilience and reduce long-term cyber risk.

NIST Offers Security Guidance for Water Utilities Using Remote-Access Tools The National Institute of Standards and Technology (NIST) published updated guidance in the final version of NIST Special Publication 1800-45, “Cybersecurity for the Water and Wastewater Sector: Build Architecture” to help water and wastewater utilities strengthen the security of remote-access technologies used to manage operational systems. Notably, Cybersecurity Dive’s reporting notes that remote-access weaknesses of exactly this kind “enabl[ed] several Iran-linked cyberattack campaigns against U.S. water systems.” The recommendations include restricting unnecessary remote access, implementing multifactor authentication, maintaining detailed access logs, and continuously monitoring remote connections for suspicious activity. Because remote-access technologies remain a common attack vector for cyber threat actors targeting critical infrastructure, Florida water utilities should review remote-access architectures, validate authentication controls, and strengthen monitoring capabilities to reduce operational risk.

Water and Wastewater Systems Sector Recommendations:

• Incorporate cybersecurity requirements into infrastructure modernization projects and grant-funded initiatives to improve long-term operational resilience.

• Identify and inventory all internet-facing operational technology (OT) systems, remote-access pathways, and supporting network infrastructure.

• Strengthen remote-access security by implementing multifactor authentication (MFA), network segmentation, and continuous monitoring of privileged connections.

• Conduct recurring cybersecurity assessments of operational technology environments and validate manual operating procedures to maintain essential services during cyber incidents.

• Coordinate proactively with federal and state partners to leverage available cybersecurity resources, technical assistance, and grant opportunities supporting water sector resilience.

CI Bulletin Vol 2, Issue 10 July 7 20262026-07-07T11:51:49-04:00

Cyber Bulls-i Critical Infrastructure Support Tool is Here.

Cyber Bulls-i

Statewide platform simplifies cybersecurity assessments and provides customized action plans for Florida organizations at no cost

July 1, 2026—Tampa, Fla—Cyber Florida today announced the launch of Cyber Bulls-i, a first-of-its-kind cybersecurity assessment and planning platform designed specifically for Florida’s critical infrastructure organizations.

As the next generation of Cyber Florida’s Critical Infrastructure Program (CIP), Cyber Bulls-i provides organizations with a faster, easier, and more effective way to assess cybersecurity risks and connect with free resources and expert assistance.

At the heart of the new platform is a significantly streamlined assessment experience. The Florida Cyber Risk Assessment (FCRA), a cornerstone of the CIP, has been reduced from 164 questions to 106 questions, making it easier for organizations to evaluate their cybersecurity posture while still receiving meaningful, actionable insights.

“Cyber Bulls-i reflects years of experience working alongside Florida’s critical infrastructure organizations,” said Emeka Okammor, M.S., CISSP, CISA, cybersecurity resource manager. “We’ve taken what we’ve learned and built a modern platform that reduces barriers, saves time, and helps organizations quickly identify their risks and the resources available to address them.”

Cyber Bulls-i guides participants through three simple steps:

  1. Complete the Florida Cyber Risk Assessment (FCRA) to receive a customized cybersecurity report.
  2. Receive a personalized cybersecurity improvement plan tailored to the organization’s unique needs.
  3. Continue improving over time through progress tracking, updated recommendations, and ongoing support.

The launch comes at a critical time. Recent assessments conducted through the CIP found that approximately half of participating organizations lacked a formal recovery plan. Similarly, nearly half had not implemented formal cybersecurity awareness training. Many organizations also reported limited cybersecurity staffing, expertise, and budgets.

Cyber Bulls-i was specifically designed to address these challenges by providing:

  • No-cost participation through state funding
  • Florida-specific recommendations and resources
  • Customized guidance aligned to organizational needs
  • Secure handling of assessment data
  • Ongoing support to help organizations improve over time

Importantly, many organizations that qualify as critical infrastructure do not realize they fall within that category. While hospitals, utilities, and government agencies are often recognized as critical infrastructure, many small and medium-sized businesses also provide essential goods and services that support Florida’s economy, public safety, and daily operations.

Organizations operating within Florida and serving any of the nation’s 16 critical infrastructure sectors are encouraged to participate, including those in communications, energy, healthcare, transportation, information technology, financial services, manufacturing, agriculture, emergency services, government, and other essential industries.

“Cybersecurity threats continue to evolve, but protecting your organization doesn’t have to be complicated or expensive,” said Okammor. “Cyber Bulls-i gives Florida organizations a practical, user-friendly roadmap to help reduce risk, improve resilience, and meet cybersecurity requirements.”

Participation in Cyber Bulls-i is completely free for eligible Florida organizations. To learn more or begin the assessment process, visit Cyber Florida’s critical infrastructure program webpage.

To receive timely updates about Cyber Florida’s news and resources, please sign up or visit the connect with Cyber Florida webpage.

Media Contact: Cyber Outreach Manager Jennifer Kleman, APR, CPRC
mailto:jennifer437@cyberflorida.org

ABOUT CYBER FLORIDA
The Florida Center for Cybersecurity at the University of South Florida, commonly referred to as Cyber Florida, was established by the Florida Legislature in 2014. Its mission is to position Florida as a national leader in cybersecurity through comprehensive education, cutting-edge research, and extensive outreach. Cyber Florida leads various initiatives to inspire and educate current and future cybersecurity professionals, advance applied research, and enhance cybersecurity awareness and safety of individuals and organizations.

Cyber Bulls-i Critical Infrastructure Support Tool is Here.2026-06-30T09:16:33-04:00

CI Bulletin Vol 2, Issue 9 June 23, 2026

Florida Critical Infrastructure Cybersecurity Intelligence

This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.

Situational Awareness Bulletin #11-2026
Cyber Threat Outlook

Over the next six months, Florida critical infrastructure owners and operators will have to navigate a threat environment in which adversaries are moving faster, and defenders are falling further behind. The 2026 Verizon Data Breach Investigations Report (DBIR) documented that automated exploitation of unpatched software vulnerabilities surpassed credential theft as the leading cause of data breaches for the first time in the report’s nineteen-year history, accounting for 31% of confirmed breach entry points. Artificial intelligence is the primary accelerant, compressing the window between a vulnerability’s public disclosure and its active weaponization from months to hours. CISA’s new Binding Operational Directive (BOD) 26-04 formally codifies this reality by replacing flat patching timelines with a graduated, risk-tiered model that mandates remediation within as few as three days, with mandatory forensic analysis to assess whether systems are already compromised, or the highest-risk vulnerabilities.

Iranian state-sponsored actors continue to escalate beyond espionage into active disruption and data destruction targeting water, energy, and defense-adjacent infrastructure. Ransomware groups are expanding their reach through supply chain and third-party vendor compromise. Against this backdrop, the contraction of federal cybersecurity grant funding means organizations cannot wait for external support. Priorities must shift toward risk-tiered vulnerability management aligned with BOD 26-04, network segmentation between operational technology and information technology environments, validated offline backups, and supply chain governance, particularly for software dependencies and cloud storage configurations.

Confidence – High

Executive Summary
  • All Sectors: Automated vulnerability exploitation has officially surpassed credential theft as the primary initial access vector. Driven by frontier AI capabilities, adversaries are weaponizing exploits at machine-speed, necessitating risk-tiered remediation under CISA BOD 26-04, which mandates patch-and-forensic-triage within three days for the highest-risk exposed assets. Iranian state actors have shifted from espionage to active data-wiping and OT disruption. Third-party and vendor-related breaches continue to rise sharply, making supply chain auditing and Zero Trust principles essential.
  • Commercial Facilities: Unauthenticated remote code execution vulnerabilities in Magento servers (CVE-2026-45247) remain under active exploitation. RCI Hospitality Holdings reported a data breach impacting approximately 40,000 individuals.
  • Defense Industrial Base: Department of Defense officials emphasized integrating cyber capabilities into all military operations and strengthening foundational cybersecurity across the defense industrial base. Iranian state actors continue targeting software suppliers and infrastructure connected to the aerospace and defense sectors to establish persistent espionage footholds in supply chains.
  • Energy: High-severity vulnerabilities were disclosed in Hitachi Energy grid control systems (RTU500 and MACH HiDraw).
  • Financial Services: The financially motivated group JINX-0164 targeted cryptocurrency firms using custom macOS malware delivered through fake recruiter lures to steal credentials and access CI/CD environments.
  • Food and Agriculture: Brazilian food delivery platform iFood suffered a data breach exposing sensitive personal information of 1.2 million users, highlighting risks to food supply chain platforms from identity-focused data theft.
  • Government Services and Facilities: The White House accelerated AI adoption through NSPM-11 while tightening control over AI model evaluations. Chinese state-sponsored actors continue targeting government and defense personnel via LinkedIn recruitment lures. The city of St. Paul, Minnesota successfully completed a comprehensive systems recovery following a severe ransomware attack.
  • Healthcare and Public Health: DentaQuest suffered a major data breach exposing sensitive records of approximately 2.6 million accounts. India-based wearable health tech startup Ultrahuman reported a data breach involving unauthorized access to customer wellness data.
  • Information Technology: The National Security Agency (NSA) launched a centralized hub for Zero Trust Implementation Guides (ZIGs). Microsoft’s June 2026 Patch Tuesday addressed nearly 200 vulnerabilities. Actively exploited zero-days affected Veeam, Cisco SD-WAN, Palo Alto Networks PAN-OS, Google Chrome, and Acer Wave 7 mesh routers. Multiple supply chain attacks targeted npm and PyPI repositories through the Miasma and Hades campaigns, variants of the self-replicating Shai-Hulud worm, which infected over 100 packages and extended into Microsoft Azure and GitHub repositories. Cisco released patches for a high-severity server-side request forgery (SSRF) vulnerability.
  • Transportation Systems: SpeedX exposed over 840 million sensitive logistics and customer records. Qilin ransomware claimed responsibility for an attack on the New York/New Jersey Shipping Association.
  • Water and Wastewater Systems: CThe U.S. Government Accountability Office (GAO) warned that many drinking water and wastewater utilities across the United States continue to lack fundamental cybersecurity protections. Water and wastewater systems face persistent, aggressive targeting from Iranian-sponsored entities.
All Sectors

Implementation Guidance for Prioritizing Security Updates Based on Risk BOD 26-04 In response to AI-assisted threat actors narrowing the gap between patch release and mass-exploitation, federal defensive frameworks have overhauled vulnerability remediation. Organizations should look to align their enterprise response with CISA’s Binding Operational Directive (BOD) 26-04. Rather than treating all vulnerabilities with a flat, Common Vulnerability Scoring System (CVSS)-based urgency, defense must be tiered dynamically based on asset exposure, Known Exploited Vulnerabilities (KEV) status, and adversary automation capability. Vulnerabilities meeting the highest-risk criteria, those actively exploited, automatable, and yielding total system control, require remediation and forensic triage within three days. Lower-risk combinations receive graduated timelines up to the next system upgrade cycle. BOD 26-04 formally revokes BOD 22-01, invalidating existing flat 14-day KEV remediation policies. CI organizations supporting federal agencies must update their vulnerability management processes accordingly.

All Sectors Recommendations:

  • Enforce phishing-resistant multi-factor authentication and strict least-privilege policies on all remote access and managed service links.
  • Isolate all public-facing virtual network computing instances behind virtual private networks (VPN) requiring multi-factor authentication.
  • Establish automated vulnerability tracking and scanning mechanisms to outpace accelerated machine-assisted exploitation windows.
  • Conduct technical audits of contractor-managed code environments, cloud storage setups, and cloud collaboration platform configurations.
Chemical Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Commercial Facilities Sector

Mirasvit Vulnerability Exploited to Execute Code on Magento Servers After a critical-severity vulnerability (CVE-2026-45247) in the Mirasvit Full Page Cache Warmer for Magento 2 extension was exploiteded, that CVE was added to the KEV catalog. This PHP object injection flaw, carrying a Common Vulnerability Scoring System (CVSS) score of 9.8, allows unauthenticated remote actors to execute arbitrary code on Magento and Adobe Commerce servers. Exploitation requires no login or special access. A single crafted web request to any vulnerable storefront page is sufficient to trigger full server compromise. The extension, intended to optimize page caching and speed, currently provides a direct pathway for full system compromise and unauthorized data access. Mirasvit released a patch in version 1.11.12. Organizations running any earlier version should update immediately or disable the extension if patching is not immediately possible.

Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals RCI Hospitality Holdings, one of the largest adult nightclub and sports bar operators in the United States, reported a data breach impacting approximately 40,000 individuals. The incident was traced to an insecure direct object reference (IDOR) vulnerability discovered in March 2026 within an IIS web server managed by the company’s internet services subsidiary. The IDOR flaw permitted unauthorized access to personal data of approximately 40,000 independent contractors, including names, dates of birth, Social Security numbers, and driver’s license numbers. Customer records and financial systems were not accessed. This breach highlights the persistent risk of data extortion and PII exposure within large-scale commercial hospitality environments.

Commercial Facilities Sector Recommendations:

  • Perform comprehensive vendor risk assessments for any third parties processing corporate personally identifiable information.
  • Deploy data loss prevention tools and end-to-end encryption on storage repositories hosting consumer or employee records.
  • Formulate incident response scripts addressing pure data extortion, detailing communication pathways for multi-stage extortion tactics.
  • Implement continuous monitoring on corporate file-sharing networks to flag unusual outbound data transfer volume.
Communications Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Critical Manufacturing Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Dams Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Defense Industrial Base Sector

DOD Wants to Integrate Cyber in All Operations, and Integrate Security into AI Department of Defense officials emphasized integrating cyber capabilities into all military operations and strengthening foundational cybersecurity across the defense industrial base. Officials warned that vulnerabilities among contractors and suppliers can directly affect military readiness and operational effectiveness.

Iran Threat Overview and Advisories Iranian advanced persistent threat (APT) groups continue targeting software suppliers and infrastructure components connected to the aerospace and defense sectors. These long-term campaigns show direct correlations with broader geopolitical activity, deploying custom backdoors and implants to establish highly persistent espionage footholds across supply chain dependencies. Moving forward, Florida’s expansive aerospace clusters and defense contractors must validate code provenance and verify that administrative accesses across engineering pipelines strictly adhere to rigorous internal authorization mechanisms. Florida’s aerospace and defense manufacturing clusters, including Space Coast suppliers and aerospace contractors, represent direct targets for Iranian APT supply chain campaigns.

Defense Industrial Base Sector Recommendations:

  • Conduct rigorous, ongoing evaluations of software sub-vendors, tracking any indicators of long-term state espionage campaigns.
  • Deploy endpoint detection and behavioral tracking systems to uncover unauthorized administrative access or unusual remote connections.
  • Validate the cryptographical signing and provenance of external software additions prior to introduction into production networks.
  • Apply strict least-privilege divisions between supplier-administered assets and core defense software assembly lines.
Emergency Services Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Energy Sector

Vulnerabilities Disclosed in Grid Control Infrastructure Technical vulnerabilities at the OT layer continue to expose power distribution systems. Serious flaws have surfaced in the Hitachi Energy RTU500 series, leaving devices susceptible to NULL pointer dereferences and infinite loops that trigger severe system-level denial of service. Concurrently, the Hitachi Energy MACH HiDraw software is vulnerable to CVE-2026-7310, a medium-severity (CVSS 5.5) heap-based buffer overflow (CVE-2026-7310) in the XML parser, exploitable by an authenticated local user via a specially crafted XML file, potentially resulting in memory corruption, denial of service, or arbitrary code execution. These platforms actively manage grid control and power transmission across international systems. Hitachi Energy has released a fix in MACH HiDraw version 9.23; organizations should contact their Hitachi Energy account team given the complexity of individual upgrade paths. MACH HiDraw is also deployed in Dams and Transportation Systems sectors; operators in those sectors should review the CISA advisory.
Energy Sector Recommendations:

  • Deploy vulnerability shielding or compensatory controls around Hitachi Energy RTU500 and MACH HiDraw systems as a priority, consistent with BOD 26-04 risk-tiered guidance; federal entities should assess KEV catalog status and apply applicable deadlines.
  • Maintain air-gapped configuration backups for power-grid control components to ensure manual operational capacity during cyber-induced disruptions.
  • Monitor for emerging risks associated with increasing data center electricity demand and coordinate with utility partners on grid resilience and capacity planning.
Financial Services Sector

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware A sophisticated campaign attributed to financially motivated actors (JINX-0164, which shares TTPs with North Korean-linked group UNC1069/Sleet) has targeted cryptocurrency firms using custom macOS malware and fake recruiter lures. The operation aims to steal credentials and move laterally within Continuous Integration/Continuous Deployment (CI/CD) and development infrastructure. JINX-0164 also conducted a confirmed supply chain attack, trojanizing an npm package to deploy a persistent backdoor, extending the threat beyond individual developers to any organization using affected open-source packages. Organizations in the financial and cryptocurrency sectors should review social engineering defenses and endpoint detection for macOS environments.

Financial Services Sector Recommendations:

  • Enforce cryptographic code-signing checks and enable strict commit verification parameters within all software building lines.
  • Monitor macOS environments for unauthorized background modifications, unexpected remote terminal commands, or atypical local repository adjustments.
  • Train technical staff to verify the identity of unsolicited recruiters on LinkedIn and to refuse requests to download or execute software during virtual interviews or onboarding calls.
  • Implement dedicated secrets-scanning utilities to identify and revoke developer keys if local developer endpoints are compromised.
Food and Agriculture Sector

iFood Confirms Data Breach Affecting 1.2 Million Users in Brazil In December 2025, the Brazilian food delivery platform iFood suffered a data breach impacting 1.2 million users, approximately 2% of its customer base. While hackers did not obtain passwords or financial records, they successfully exfiltrated sensitive personal information, including names, phone numbers, addresses, and CPF numbers, which are the Brazilian taxpayer identity documents equivalent to U.S. Social Security Numbers. The incident underscores the vulnerability of food supply chain enablers to identity-focused data theft and extortion operations.

Food and Agriculture Sector Recommendations:

  • Conduct comprehensive audits of third-party food delivery and supply chain platform vendors to identify and remediate gaps in personally identifiable information (PII) storage, access controls, and data retention policies.
  • Enforce strict data minimization and access controls on platforms that aggregate consumer PII, ensuring that sensitive identifiers such as government-issued identification numbers are encrypted at rest and accessible only to explicitly authorized systems.
  • Establish data breach notification workflows that align with both domestic and international regulatory requirements, given the cross-border nature of food supply chain data exposure.
  • Strengthen monitoring and logging on food delivery and agricultural logistics platforms to detect unusual data access or exfiltration activity, particularly involving sensitive customer and supplier information.
Government Services and Facilities Sector

Promoting Advanced Artificial Intelligence Innovation and Security President Trump signed National Security Presidential Memorandum (NSPM-11) to accelerate artificial intelligence adoption across the military, intelligence community, and federal agencies, directing entities to strengthen public-private AI partnerships while expanding procurement workflows. Concurrently, the administration instructed the Center for AI Standards and Innovation to halt the public release of its model safety assessments while an aligned executive order is implemented. These developments reflect a broader White House strategy to accelerate AI integration across federal operations while maintaining executive control over AI model evaluations and disclosures.

Five Eyes Security Alliance Warns of Chinese Spy Threat on Job Sites The United States and its Five Eyes international partners issued a joint operational warning regarding Chinese state-sponsored intelligence services aggressively targeting government, military, and critical infrastructure personnel on LinkedIn. Sophisticated actors pose as legitimate maritime consultancies, think-tank recruiters, and professional headhunters to build relationships with individuals holding active security clearances or specialized technical expertise. Once a connection is established, targets are funneled toward encrypted messaging applications where they are offered financial compensation for internal research, non-public defense insights, or supply-chain logistics data.

How St. Paul, Minnesota, Recovered From a Ransomware Attack The city of St. Paul, Minnesota successfully completed a comprehensive systems recovery following a severe ransomware attack, utilizing a coordinated framework involving municipal departments, state agency responders, and the National Guard. The operation focused on emergency management integration and multi-agency incident response planning to systematically restore public services without paying an extortion demand. Key to St. Paul’s success: a pre-existing multi-agency coordination structure, National Guard cyber support activation, sequenced service restoration prioritizing public safety systems, and refusal to pay the ransom demand. This successful stabilization effort has since become a standard case study in municipal cyber resilience, offering an immediate operational roadmap for Florida’s county and local government facilities facing similar local infrastructure threats.

Government Services and Facilities Sector Recommendations:

  • Assess the cybersecurity and governance implications of accelerating artificial intelligence adoption across government agencies. Focus on protecting AI systems from foreign theft and manipulation while maintaining appropriate oversight of AI model evaluations and disclosures.
  • Train staff with security clearances and access to sensitive information to recognize Chinese state-sponsored recruitment lures on professional networking platforms, as warned by Five Eyes partners. Implement verification procedures for unsolicited job offers from entities posing as consultancies or think tanks.
  • Utilize the St. Paul municipal recovery model to develop multi-agency incident response plans that prioritize service restoration and continuity of operations over extortion payments during ransomware attacks.
Healthcare and Public Health Sector

DentaQuest Data Breach Exposes 2.6 Million Accounts Dental benefits administrator DentaQuest suffered a major data breach that exposed the sensitive personal and health records of approximately 2.6 million accounts. The extortion group ShinyHunters claimed responsibility for the intrusion, leaking 234 gigabytes (GB) of stolen data on a dark web forum after corporate leadership reportedly declined ransom negotiations. The incident follows a persistent operational pattern where advanced extortion groups target third-party health administrators to exfiltrate high-value wellness data and personally identifiable information. Exposed data includes Medicaid IDs, government-issued identification, health insurance records, and contact information. This directly affected individuals enrolled in Medicaid programs managed by DentaQuest in Florida. Because DentaQuest manages dental benefits for a substantial volume of residents across the state, this compromise directly impacts the health, financial, and insurance records of thousands of Florida citizens.

Ultrahuman Says Hackers Accessed Customers’ Wellness Data via Internal Tool India-based wearable health tech startup Ultrahuman r disclosed a data breach on March 27, 2026, involving unauthorized access to an internal analytics tool. Threat actors gained entry by stealing an employee’s credentials through malware to compromise an internal analytics system. Although the company detected the intrusion promptly and took the affected system offline, the breach underscores the escalating risk of malware-driven credential theft targeting centralized health data repositories.

Healthcare and Public Health Sector Recommendations:

  • Apply deep encryption and strict access logging to biometric files and patient wellness data stored in third-party or internal analytics tools.
  • Isolate medical devices and electronic health record (EHR) directories on sub-networks detached from internet-facing boundaries.
  • Practice paper-based admittances and hand-off protocols to sustain care during total IT infrastructure failures.
Information Technology Sector

NSA Launches Zero Trust Implementation Guidelines Resource Webpage The National Security Agency (NSA) launched a centralized hub for Zero Trust Implementation Guides (ZIGs), consolidating legacy technical recommendations and interactive planning tools designed to assist enterprises in strengthening multi-layered infrastructure security. Operating on a “never trust, always verify” framework, the resource center provides a modular, adaptable approach allowing critical infrastructure operators to prioritize defensive integration based on their explicit asset maturity levels and budgets. The interactive platform delivers focused mitigation paths across identity governance, endpoint defense, network isolation, application security, and data protection. Florida infrastructure defenders should immediately utilize these centralized blueprints to transition away from legacy perimeter assumptions and establish validated, continuous authentication controls across state-managed administrative interfaces. The hub is accessible at nsa.gov.

Check Point Warns of Zero-Day Flaw Targeted by Ransomware Affiliate A wave of high-severity network perimeter vulnerabilities is fueling mass-exploitation campaigns targeting virtual private networks (VPNs) and enterprise routing infrastructure. Critical threats include an actively weaponized Cisco Catalyst SD-WAN Manager zero-day (CVE-2026-20245) allowing low-privileged users to execute root-level terminal commands, a Palo Alto Networks PAN-OS cookie-forgery flaw (CVE-2026-0257) enabling unauthorized VPN sessions, and a Check Point Remote Access vulnerability (CVE-2026-50751) actively abused by Qilin ransomware affiliates. Concurrently, Microsoft Exchange Online environments face spoofing risks via the “Ghost-Sender” configuration bypass, while ServiceNow reported unauthorized tenant access incidents, highlighting that Florida public-sector agencies and infrastructure operators must prioritize immediate boundary patching, multi-factor authentication enforcement, and log audits.

Record-Breaking June Patch Tuesday Highlights Enterprise Software Hazards The June 2026 Patch Tuesday cycle marked a historic high, with Microsoft addressing nearly 200 vulnerabilities, including over three dozen critical bugs and an actively exploited Windows Netlogon remote code execution flaw (CVE-2026-41089) carrying a Common Vulnerability Scoring System (CVSS) score of 9.8. This surge is mirrored across the enterprise ecosystem, with Oracle transitioning to a rapid monthly patching model to fix 77 vulnerabilities, Google patching its fifth Chrome browser zero-day of the year (CVE-2026-11645), and Veeam releasing emergency fixes for a critical Backup & Replication flaw (CVE-2026-44963) that allows unauthenticated domain-level takeover. Oracle transitioned to a monthly patching cadence, releasing fixes for 77 vulnerabilities. CI operators using Oracle products should update their patch management schedules accordingly. Because adversaries are increasingly leveraging machine-assisted fuzzing to weaponize these disclosures within days, Florida entities must establish compressed patch timelines to protect internet-facing infrastructure and backup servers.

Sophisticated Supply Chain Tactics Weaponize Open-Source Repositories and AI Coding Tools Security researchers have uncovered distinct software supply chain campaigns engineered to infect upstream development blocks and autonomous programming environments. The ‘Miasma’ campaign infected over 100 npm packages including Red Hat Cloud Services packages and extended into Microsoft Azure and GitHub repositories. Miasma demonstrated worm-like self-propagation by stealing developer credentials to automatically infect and republish additional packages, which extended the compromise from individual developers to entire organizational code repositories. While the ‘Hades’ campaign poisoned 19 PyPI packages to execute automated credential-harvesting scripts. Because the malware executes at Python interpreter startup (not only at runtime of the specific package), any Python environment that has installed the package is at risk even if the package is never imported. Additionally, researchers demonstrated successful security scanner bypasses on Vercel and Cisco platforms, illustrating that automated code-review tools fail to catch malicious AI agent extensions, meaning Florida development teams must implement strict cryptographic dependency validation and code signing.

Acer Working to Patch Max Severity Zero-days in Wave 7 Routers Acer is developing patches for two maximum-severity zero-day vulnerabilities in its Wave 7 mesh routers. One flaw, CVE-2026-49200, involves a broken access control issue allowing unauthenticated attackers to remotely access plaintext credentials stored in log archives. The vulnerability affects routers running firmware version T7c_GBL_1.01.000055 or earlier. Successful exploitation provides an immediate path for initial access and lateral movement within compromised networks.

Cisco Warns of Available PoC for Critical Unified CM Vulnerability Cisco released patches for a high-severity server-side request forgery (SSRF) vulnerability (CVE-2026-20230) affecting Unified Communications Manager (Unified CM) and Session Management Edition (SME). The flaw stems from insufficient input validation in specific HTTP requests, allowing unauthenticated attackers to send crafted requests to internal systems. Cisco warned that proof-of-concept (PoC) code is publicly available, drastically compressing the timeline between patch release and weaponization. This development aligns with the strategic warning regarding AI-assisted machine-speed exploitation, necessitating rapid remediation to outpace automated threats.

Information Technology Sector Recommendations:

  • Implement strict application whitelisting and endpoint execution controls for all developer tooling, integrated development environment (IDE) plugins, and third-party extension marketplaces.
  • Enforce automated secrets-scanning utilities across all internal repositories, code pipelines, and cloud-hosted environments to rapidly discover and revoke exposed keys or cloud credentials.
  • Mandate the complete network segmentation of enterprise backup infrastructure (specifically Veeam architectures) from the primary active directory domain to prevent cross-compromise during ransomware operations.
  • Transition infrastructure administration pipelines to a strict Zero Trust model, enforcing phishing-resistant multi-factor authentication and continuous device posture verification.
  • Establish formal software dependency review protocols, utilizing cryptographic verification and strict commit controls to evaluate open-source Python (PyPI) and JavaScript (npm) additions before introduction into local development chains.
  • Review Exchange Online configurations for the Ghost-Sender bypass and audit ServiceNow tenant access logs for unauthorized activity.
Nuclear Reactors, Materials, and Waste Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Transportation Systems Sector

Delivery Mega Leak: 840M+ Files Exposed as US Delivery Company Leaks Massive File Storage Security researchers identified a major cloud database exposure involving SpeedX, a prominent U.S.-based delivery and logistics company, which inadvertently left over 840 million records accessible to the public internet without authentication. The leaked dataset contained highly sensitive corporate and consumer assets, including customer delivery details, unredacted shipping labels, warehouse photographs, and official driver identification documentation. While SpeedX characterizes the incident as a cloud storage configuration issue rather than a confirmed breach, Cybernews researchers dispute this, asserting the exposed container was accessible to anyone who knew the container name. Regardless of characterization, the incident demonstrates the catastrophic scale of data exposure possible from misconfigured cloud storage in transportation logistics environments. The massive exposure highlights the catastrophic privacy and supply chain risks facing transportation hubs that fail to properly audit automated cloud storage environments, making rigorous access control verification necessary for regional logistics providers.

Qilin Ransomware Claims Hack of Major New York and New Jersey Shipping Association The Qilin ransomware group claimed responsibility for a targeted network intrusion against the New York Shipping Association, a vital maritime organization supporting cargo logistics at one of North America’s busiest ports. Although the full operational impact is still being evaluated, the attack represents a direct threat to maritime supply chains, as disruptions to shipping association networks can rapidly trigger cascading delays across port terminal operations, cargo movements, and regional economic activity. This incident serves as an immediate warning for Florida’s major commercial maritime hubs proving that third-party maritime service organizations are primary targets for ransomware syndicates.

Transportation Systems Sector Recommendations:

  • Separate public information display systems, scheduling applications, and passenger portals from core operational transit control planes into distinct, firewalled network zones.
  • Implement immutable offline system state backups and verified gold-image snapshots to facilitate rapid bare-metal recovery following potential data-wiping or ransomware events.
  • Review cloud storage configurations, object bucket access controls, and data exposure settings for all logistics platforms, enforcing regular security audits over third-party transportation technology providers.
  • Conduct ransomware readiness exercises specifically focused on maritime logistics, validating network segmentation boundaries and backup integrity across port community systems and shipping association networks.
  • Assess and strengthen enterprise resilience against Positioning, Navigation, and Timing (PNT) vulnerabilities by establishing secondary, out-of-band communication and redundant tracking workflows for local logistics fleets.
Water and Wastewater Systems Sector

GAO: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector The U.S. Government Accountability Office (GAO) warned that many drinking water and wastewater utilities across the United States continue to lack fundamental cybersecurity protections. The report found that numerous utilities still do not maintain basic asset inventories, incident response plans, or adequate segmentation between operational technology (OT) and information technology (IT) networks. These deficiencies leave critical water infrastructure vulnerable to cyberattacks that could disrupt service delivery and pose risks to public health and the environment. The GAO called for stronger federal support and sector-wide actions to close long-standing cybersecurity gaps.

Cyber Intel Brief: Handala Claims Breach of California Water Service On June 11, 2026, the Iranian-affiliated threat actor Handala compromised California Water Service, releasing a five-gigabyte dump of customer personally identifiable information and administrative credentials. The adversaries breached an open-source RTKBase GPS correction server on port 10000 and a customer billing database across seven districts, including Chico, California. Critically, there is no evidence of operational technology (OT) or industrial control systems (ICS) compromise. Handala’s claims of disruptive capabilities against water treatment processes remain unproven. This incident highlights vulnerabilities in municipal water infrastructure, signaling elevated risk for Florida utilities operating exposed mapping portals without rigid IT and OT network segmentation.

Water and Wastewater Systems Sector Recommendations:

  • Use automated network mapping to guarantee SCADA networks and PLCs have no unauthenticated public internet exposure.
  • Close GAO-identified gaps by maintaining a comprehensive inventory of all OT assets and hardening the boundary between IT and OT networks.
  • Maintain offline, validated backups to support recovery from disruptive cyber incidents affecting operational technology environments.
  • Actively engage with federal and state funding channels to offset budget shortfalls for cybersecurity posture improvements in smaller districts.

CI Bulletin Vol 2, Issue 9 June 23, 20262026-06-22T14:10:45-04:00

CI Bulletin Vol 2, Issue 8 June 9, 2026

Florida Critical Infrastructure Cybersecurity Intelligence

This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.

Situational Awareness Bulletin #10-2026
Cyber Threat Outlook

Over the next six to nine months, Florida’s critical infrastructure operators face escalating pressure from three reinforcing threats: Iranian state-sponsored actors targeting energy, water, and transportation OT systems; financially motivated extortion groups exploiting third-party vendors in education, healthcare, and commercial facilities; and automated vulnerability exploitation that is closing the gap between disclosure and weaponization faster than most organizations can patch. The 2026 Verizon Data Breach Investigations Report confirmed that exploitation of unpatched vulnerabilities has surpassed credential theft as the leading breach entry point — a structural shift that favors well-resourced adversaries and penalizes organizations slow to remediate. CISA’s CI Fortify initiative signals that federal planners now treat destructive OT attacks as a near-term contingency, not a theoretical risk. The campaign against LA Metro and ongoing Iranian targeting of gas-station tank gauges and PLCs in water and energy systems demonstrate transferable risk to Florida’s ports, utilities, and transit networks. Critical infrastructure owners should treat supply chain vendors, contractor-managed cloud accounts, and internet-exposed OT devices as the highest-priority attack surface for the foreseeable future.

Confidence – High

Executive Summary
  • All Sectors: CISA’s CI Fortify initiative and continued Iranian OT targeting require Florida operators to test manual fallback procedures and close contractor access gaps.
  • Commercial Facilities: ShinyHunters breached 7-Eleven, exposing personal data on 185,300 individuals after holding the data for ransom and then leaking it publicly.
  • Communications: Major U.S. telecoms launched the C2 ISAC, a new sector-specific threat-sharing body; a Huawei zero-day caused a nationwide telecom outage in Luxembourg.
  • Critical Manufacturing: Nitrogen ransomware breached Foxconn’s North American facilities, exfiltrating 8 TB of data and disrupting production; Four-Faith router exploitation continues at scale.
  • Defense Industrial Base: Iranian APT Seedworm (MuddyWater) maintains persistent access inside a U.S. defense and aerospace software supplier using the previously undocumented Dindoor backdoor.
  • Energy: NEMA and NERC warn of growing data-center grid strain; Iranian actors have breached unprotected automatic tank gauge systems at gas stations across multiple states.
  • Government Services and Facilities: ShinyHunters’ Canvas breach directly hit USF and multiple Florida school districts; Chelan County’s full network shutdown illustrates ransomware risk for Florida municipalities; federal cyber grant reauthorization is in jeopardy.
  • Healthcare and Public Health: OpenLoop Health breach exposed 716,000 individuals; a ransomware attack at another hospital allegedly caused an infant’s death; NYC Health + Hospitals vendor breach exposed 1.8 million patients.
  • Information Technology: Exploited vulnerabilities in Drupal, Gitea, Notepad++, and SonicWall SSL-VPN, combined with GitHub supply chain compromises and novel blockchain-based malware, expand attack surface across developer and CI environments.
  • Transportation Systems: Iranian state-linked actors breached LA Metro in a destructive attack that required weeks of recovery — directly transferable risk to Florida ports, transit, and aviation.
  • Water and Wastewater Systems: CISA CI Fortify guidance is directly applicable to Florida water utilities, which face continued Iranian PLC targeting and reduced federal support.
All Sectors

CISA Unveils New Initiative to Fortify America’s Critical Infrastructure The Cybersecurity and Infrastructure Security Agency (CISA) launched the CI Fortify initiative on May 5, 2026, urging critical infrastructure operators, particularly in energy, water, and government facilities, to prepare for “weeks to months” of information technology/operational technology (IT/OT) isolation and manual operations in the event of sustained state-sponsored cyber campaigns. The guidance emphasizes proactive network segmentation, offline backups of system configurations, and regular drills of manual fallback procedures. It is important to note that the initiative’s planning assumption is that adversaries may already have a foothold inside OT networks during a conflict scenario, requiring operators to plan for continuity under a ‘communications-degraded’ environment in which external vendors, internet connectivity, and third-party dependencies may be unavailable. This is directly relevant to Florida, whose hurricane-prone utilities, ports, and water systems already face compounded risks from Iranian-linked OT targeting campaigns that continue to probe internet-exposed programmable logic controllers.

CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on May 21, 2026, based on confirmed active exploitation in the wild. The additions include CVE-2026-41091 (a link-following vulnerability) in the Microsoft Malware Protection Engine that enables local privilege escalation to SYSTEM level) and CVE-2026-45498 (Microsoft Defender denial of service), along with several legacy but still-weaponized flaws. These vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to federal, state, local, and critical infrastructure entities. Florida operators of Microsoft Defender, Windows systems, and related OT environments should apply patches immediately to prevent privilege escalation and service disruption. Organizations that disable automatic Microsoft Defender engine updates, including some OT-adjacent environments, should verify manually that engine version 1.1.26040.8 or later is installed.

Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector Verizon’s 2026 Data Breach Investigations Report (DBIR) found that vulnerability exploitation surpassed credential theft as the leading initial access vector in confirmed breaches. The DBIR analyzed more than 31,000 security incidents, of which more than 22,000 were confirmed breaches. Approximately 31% of breaches involved exploitation of unpatched vulnerabilities, highlighting the growing impact of internet-facing systems and delayed remediation cycles. Third-party involvement also rose sharply, reaching 48% of confirmed breaches. That represents a 60% year-over-year increase underscoring the growing risk of vendor and contractor access across CI environments. The report emphasized that organizations continue to struggle with patch management timelines and exposure to third-party applications. These findings reinforce concerns that cyber threat actors are increasingly prioritizing automated exploitation of known vulnerabilities across critical infrastructure sectors.

CISA Admin Leaked AWS GovCloud Keys on Github A public GitHub repository managed by a CISA contractor (Nightwing) inadvertently exposed credentials for several highly privileged Amazon Web Services (AWS) GovCloud accounts as well as a large number of internal CISA systems. The leak prompted legislators to request an urgent classified briefing within 24 hours. This incident underscores persistent third-party and supply chain risks, where basic credential hygiene and repository security failures can have cascading effects. Notably, the contractor had disabled GitHub’s built-in secret-scanning protections, underscoring that policy-level controls are insufficient without enforced technical guardrails that prevent circumvention. Florida critical infrastructure owners and operators should apply the same rigorous scrutiny to contractor-managed code repositories and third-party cloud environments that they apply to external vendors.

Security Update for LiteSpeed cPanel Plugin CISA added CVE-2026-48172, a critical privilege-escalation vulnerability in the LiteSpeed user-end cPanel plugin (before version 2.4.5), to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw allows any authenticated cPanel user, including low-privileged or compromised accounts, to execute arbitrary scripts with root privileges, meaning a single compromised hosting account on a shared server is sufficient for full system takeover. LiteSpeed resolved the issue in version 2.4.5. This development is highly relevant to Florida state agencies, school districts, municipal utilities, and other critical infrastructure entities that use cPanel-hosted web services for public-facing systems.

FBI Warns Extortion Hackers are Visiting US Law Firms to Steal Data The FBI has issued a warning about the Silent Ransom Group (SRG), a cyber extortion gang with roots in the Conti ransomware syndicate that is actively targeting U.S. law firms using an unusually bold mix of phishing, fake IT calls, and in-person office visits. The group’s tactics are exceptionally hard to detect: attackers use legitimate remote management tools and transfer stolen data through trusted platforms such as Google Drive and Microsoft OneDrive, blending in with normal IT activity. Notably, SRG deploys no ransomware encryption — systems remain fully operational throughout the attack with no locked files or ransom screens, making the intrusion effectively invisible until an extortion email arrives. SRG’s reach extends beyond legal services—the FBI notes the group has also hit organizations in healthcare, insurance, and financial sectors. This is pertinent to all Florida critical infrastructure sectors, and law firms frequently hold sensitive legal, financial, and corporate data for CI operators. SRG has been active since at least 2022. They have compromised data from more than 38 law firms, with at least 100 confirmed attacks as of Spring 2026.

All Sectors Recommendations:

  • Implement phishing-resistant multi-factor authentication and the principle of least privilege on all managed service provider remote access connections to prevent adversaries from pivoting into downstream municipal utility networks.
  • Identify all internet-facing VNC instances and secure them behind a virtual private network with multi-factor authentication to prevent unauthorized manipulation of industrial controls.
  • Develop and test manual fallback procedures for all life-safety services to ensure operational resilience during a sustained cyber outage.
  • Shift toward automated vulnerability management to reduce exposure windows as artificial intelligence-assisted exploitation compresses the time between disclosure and weaponization.
  • Audit all third-party and contractor-managed code repositories, cloud credentials, and privileged service accounts, and the use of cloud collaboration tools (such as Google Drive and Microsoft OneDrive) for exposed secrets or misconfigured access controls.
  • Immediately inventory, patch, or isolate systems affected by newly added CISA KEVs to prevent active exploitation.
Chemical Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Commercial Facilities Sector

185,000 Likely Impacted by 7-Eleven Data Breach 7-Eleven has confirmed that it was the victim of a data breach. An April 8, 2026 breach of 7-Eleven systems, via their Salesforce environment, exposed personal information (including names, dates of birth, email addresses, phone numbers, and physical addresses) affecting roughly 185,300 individuals. The ShinyHunters extortion group claimed responsibility, initially demanding ransom and later offering the data for sale on a Russian hacking forum. This incident highlights ongoing risks to commercial facilities from extortion groups like ShinyHunters, which have also targeted education vendors serving Florida school districts and higher-education institutions.

Commercial Facilities Sector Recommendations:

  • Conduct regular third-party risk assessments of vendors and service providers that handle customer or employee personally identifiable information (PII).
  • Implement robust data encryption, access controls, and data-loss-prevention monitoring on systems containing sensitive personal or financial data.
  • Develop and regularly test incident response playbooks specifically for data-extortion campaigns, including protocols for ransom demands and mandatory breach notification.
  • Monitor closely for anomalous data exfiltration, especially involving legitimate cloud storage and file-sharing platforms commonly abused by groups like ShinyHunters.
  • Provide targeted security awareness training for staff on advanced social engineering, phishing, and impersonation tactics used in these extortion operations.
Communications Sector

Telecom Sector Launches its Own Private ISAC Major U.S. telecommunications providers launched the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC) to improve coordination against AI-enabled cyberattacks, espionage, and nation-state threats targeting communications infrastructure. The initiative aims to strengthen collaboration between telecommunications companies and government cybersecurity partners. Officials warned that adversaries continue targeting telecom infrastructure to support surveillance, espionage, and operational disruption campaigns. This development is relevant to Florida as the state’s extensive network of MSPs provides foundational support for municipal utilities and local government services.

Huawei Zero-day Attack Behind Last Year’s Crash of Luxembourg’s Entire Telecoms Network An attack exploiting a previously undisclosed vulnerability in Huawei enterprise router software caused a nationwide telecom outage in Luxembourg, disrupting mobile, landline, and emergency communications for more than three hours. As of this reporting, the vulnerability has not been publicly disclosed or assigned as a CVE identifier. Because no CVE has been assigned, operators cannot rely on standard vulnerability management tools to identify this exposure — network inventory and manual review of Huawei equipment are the only current detection paths. This incident highlights persistent supply-chain risks associated with Chinese-manufactured networking equipment in critical communications infrastructure. Florida’s telecommunications providers, managed service providers, and municipal utilities that rely on similar enterprise routing and OT networking hardware should review Huawei equipment inventories and consider immediate segmentation or replacement strategies where feasible.

Communications Sector Recommendations:

  • Enforce strict multi-factor authentication and the principle of least privilege on all managed service provider remote access connections to prevent adversaries from pivoting into downstream municipal utility networks.
  • Monitor telecommunications and managed service provider environments continuously for unauthorized affiliate activity or staging of data exfiltration tools that typically precede ransomware deployment.
  • Prepare contingency plans to immediately sever or isolate administrative access from managed service providers if anomalous activity or cascading ransomware attempts are detected.
  • Inventory all enterprise routers and OT networking hardware for Huawei or other high-risk vendors and implement strict network segmentation or accelerated replacement to mitigate undisclosed zero-day supply-chain risks.
Critical Manufacturing Sector

Ransomware Hackers Claim Breach at Foxconn, Major Electronics Manufacturer for Apple, Google, and Nvidia The Nitrogen ransomware group claimed responsibility for breaching Foxconn’s North American facilities in Mount Pleasant, Wisconsin and Houston, Texas, alleging theft of more than 11 million files totaling 8 terabytes (TB) of data, including confidential instructions, internal project documentation, technical drawings (including circuit board layouts and integrated circuit documentation), financial files, and temperature sensor records — tied to projects for Apple, Intel, Google, Dell, Nvidia, and AMD. The affected plants have resumed normal production, but the incident highlights downstream supply chain risk to U.S. critical manufacturing. This is highly relevant to Florida, where ports in Jacksonville, Tampa, and Miami serve as key logistics hubs for electronics and aerospace components.

CVE-2024-9643: Four-Faith Router Authentication Bypass Fuels Botnet Activity CrowdSec researchers reported a surge in exploitation of Common Vulnerabilities and Exposures (CVE)-2024-9643, a critical authentication-bypass flaw with hard-coded credentials in Four-Faith F3x36 industrial cellular routers. The activity has escalated into large-scale botnet campaigns targeting utilities, warehouses, and critical infrastructure. These routers are commonly deployed in remote monitoring and operational technology (OT) environments. Florida municipal utilities, water systems, and energy providers using similar industrial routers should immediately inventory, patch, or isolate these devices.

CVE-2026-8153: Command Injection in the PolyScope 5 Dashboard Server Universal Robots disclosed and patched a critical command injection vulnerability (CVE-2026-8153) in the Dashboard Server interface of its PolyScope 5 operating system used on collaborative robots deployed across operational technology environments. The flaw allows unauthenticated remote attackers to execute arbitrary commands, potentially compromising system integrity and physical security safety. Collaborative robots are widely used in manufacturing, energy, and logistics facilities. This development is highly relevant to Florida’s aerospace, critical manufacturing, and port logistics clusters that employ Universal Robots systems.

Critical Manufacturing Sector Recommendations:

  • Harden remote access gateways and segment manufacturing networks from corporate IT systems to limit lateral movement during supply-chain ransomware incidents.
  • Implement immutable offline backups of engineering schematics and design files to ensure rapid recovery without paying ransoms.
  • Conduct immediate third-party risk assessments of electronics and component suppliers to identify exposure from large-scale breaches such as the Foxconn incident.
  • Inventory all collaborative robots and industrial cellular routers (Universal Robots PolyScope and Four-Faith F3x36) for exposed interfaces and apply available patches or implement strict network segmentation.
Dams Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Defense Industrial Base Sector

Iran-Linked Seedworm Maintains Persistent Access in U.S. Defense Supply Chain Networks Symantec reporting (continuing through recent days) describes Iranian APT Seedworm targeting the Israeli operation of a U.S. software company that supplies defense and aerospace. The campaign, which began in early February 2026, is ongoing, and that the activity correlates with U.S. and Israeli military strikes on Iran. The attack using a new Dindoor backdoor and a second, separate Python-based backdoor called Fakeset on networks of a U.S. airport and nonprofit, to engage in espionage and potential follow-on disruption against defense-related environments in the U.S. and allied countries. This activity underscores persistent supply-chain risks to the Defense Industrial Base from Iranian cyber threat actors. Florida’s aerospace clusters and defense contractors should conduct immediate third-party risk assessments of software suppliers.

Defense Industrial Base Sector Recommendations:

  • Conduct rigorous and recurring third-party risk assessments of all software suppliers and service providers supporting defense and aerospace operations, with focused scrutiny on potential Iranian-linked activity.
  • Implement continuous monitoring and behavioral analytics to detect persistent access, backdoors (such as Dindoor), and anomalous activity originating from supply-chain compromises.
  • Enforce strict network segmentation and least-privilege principles between supplier-managed systems and critical internal networks to limit lateral movement.
  • Verify the integrity of all third-party software updates and components prior to deployment in operational environments.
  • Develop and regularly test incident response plans tailored to nation-state supply-chain attacks involving long-term espionage and potential disruptive follow-on operations.
Emergency Services Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Energy Sector

US Annual Electricity Consumption to Grow 55% by 2050: NEMA The National Electrical Manufacturers Association (NEMA) forecast shows accelerating electricity demand from data centers, straining U.S. utilities and raising affordability concerns. Florida utilities are already experiencing similar grid pressure from artificial intelligence (AI)-driven data-center growth.

NERC 2026 Summer Reliability Assessment North American Electric Reliability Corporation’s (NERC) 2026 Summer Reliability Assessment warned that accelerated electricity demand, rapid growth of large data-center loads, and extreme heat conditions may strain portions of the North American electric grid. The assessment highlighted increasing operational pressure associated with AI-driven infrastructure expansion, maintenance outages, and periods of reduced renewable energy generation. Several regions may experience elevated reserve shortfalls during sustained peak-demand conditions. Florida utilities may face similar reliability and operational challenges during hurricane season and summer heat events.

Hackers Have Breached Tank Readers at US Gas Stations; Officials Suspect Iran is Responsible U.S. officials suspect Iranian-linked actors are responsible for a series of breaches targeting automatic tank gauge (ATG) systems. Notably, the affected systems were internet-exposed and unprotected by passwords, which represents a basic configuration failure. CI operators should immediately verify that all ATG systems are removed from the public internet or placed behind password-protected access controls. The attacks focus on operational technology used for real-time inventory and distribution management rather than traditional information technology (IT) networks. The attackers capability, however, was limited to manipulating display readings, not actual fuel levels or distribution flows. U.S. officials suspect Iranian-linked actors are responsible, though a lack of forensic evidence means definitive attribution has not been confirmed. If confirmed, the activity would represent continued Iranian interest in disrupting or gathering intelligence on U.S. energy infrastructure. The incidents are highly relevant to Florida’s extensive fuel distribution networks, ports, and municipal energy providers that rely on similar tank-gauge and monitoring systems.

PJM Gets Emergency Approval to Curtail Data Centers, Large Loads During Hot Weather The Department of Energy authorized PJM Interconnection to curtail power usage by large facilities with backup generation capability, including data centers, amid reserve shortages caused by extreme heat and maintenance outages. The emergency authority reflects growing operational stress on energy infrastructure that supports AI-driven data-center growth and increasing electricity demand. Grid operators continue evaluating emergency procedures to maintain system stability during high-load events. The incident also highlights increasing dependence on resilient backup-generation systems across critical infrastructure sectors.

CI Fortify: Strengthening Resilience Across Critical Infrastructure Iranian-linked actors continue to target internet-exposed PLCs and SCADA systems in the water and energy sectors. CISA’s CI Fortify guidance explicitly calls for OT isolation and manual operations readiness—directly applicable to Florida’s energy providers.

Energy Sector Recommendations:

  • Verify that all operational technology (OT) assets, particularly Rockwell Automation and Allen-Bradley programmable logic controllers, are removed from the public internet or placed behind strict network segmentation.
  • Store critical OT configurations and backups in immutable offline formats to enable manual operations during sustained cyber campaigns.
  • Audit third-party vendor accounts and monitor for anomalous remote access to smart-grid and energy-management systems.
  • Inventory and segment all operational technology assets used for fuel storage, tank monitoring, and distribution systems, ensuring they are not internet-exposed and are protected by strict network segmentation.
Financial Services Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Food and Agriculture Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Government Services and Facilities Sector

Aurora Lost Nearly $1.1M from City Bank Accounts After Employee Fell for Phone Scam Authorities in Aurora, Illinois are investigating a cyber-enabled fraud incident that resulted in approximately $1.1 million being transferred from municipal accounts after an employee reportedly fell victim to a phone scam. The incident reflects continuing business email compromise and social-engineering threats targeting local governments and public-sector financial operations. Cyber threat actors increasingly use impersonation techniques and financial fraud schemes to exploit municipal payment processes. Florida municipalities and tourism-dependent communities remain vulnerable to similar financially motivated cyber campaigns.

Chelan County WA Government Shuts Down Networks After Cyberattack Chelan County officials shut down all government computers, networks, and telephone systems on Memorial Day after detecting a malware attack that impacted every county department. The county’s information technology (IT) department identified the malware at 10 a.m. and immediately isolated systems as a safety precaution. Emergency services remained operational. This incident serves as a direct tactical analog for Florida’s numerous county and municipal government facilities that routinely handle high-volume administrative and public safety systems.

State IT Officials Make a Case for Cyber Grant Reauthorization Before House Subcommittee Florida’s Chief Information Officer and technology leaders from Tennessee and New York testified before the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection regarding the now-unfunded State and Local Cybersecurity Grant Program (SLCGP). The officials highlighted how the grant program has improved state and local network defenses and urged Congress to reauthorize funding amid escalating nation-state threats and reduced federal support. This testimony is directly relevant to Florida’s municipal, county, and educational networks, which rely on these grants to maintain resilience against ransomware, operational technology (OT) targeting, and supply chain risks.

Canvas Hack: Company Pays Criminals to Delete Students’ Stolen Data Instructure (provider of the widely used Canvas learning management system) reached an agreement with the ShinyHunters group after a major breach that exposed student and staff data from 275 million records across approximately 9,000 institutions, including names, email addresses, student ID numbers, and private messages between students and instructors. across thousands of educational institutions. Instructure reportedly paid a ransom to the ShinyHunters group, receiving digital confirmation that exfiltrated data was destroyed, though no certainty exists that the cybercriminals honored the agreement. The FBI’s Internet Crime Complaint Center (IC3) issued a separate advisory on May 15, 2026 warning students and staff that ShinyHunters may directly contact individuals whose data was exposed. The incident directly impacted the University of South Florida (USF) in Tampa as well as Hillsborough County Public Schools, Pinellas County Schools, and other Florida districts, underscoring the systemic risk to Florida’s K-12 and higher-education systems that rely on third-party education vendors.

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment Attackers have exploited a zero-day vulnerability in KnowledgeDeliver, a widely used learning management system (LMS). The flaw stemmed from hardcoded ASP.NET machineKey values shared across installations. With these keys, cyber threat actors performed ViewState deserialization attacks to achieve remote code execution and deployed web shells. This incident demonstrates that cyber threat actors continue to pursue LMS platforms used by schools and government entities. The development is highly relevant to Florida’s K-12 and higher-education systems as well as municipal government facilities that rely on similar third-party administrative and education platforms.

Government Services and Facilities Sector Recommendations:

  • Train staff to verify all financial requests through out-of-band channels before initiating wire transfers or payments.
  • Implement strict multi-factor authentication and least-privilege controls on email and financial systems used by municipal staff.
  • Conduct regular phishing simulations and rigorous vendor risk assessments of third-party learning management systems (LMS), education platforms, and administrative software to reduce exposure to supply-chain and zero-day vulnerabilities.
  • Inventory, promptly patch (or isolate) all internet-facing third-party LMS and web-based administrative applications, with special attention to hardcoded credentials, shared configuration keys, and web-shell risks.
  • Maintain and regularly test offline backups and manual fallback procedures for all county and municipal administrative systems to ensure continuity during ransomware or malware-induced outages.
  • Advocate for and prepare contingency plans around reauthorization of the State and Local Cybersecurity Grant Program to sustain network defenses amid reduced federal support.
Healthcare and Public Health Sector

OpenLoop Health Data Breach Affects 716,000 Individuals OpenLoop Health disclosed a breach exposing names, addresses, email addresses, dates of birth, and medical information (but not Social Security Numbers) of approximately 716,000 individuals. The incident aligns with the broader pattern of persistent data-theft and extortion campaigns targeting the U.S. healthcare sector. Florida’s large healthcare network and retiree population make this a continuing high-priority risk.

Data Breach on New York Public Health System Claims 1.8M Victims, Leaking Biometric Data to Hackers NYC Health + Hospitals confirmed that a vendor-related compromise exposed sensitive patient data, including biometric data, affecting approximately 1.8 million individuals after attackers reportedly maintained access to systems for several months. Exposed information included protected health information and personally identifiable information tied to healthcare operations. The incident highlights the ongoing risks associated with third-party vendors and healthcare-sector supply chain exposure.

Hospital Ransomware Attack Led to Infant’s Death, Lawsuit Alleges A hospital ransomware attack allegedly led to an infant’s death, according to a lawsuit. The incident highlights the severe life-safety risks when ransomware disrupts critical healthcare operations and patient care systems. This is directly relevant to Florida’s large healthcare network and retiree population, where ransomware continues to threaten both patient data and care continuity.

Healthcare and Public Health Sector Recommendations:

  • Isolate electronic health record systems and medical devices on segmented networks to prevent lateral movement during ransomware incidents.
  • Maintain and regularly test manual downtime procedures for all critical patient care and life-safety systems to sustain operations and protect patient safety during IT outages or ransomware events.
  • Perform rigorous third-party risk assessments of billing and health-data vendors to limit exposure from supply-chain breaches.
  • Prioritize patient safety and life-safety system continuity in all ransomware incident response planning and conduct regular drills focused on rapid transition to manual operations.
Information Technology Sector

CISA Releases 18 New ICS Advisories Cybersecurity and Infrastructure Security Agency (CISA) released 18 new industrial control system advisories on May 14, 2026, detailing remotely exploitable vulnerabilities in products used across manufacturing, emergency communications, and supporting OT environments. Florida operators of these systems should apply patches immediately.

GitHub Confirms Breach of 3,800 Repos via Malicious VSCode Extension GitHub confirmed that approximately 3,800 internal repositories were compromised after an employee installed a malicious Visual Studio Code extension. The incident demonstrates the growing threat posed by software supply chain compromises targeting trusted developer environments and third-party extensions. Additional organizations, including major technology firms and artificial intelligence (AI) companies, were reportedly impacted by related activity. The compromise reinforces concerns about dependency trust, extension security, and vulnerabilities in the software development ecosystem.

CISA Adds One Known Exploited Vulnerability to Catalog CISA has added CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core’s database abstraction API, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The agency ordered federal agencies to patch by May 27, 2026. Drupal is widely used by government agencies, educational institutions, and critical infrastructure entities for managing large-scale websites and content. Florida state agencies, school districts, and municipal utilities running Drupal instances should apply patches immediately to prevent unauthorized database access and potential lateral movement.

Exposing Fox Tempest: A Malware-signing Service Operation Microsoft identified Fox Tempest as a financially motivated cyber threat actor operating a malware-signing-as-a-service platform used by cybercriminals and ransomware operators. The group abuses Microsoft Artifact Signing to generate fraudulent short-lived certificates that allow malicious software to appear legitimate and evade traditional security controls. The operation demonstrates the increasing sophistication of ransomware enablement services and malware delivery infrastructure. Security researchers warned that signed malware continues posing significant detection and trust challenges for defenders.

Patch Bypass Allows Hackers to Exploit Prior Flaw in SonicWall SSL-VPN Cyber threat actors continue to exploit a SonicWall Secure Sockets Layer virtual private network (SSL-VPN) vulnerability that enables attackers to bypass multifactor authentication protections during automated brute-force attacks. Researchers warned that a patch bypass allowed exploitation activity to continue despite earlier remediation efforts. SSL-VPN appliances remain at frequent targets for ransomware operators and cybercriminal groups seeking remote access into enterprise environments. Organizations relying on internet-facing VPN infrastructure continue facing elevated risks from credential attacks and remote-access exploitation.

ClearFake Abuses BSC Testnet Contracts for Resilient C2 Operations Cyber threat actors behind the ClearFake campaign have adopted a novel and highly resilient command-and-control (C2) architecture by leveraging BNB Smart Chain (BSC) testnet smart contracts. This approach embeds malicious JavaScript and instructions within immutable blockchain storage. That means that standard threat intelligence feeds and domain blocklists are ineffective against this C2 channel, so defenders must instead focus on monitoring anomalous outbound connections and JavaScript injection patterns. That makes the infrastructure effectively immune to traditional takedown efforts. The tactic expands supply-chain and developer-pipeline risks for Florida critical infrastructure entities that rely on third-party IT tools and extensions.

Hackers Host JS Malware GHOSTYNETWORKS and OMEGATECH Hackers are abusing two bulletproof hosting providers, GHOSTYNETWORKS and OMEGATECH, to run a global JavaScript (JS) malware infrastructure that powers large-scale malspam and business email compromise (BEC) activity. In March 2026, multiple malspam waves delivered a JavaScript backdoor via ZIP or RAR attachments to organizations across sectors, including energy companies and finance ministries. The financially motivated operators focus on email account compromise and BEC rather than espionage.

Gitea Vulnerability Exposes Private Container Images Without Authentication Cybersecurity researchers disclosed a security flaw in Gitea (CVE-2026-27771, CVSS 8.2) that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring credentials. The vulnerability affects all versions prior to 1.26.2 and likely impacts more than 30,000 deployments worldwide. Florida state agencies, school districts, and critical infrastructure operators running self-hosted Gitea instances should apply the patch immediately.

Critical Notepad++ Flaw Could Enable Remote Code Execution Attacks Notepad++ has released version 8.9.6.1 to address multiple critical vulnerabilities, including CVE-2026-48778, which could allow arbitrary code execution under specific conditions involving improper handling of configuration files. The update patches flaws in versions up to 8.9.6. Developers and administrators across Florida critical infrastructure environments should update immediately to prevent potential supply-chain compromise via developer tools.

Information Technology Sector Recommendations:

  • Apply all CISA Known Exploited Vulnerabilities catalog updates and the latest ICS advisories without delay.
  • Immediately inventory, patch, or isolate all Drupal installations, Gitea instances, and other internet-facing web applications, prioritizing those used by government, educational, and critical infrastructure systems.
  • Enforce strict package verification, code-signing validation, and security checks for all developer tools, extensions (including VSCode), and applications such as Notepad++ to prevent supply-chain and remote code execution attacks.
  • Implement strong authentication and access controls on self-hosted code repositories and container registries (such as Gitea) to block unauthenticated access to private container images and source code.
  • Monitor for and block malicious JavaScript malware campaigns, abuse of bulletproof hosting providers, and resilient C2 techniques such as blockchain-based infrastructure.
  • Scan and restrict internet-facing remote-access services (including SSL-VPN appliances) and apply patches immediately to counter bypass techniques and automated attacks.
  • Strengthen supply-chain security practices to defend against malware-signing-as-a-service operations (such as Fox Tempest) and third-party extension compromises.
Nuclear Reactors, Materials, and Waste Sector

No sector-specific incidents, advisories, or operationally relevant reporting were identified during this biweekly reporting period.

Transportation Systems Sector

Iranian Hackers Blamed for Breach of Los Angeles Transit System that Took Weeks to Recover Israeli cybersecurity firm Gambit Security attributed a March 2026 breach of the Los Angeles County Metropolitan Transportation Authority (LA Metro) to Iranian government-linked (MOSI) actors—Black Shadow–operating under a hacktivist cover persona of “Ababil of Minab”. Attackers used a virtual machine to delete critical operating system data, stole at least 700 GB of emails/backups/files, and forced multi-week network isolation and recovery. Gambit Security reported that attackers also reached a real-time rail yard control display system, crossing from administrative IT networks into OT territory — though no manipulation of physical operations has been confirmed. This incident demonstrates state-sponsored destructive capabilities against U.S. transportation OT/IT systems. Florida’s ports, transit authorities, and logistics networks that rely on similar interconnected systems should treat this as a transferable risk.

Iranian APT Targets Aviation, Software Companies with Updated Tools Iranian APT Nimbus Manticore has adopted new tactics and malware variants in campaigns against aviation and software companies. Recent operations used updated tooling that enhances persistence and evasion. This activity demonstrates continued Iranian state-sponsored focus on transportation and related supply-chain targets. Florida’s ports, aviation facilities, and transit networks should treat this as transferable risk and review vendor software supply chains.

Transportation Systems Sector Recommendations:

  • Monitor maritime traffic networks and commercial port environments for localized GPS spoofing attempts or electronic warfare interference.
  • Encrypt all vessel communication systems to prevent threat actors from intercepting sensitive navigation and logistics data.
  • Implement redundant positioning, navigation, and timing systems to maintain safe maritime operations if primary GPS signals are disrupted.
  • Audit and segment all virtual machines, remote-access tools, and OT/IT convergence points in transit and port systems to prevent destructive data-wiping attacks by state actors.
Water and Wastewater Systems Sector

CI Fortify: Strengthening Resilience Across Critical Infrastructure Iranian-linked actors continue to target internet-exposed PLCs and SCADA systems in the water and energy sectors. CISA’s CI Fortify guidance explicitly calls for OT isolation and manual operations readiness—directly applicable to Florida’s municipal water utilities.

Water and Wastewater Systems Sector Recommendations:

  • Immediately remove or isolate all internet-exposed programmable logic controllers and SCADA interfaces.
  • Develop and regularly test manual fallback procedures for water treatment and distribution operations.
  • Monitor anomalous changes to PLC project files and HMI configurations that could indicate manipulation attempts.
  • Accelerate the adoption of AI-assisted defensive tools and conduct regular third-party risk assessments of OT vendors in light of shrinking federal support for water-sector cybersecurity.
CI Bulletin Vol 2, Issue 8 June 9, 20262026-06-09T10:00:00-04:00

Career Launch Series: From SOCAP to Security Engineering

Sanaan Wani

Meet Sanaan Wani, an accomplished student, now a cybersecurity professional at Amazon

For recent USF graduate Sanaan Wani, cybersecurity has never been just a career path; it has been a challenge worth pursuing.

After years of competing, researching, building tools, and securing systems, Wani is now taking the next step in his professional journey. This summer, he will relocate to Dallas, Texas, to begin a full-time role as a security engineer with Amazon. Before graduation, however, he added another impressive accomplishment to an already distinguished résumé: the discovery and responsible disclosure of a software vulnerability that earned an official Common Vulnerabilities and Exposures (CVE) designation.

His journey reflects the hands-on learning, mentorship, and real-world experience that define Cyber Florida’s Security Operations Center Analyst Program (SOCAP).

Finding his place in cybersecurity

Wani graduated from USF in May with a degree in computer science, but his interest in cybersecurity began outside the classroom.

Toward the end of his freshman year, he started attending meetings hosted by USF’s cybersecurity student organizations and quickly discovered that protecting systems was more compelling to him than simply building software.

“I realized I found securing systems much more interesting than just building software,” Wani said.

That curiosity led him to become involved with CyberHerd, USF’s nationally recognized cybersecurity competition team, where he eventually served as blue team captain. Through competitions, training opportunities, and mentorship from coaches and faculty advisors, Wani developed both technical skills and a passion for solving difficult security challenges.

His path to joining the SOCAP began through Cyber Florida’s NIST-funded Industrial Control Systems (ICS) training program, where he learned from Cyber Florida faculty and staff and completed a SANS certification funded through the program. After successfully earning the certification, he applied to SOCAP and officially joined the team in August 2025.

Building skills through real-world security operations

As a SOCAP analyst, Wani worked alongside other students to help monitor and secure networks, investigate security incidents, and support clients across Florida.

His responsibilities ranged from incident response and threat analysis to developing operational improvements for the security operations center itself. One project involved collaborating with fellow SOCAP students to develop a SOC console designed to streamline ticket processing and accelerate response times.

“We do a bit of everything,” Wani said. “From weekly incident responses to writing threat advisories.”

The experience gave him exposure to the realities of cybersecurity operations while also allowing him to pursue emerging areas of research that interested him.

Discovering a vulnerability through AI-assisted research

Outside of his operational work, Wani has spent significant time exploring the intersection of artificial intelligence and cybersecurity. Inspired and encouraged by his CyberHerd teammate, Yeran Gamage, he began building his own autonomous tools to identify security weaknesses in open-source software projects.

“Seeing his success with finding vulnerabilities really inspired me,” Wani said. “He encouraged me to start looking into securing open-source software, which is what originally got me started in vulnerability research.”

Because open-source software powers much of today’s technology ecosystem, Wani saw vulnerability research as an opportunity to strengthen tools used by organizations around the world.

His AI-powered systems scan software repositories for potential security flaws. Once a possible issue is identified, he manually investigates the findings, validates the results, and determines whether the vulnerability could have broader security implications.

That process recently led to the discovery of CVE-2026-45675, a vulnerability in Open WebUI.

The flaw involved a race condition in the platform’s authentication process. During an initial deployment, the first user to log in is intended to become the system administrator. Because of the vulnerability, however, multiple users logging in simultaneously could potentially receive full administrator privileges.

In practical terms, that could allow an unauthorized individual to gain complete administrative control over the platform and its data.

Responsible disclosure in action

After identifying and validating the vulnerability, Wani followed the industry’s responsible disclosure process.

Because Open WebUI accepts vulnerability reports through GitHub, he submitted his findings directly to the project’s maintainers. The development team reviewed the report, verified the issue, implemented a fix, and ultimately assigned an official CVE identifier.

For Wani, the milestone was meaningful not simply because of the CVE designation itself, but because it validated the effectiveness of the research methodology he had been developing.

“I’ve been using my AI tooling to find and submit vulnerabilities for a while now,” he said. “Having this one fully verified, patched, and assigned a CVE was a nice nod that the methodology works.”

The accomplishment may be his first officially assigned CVE, but it is unlikely to be his last. He currently has additional vulnerability reports under review and remediation.

The power of mentorship

Wani credits much of his success to the mentors and teammates who encouraged him to pursue ambitious goals.

Within SOCAP, he found a culture that supported innovation and exploration. He points to Duy Dao, assistant security operations center manager, as a major influence on his interest in AI-driven security research.

“Duy encouraged us to consider new research and tools in the AI space,” Wani said. “He didn’t just talk about concepts; he built things and showed them to us.”

He also credits SOCAP Program Manager Ryan Irving for creating an environment where student accomplishments are recognized and celebrated.

“There was a point where I worried I wasn’t completing enough tickets because I was spending so much time focused on AI vulnerability research,” Wani said. “Ryan and Duy were incredibly supportive. They encouraged me to keep going and fully supported my work.”

That encouragement helped him continue pursuing research that ultimately resulted in a verified vulnerability disclosure and CVE assignment.

Looking ahead

With graduation complete, Wani is preparing for his next chapter as a security engineer at Amazon. Having previously interned with the company’s red team, he is eager to return and continue building his career in cybersecurity.

Beyond his professional goals, he hopes to make cybersecurity and artificial intelligence more accessible to broader audiences. One of his long-term aspirations is to create educational content that helps people better understand complex technical concepts.

“Breaking down complex technical concepts into ideas that are accessible and engaging for everyone is a fun challenge,” he said. “I think bridging that knowledge gap is incredibly important.”

Outside of cybersecurity, Wani channels his competitive nature into soccer and competitive gaming, particularly Counter-Strike 2 and Valorant.

Whether on the field, in competition, or researching the next vulnerability, he is constantly looking for opportunities to learn, improve, and push himself further. As he begins his professional career, his accomplishments already demonstrate what can happen when technical talent, curiosity, mentorship, and hands-on experience come together.

Career Launch Series: From SOCAP to Security Engineering2026-06-02T17:24:32-04:00

Cyber Florida Seeks Fla Residents for Fall CyberWorks Training Program

12-week virtual cybersecurity training program accepts Florida’s veterans, first responders, military spouses, government employees

June 1, 2026—Tampa, Fla—Cyber Florida is accepting applications for the Fall 2026 cohort of CyberWorks, its workforce development program designed to prepare Florida’s public-minded professionals for careers in cybersecurity. The new cohort begins in September 2026 and is available at no cost to eligible participants. The deadline to apply is August 31.

CyberWorks is a 12-week, fully virtual training program that guides participants toward earning the CompTIA Security+ certification, one of the most widely recognized credentials for entry-level cybersecurity roles. In addition to technical training, participants gain access to a network of peers and mentors, career-advancement support, and a collaborative learning community.

Cyber Florida welcomes applications from Florida residents who are:

  • Veterans
  • Transitioning military personnel
  • First responders
  • Military spouses
  • Government employees (federal, state, local, tribal, or territorial)

“Our goal with CyberWorks is to create opportunities for those who serve and support our nation to build new skills, advance their careers, and step confidently into Florida’s growing cybersecurity workforce,” said Cyber Florida’s CyberWorks Assistant Cyber Program Manager Mai Ensmann. “This program is designed to meet learners where they are and help them succeed.”

CyberWorks is funded by the DoW CIO Cyber Academic Engagement Office and the NSA National Centers of Academic Excellence in Cybersecurity Program.

Those interested are encouraged to apply early, as space is limited. For more information or to apply, visit the CyberWorks page on the Cyber Florida website. To hear from CyberWorks graduates, check out the CyberWorks playlist on the Cyber Florida YouTube channel.

Media Contact: Cyber Outreach Manager Jennifer Kleman, APR, CPRC
mailto:jennifer437@cyberflorida.org

 

ABOUT CYBER FLORIDA
The Florida Center for Cybersecurity at the University of South Florida, commonly referred to as Cyber Florida, was established by the Florida Legislature in 2014. Its mission is to position Florida as a national leader in cybersecurity through comprehensive education, cutting-edge research, and extensive outreach. Cyber Florida leads various initiatives to inspire and educate current and future cybersecurity professionals, advance applied research, and enhance cybersecurity awareness and safety of individuals and organizations.

Cyber Florida Seeks Fla Residents for Fall CyberWorks Training Program2026-06-16T09:59:10-04:00

Jack Voltaic® Tampa Strengthens Regional Cyber Readiness

Aligned Realistic Cyberattack Simulation Range

Successful Multi-Sector Cyber Exercise Strengthens Tampa Bay Preparedness

From May 18–20, 2026, Cyber Florida, in partnership with the Army Cyber Institute and a broad coalition of federal, state, local, military, academic, and private-sector partners, successfully completed the Jack Voltaic® Tampa Cyber Incident Exercise at the University of South Florida Marshall Student Center.

The three-day, immersive exercise simulated a coordinated cyberattack targeting Tampa Bay’s critical water infrastructure, creating cascading impacts across essential services and adjacent military operations. The event brought together decision makers and technical responders to test coordination, improve readiness, and strengthen cyber resilience across the region.

About Jack Voltaic®

Jack Voltaic® is an initiative led by the Army Cyber Institute designed to evaluate and enhance the resilience of communities surrounding U.S. military installations.

Because modern infrastructure systems are deeply interconnected, disruptions in cyber-physical systems, such as water, energy, transportation, and communications, can quickly ripple across both civilian and defense environments.

Since its launch in 2016, the Jack Voltaic® series has focused on:

  • Strengthening civil-military cyber coordination
  • Testing multi-sector incident response capabilities
  • Identifying infrastructure interdependencies and vulnerabilities
  • Improving regional resilience through realistic scenario-based training

The 2026 Tampa exercise built on this foundation with an expanded focus on operational execution and cross-sector integration.

Exercise Scenario: Coordinated Cyberattack on Water Infrastructure

Participants worked through a realistic, escalating cyber incident affecting water treatment and distribution systems in the Tampa Bay region. The scenario was designed to reflect the complexity of modern cyberattacks against operational technology (OT) and critical infrastructure environments.

Scenario progression included:

  • Corruption of vendor-managed PLC systems
  • Altered chemical setpoints impacting water treatment processes
  • Theft of sensitive utility operational data
  • Loss of SCADA control and degraded system visibility

These events created cascading operational challenges for utilities, emergency managers, and defense-supporting infrastructure, requiring coordinated response across multiple jurisdictions.

Exercise Objectives and Outcomes

The exercise successfully met its core objectives:

  1. Strengthening Regional Response Capabilities

Participants tested and refined the ability of the Tampa Bay region to respond to a sophisticated, multi-sector cyberattack under realistic operational pressure.

  1. Evaluating Emergency Management Under Stress

State and local agencies examined response coordination in an environment reflecting concurrent emergency demands and infrastructure disruption.

  1. Demonstrating Regional Leadership

The Tampa Bay region further established itself as a national leader in cyber incident preparedness and cross-sector collaboration.

  1. Assessing Defense Operational Impacts

The exercise highlighted potential implications for nearby defense installations, including MacDill Air Force Base, as well as U.S. Central Command and U.S. Special Operations Command.

A Dual-Track Training Environment: Tabletop and Live-Fire Integration

A defining feature of the 2026 exercise was the integration of two complementary training environments: a facilitated tabletop exercise (TTX) and a live-fire cyber range exercise (LFX).

Tabletop Exercise (TTX): Strategic Decision-Making in Action

Led in partnership with Norwich University Applied Research Institutes, the tabletop exercise brought together leadership from across sectors to:

  • Evaluate response plans and procedures
  • Coordinate crisis communications strategies
  • Identify gaps in interagency coordination
  • Discuss policy, governance, and resource alignment

Facilitated discussions enabled participants to test assumptions and refine decision-making frameworks under evolving scenario conditions.

Live-Fire Exercise (LFX): Operational Execution at Scale

The live-fire exercise, powered by SimSpace, provided participants with a realistic cyber range environment where technical teams:

  • Analyzed live telemetry, logs, and simulated alerts
  • Identified indicators of compromise across IT and OT systems
  • Implemented containment and mitigation strategies
  • Coordinated across SOC, engineering, and leadership roles
  • Delivered operational briefings to executive stakeholders

The LFX environment enabled participants to directly translate tabletop decisions into technical execution, reinforcing real-world readiness.

Broad Cross-Sector Participation

The exercise brought together an extensive coalition of partners, including:

Federal and Military Partners

State and Local Government

Critical Infrastructure and Industry

Key infrastructure partners included:

  • TECO Energy
  • Tampa Bay Water
  • Tampa General Hospital
  • BayCare Health System
  • AdventHealth
  • US Water Services Corporation
  • Academic and Research Partners

Idaho National Laboratory and the University of South Florida played key roles in supporting scenario design, technical integration, and research-informed facilitation.

Key Outcomes and Takeaways

Across all three days, participants identified several critical outcomes:

Stronger Cross-Sector Coordination

The exercise reinforced the importance of pre-established relationships between government, industry, and military stakeholders in responding to cyber incidents affecting shared infrastructure.

Improved Operational Awareness

Participants demonstrated improved ability to maintain shared situational awareness across IT and OT environments during rapidly evolving incidents.

Identification of Infrastructure Interdependencies

The scenario highlighted how disruptions in water systems can cascade into healthcare, energy, and defense operations.

Enhanced Crisis Communication Practices

Leadership teams refined strategies for communicating risk, coordinating messaging, and maintaining public trust during cyber disruptions.

After-Action Review and Next Steps

Following the exercise, participants contributed to a comprehensive after-action review capturing:

  • Key strengths in coordination and response
  • Gaps in technical and organizational capabilities
  • Opportunities to improve communication and decision-making workflows
  • Recommendations for future regional cyber preparedness efforts

These findings will inform ongoing efforts to strengthen cyber resilience across Florida’s critical infrastructure ecosystem.

Advancing Cyber Resilience for the Future

The successful completion of the Jack Voltaic® Tampa Cyber Incident Exercise underscored the value of sustained, cross-sector collaboration in addressing today’s evolving cyber threats.

By bringing together civilian leadership, military commands, infrastructure operators, and cybersecurity practitioners in a shared training environment, the exercise strengthened both relationships and operational readiness across the Tampa Bay region.

Cyber Florida and its partners remain committed to advancing this collaborative model, ensuring Florida continues to lead in building resilient, secure, and well-coordinated cyber defense capabilities.

Cyber Florida’s services and resources are available at no charge. To arrange for access to the ARCS Range, visit https://cyberflorida.org/arcs-range/. To explore no-cost cybersecurity training and educational opportunities for all levels of public sector employees, including certification preparation, visit our FirstLine page at https://cyberflorida.org/firstline/. Critical infrastructure organizations interested in completing the Florida Cyber Risk Assessment to access free resources and expert help should visit https://cyberflorida.org/cip/.

Jack Voltaic® Tampa Strengthens Regional Cyber Readiness2026-06-01T13:31:21-04:00

CI Bulletin Vol 2, Issue 7 May 19, 2026

Florida Critical Infrastructure Cybersecurity Intelligence

This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.

Situational Awareness Bulletin #09-2026
Cyber Threat Outlook

Over the next six to nine months, Florida’s critical infrastructure operators face a rapidly deteriorating threat environment shaped by three converging forces: (1) machine-speed exploitation driven by AI-assisted automation, (2) the deliberate targeting of IT/OT convergence points by nation-state actors, and (3) an expanding supply chain attack surface that includes managed service providers, code repositories, and certificate authorities. Threat actors are using generative AI and agentic workflows to discover vulnerabilities, fabricate phishing lures at scale, and automate credential exfiltration through poisoned development pipelines. Simultaneously, state-sponsored actors—particularly Iranian and Chinese-affiliated groups—are refining destructive and persistent techniques against internet-exposed operational technology, including programmable logic controllers and energy management gateways. These trends are compressing the window between vulnerability disclosure and active exploitation to hours or days. Organizations relying solely on periodic patching and signature-based detection are no longer adequately protected. CI owners and operators must treat operational resilience—including tested manual fallback procedures and isolated OT network architectures—as a baseline operational requirement, not a contingency plan. CISA’s new CI Fortify initiative, structured around proactive isolation and systematic recovery, provides a practical starting framework for this transition.

Confidence – High

Executive Summary
  • All Sectors: GenAI and automated tools are lowering the barrier for cyber threat actors to execute high-fidelity phishing and machine-speed exploitation, necessitating a strategic shift toward operational resilience and manual fallback capabilities.
  • Commercial Facilities: Large hospitality venues and building automation systems face data extortion and BAS hijacking risk. The Carnival Corporation incident in which ShinyHunters claims, via phishing, to have stolen 8.7 million records, demonstrates that pure data-extortion operations without encryption are increasingly common and may bypass traditional ransomware detection.
  • Communications: Telecommunications carriers and managed service providers (MSPs) face elevated ransomware targeting as adversaries seek to launch cascading attacks against downstream municipal utilities.
  • Critical Manufacturing: Financially motivated actors continue to target the aerospace supply chain with ransomware, highlighting the critical need to harden remote access gateways and segment manufacturing operations.
  • Defense Industrial Base: Persistent targeting of third-party application programming interfaces (APIs) and supply chain vulnerabilities.
  • Energy: Energy providers face multi-vector threats from Iranian-affiliated actors actively probing internet-facing OT systems, a new destructive wiper (Lotus) with no financial motive—indicating state-sponsored intent—and a supply chain breach at smart-meter provider Itron that underscores vendor access risk.
  • Financial Services: The financial sector remains a top target for ransomware and phishing campaigns abusing legitimate management platforms, requiring robust vendor management and anti-money laundering (AML) controls.
  • Government Facilities: Municipal and educational institutions face ransomware, third-party vendor breaches, and identity fraud involving the fabrication of official government credentials.
  • Healthcare and Public Health: Hospitals remain a primary target for sophisticated double-extortion ransomware and medical device targeting, necessitating the adoption of manual-first downtime procedures to sustain patient care.
  • Information Technology: Developer environments and automated build pipelines are experiencing a surge in supply-chain attacks utilizing poisoned open-source packages, agentic AI backdoors, and compromised administrative portals.
  • Transportation Systems: Commercial maritime traffic networks face emerging operational risks from advanced electronic warfare tactics, including localized spoofing and the targeted interception of vessel communication systems.
  • Water and Wastewater Systems: Water utilities must defend against AI-assisted exploitation of PLCs and persistent living-off-the-land (LOTL) administrative access.
All Sectors

Cybersecurity and Infrastructure Security Agency Tells Critical Organizations to Prepare for Cyber Outages The Cybersecurity and Infrastructure Security Agency (CISA) has launched the CI Fortify initiative, a formal CI emergency planning framework to enhance preparation for significant cyber outages. The initiative centers on two operational objectives: (1) isolation—proactively severing connections from third-party and business networks to protect OT environments, and (2) recovery—documenting system configurations, backing up critical files offline, and practicing restoration or transition to manual operations. CISA emphasizes that in the current geopolitical context, as adversaries refine their disruptive capabilities (e.g., Volt Typhoon-style prepositioning), the focus must shift from pure prevention to operational resilience and the ability to maintain essential services during a sustained technical failure. This development is relevant to Florida because the state’s reliance on integrated digital systems for power and water management means that an outage in one sector can quickly cascade into others, requiring tested manual fallback procedures to protect public safety.

Europol IOCTA 2026 Report Highlights Evolving Threat Landscape and the Proliferation of Artificial Intelligence Europol released its 2026 Internet Organised Crime Threat Assessment (IOCTA), detailing a strategic shift toward multi-staged cyber operations. The report emphasizes how generative artificial intelligence (GenAI) lowers the barrier for entry by facilitating high-fidelity phishing and basic malware creation. Additionally, it identifies the expansion of “as-a-service” models into initial access brokerage and distributed denial-of-service (DDoS). This development is significant for Florida’s critical infrastructure (CI) as it signals an increased volume of non-state threats targeting essential services through automated exploitation.

BlueKit Phishing Kit Targets Multiple Platforms with Sophisticated MFA Bypass Attacks The emergence of the “BlueKit” phishing kit marks a significant escalation in credential-harvesting tactics by multi-factor authentication (MFA) bypass through adversary-in-the-middle (AitM) techniques. Bluekit operates as a Phishing-as-a-Service (PhaaS) platform, consolidating all attack functions—domain purchase, phishing page deployment, victim session monitoring, and credential exfiltration via Telegram—into a single commercial dashboard. The kit targets over 40 platforms, including Gmail, Outlook, iCloud, GitHub, ProtonMail, and cryptocurrency services, to capture session cookies and bypass traditional authentication guardrails. Because Bluekit steals authenticated session cookies rather than just credentials, standard one-time-password (OTP) and push-notification MFA are not effective defenses. Only FIDO2-compliant hardware security keys fully mitigate this threat class. This development is relevant to Florida as state agencies and municipal utilities increasingly rely on these cloud platforms for administrative operations.

Pro-Russian Hacker Group Gamifies Cyberattacks on Europe with Cryptocurrency Rewards. An investigation revealed that a pro-Russian hacktivist collective is utilizing a gamified platform to coordinate cyberattacks against European infrastructure. Participants earn cryptocurrency rewards for successfully carrying out DDoS attacks or defacing government websites. While currently focused on European targets, the industrialized scale and crowdsourced nature of this campaign represent a transferable risk to the United States infrastructure. This news is relevant to Florida as it highlights how ideological adversaries can incentivize widespread disruption of municipal or utility networks through decentralized financial incentives and automated attack platforms.

Hundreds of Internet-Facing VNC Servers Expose Industrial Control Systems and Operational Technology A global scan by security researchers has identified hundreds of internet-facing virtual network computing (VNC) servers that provide direct access to industrial control systems (ICS) and operational technology (OT) environments. These servers are often configured without authentication or with weak credentials, allowing unauthorized actors to manipulate human-machine interface (HMI) screens and control logic. This exposure is highly relevant to Florida as many municipal water and energy utilities utilize VNC for remote monitoring.

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia The Chinese-affiliated advanced persistent threat (APT) group Silver Fox is targeting organizations across the industrial, consulting, retail, and transportation sectors using a new Python-based backdoor dubbed ABCDoor alongside the ValleyRAT malware. The campaign sent over 1,600 malicious emails between early January and early February 2026. The attack chain begins with tax-themed phishing emails containing PDF files with malicious links to ZIP or RAR archives hosted on abc.haijing88[.]com. The archives contain a modified RustSL loader that unpacks the payload and employs phantom persistence to hijack system reboot sequences for survival. While current targeting focuses heavily on Russia and India, Florida’s critical infrastructure operators should monitor for these tactics, techniques, and procedures.

Fortinet Flags Industrial-Scale Cybercrime Driven by Continuous Machine-Speed Attacks A recent report from Fortinet highlights a strategic shift toward industrial-scale cybercrime where attackers utilize automated tools to conduct machine-speed exploitation of vulnerabilities. These campaigns do not rely on manual interaction; instead, they use scripts to identify and compromise thousands of targets simultaneously. This trend is significant for Florida as the state’s large footprint of small and medium-sized municipal utilities may lack the automated defensive tools necessary to counter these high-velocity attacks, making them susceptible to rapid, widespread compromise of their administrative and OT networks.

Security Professionals Identify Identity Management as a Growing Challenge A recent industry survey indicates that the vast majority of cybersecurity professionals now view identity and access management (IAM) as their primary operational hurdle. The rise of GenAI-powered social engineering has made traditional authentication methods less effective, leading to increased unauthorized access. Florida organizations must recognize that identity is the new perimeter and prioritize phishing-resistant MFA to protect sensitive administrative credentials.

Mirai-Based XLabsV1 Botnet Exploits Android Debugging Interfaces Security researchers have identified a new Mirai-based botnet variant, XLabsV1, which is actively exploiting exposed Android Debug Bridge (ADB) interfaces to enlist devices into a DDoS network. The botnet targets Internet of Things (IoT) devices and industrial sensors that have remained insecurely connected to the public internet. This trend is relevant to Florida’s critical infrastructure because of the high density of connected sensors used in smart-city and environmental-monitoring applications across the state.

United States Lists Offensive Cyberattacks in Counterterrorism Strategy The White House has released the 2026 United States Counterterrorism Strategy, which for the first time explicitly integrates offensive cyber operations to proactively disrupt the digital infrastructure of threat actors. This strategy aims to dismantle command and control (C2) nodes before they can be utilized for coordinated physical or cyber strikes. This development is significant for Florida as it signals a shift toward federal pre-emptive actions that may decrease the volume of sophisticated external threats targeting state municipal networks.

Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access The Google Threat Intelligence Group (GTIG) has identified the first known instance of a zero-day exploit developed with the assistance of a large language model (LLM). A prominent cybercrime group utilized AI to create a Python script designed to bypass two-factor authentication (2FA) on a popular open-source system administration tool. Additionally, Chinese threat groups (UNC2814) and North Korean actors (APT45) are increasingly using “agentic” workflows to recursively analyze technical documentation and automate vulnerability discovery in embedded devices. This development is highly relevant to Florida as state agencies and municipal utilities rely on these ubiquitous administration tools and connected hardware for public service delivery. Relevant forensic data are being exfiltrated via AI-assisted reconnaissance to facilitate mass exploitation. Organizations must shift toward automated vulnerability management and reduce exposure windows as AI-assisted weaponization compresses the time between disclosure and exploitation.

New Ghostlock Tool Abuses Windows API to Block File Access and Facilitate Extortion The “Ghostlock” tool has emerged as a novel extortion mechanism that abuses legitimate Windows APIs to lock file access without performing traditional encryption. By manipulating system permissions and handles, the tool renders data inaccessible to users, allowing threat actors to demand payment for restoration. These tactics, techniques, and procedures (TTPs) is relevant to Florida CI because it bypasses many signature-based ransomware detection tools that monitor specifically for intermittent file encryption patterns or mass file renaming.

Critical Infrastructure Coalition ACI Government Partners with Federal Agencies to Bolster Defense A new coalition of critical infrastructure providers has partnered with federal agencies to streamline threat intelligence sharing and incident response coordination. This partnership is highly relevant to Florida, where the decentralized nature of municipal utilities requires a unified reporting structure.

Mini Shai-Hulud Worm Compromises Development Pipelines via Malicious npm Packages Security researchers have identified a successor to the Bitwarden CLI worm, dubbed “Mini Shai-Hulud,” that uses poisoned npm packages to automate credential exfiltration from continuous integration and continuous delivery (CI/CD) pipelines. The worm targets cloud provider tokens and exfiltrates them to public repositories, mimicking legitimate developer activity. This trend is significant for Florida’s IT and administrative sectors, as automated deployment pipelines are increasingly utilized for municipal web services and infrastructure management.

All Sectors Recommendations:

  • Implement phishing-resistant multi-factor authentication, such as FIDO2-compliant security keys, to mitigate session hijacking via automated adversary-in-the-middle attacks.
  • Identify all internet-facing VNC instances and secure them behind a virtual private network with multi-factor authentication to prevent unauthorized manipulation of industrial controls.
  • Develop and test manual fallback procedures for all life-safety services to ensure operational resilience during a sustained cyber outage.
  • Disable exposed ADB interfaces on internet-connected sensors and internet-of-things devices to prevent enrollment in distributed denial-of-service botnets.
  • Shift toward automated vulnerability management to reduce exposure windows as artificial intelligence-assisted exploitation compresses the time between disclosure and weaponization.
Chemical Sector

No sector-specific incidents, advisories, or tactically relevant reporting were identified during this biweekly reporting period.

Commercial Facilities Sector

Carnival Corporation Targeted in Ransomware Attack
ShinyHunters, a group known for data extortion, claimed responsibility for the theft of approximately 8.7 million Carnival Corporation records, including names, dates of birth, and loyalty program data, after gaining access through a phishing attack on a single employee account. Carnival confirmed the unauthorized access and activated its incident response plan but has not confirmed whether customer data was compromised. This incident highlights the ongoing exposure of large hospitality and entertainment venues within the commercial facilities infrastructure. Florida serves as the global epicenter for the cruise industry, with major hubs in Miami and Fort Lauderdale, making this breach directly relevant to the state’s economic and maritime safety. Relevant data are often exfiltrated to pressure operators during peak travel seasons. Organizations must prioritize segmenting guest services from core vessel navigation and administrative systems.

EnOcean SmartServer Flaws Expose Building Automation Systems to Remote Hijacking Security researchers disclosed multiple critical vulnerabilities in the EnOcean SmartServer IoT gateway, which is widely used in building automation systems (BAS). The flaws allow unauthenticated remote code execution (RCE) on the device, potentially giving attackers control over physical building systems, including lighting, climate control, and electronic locks. This discovery is relevant to Florida as many large-scale commercial facilities, such as stadiums and convention centers, rely on these gateways for facility management. Compromised systems could be used to disrupt operations or facilitate unauthorized physical access during high-traffic public events.

Commercial Facilities Sector Recommendations:

  • Segment guest services and public-facing networks from core vessel navigation and administrative systems to prevent lateral movement during a ransomware intrusion.
  • Patch EnOcean SmartServer IoT gateways immediately and restrict external network access to building automation systems to block unauthenticated remote code execution attempts.
  • Monitor network environments for unauthorized data exfiltration activities that frequently precede ransomware deployment and extortion demands during peak operational seasons.
Communications Sector

VECTR-CAST: Elevated Telecom and MSP Targeting in Next 14 Days A private threat-forecast report released on May 4, 2026, highlights a heightened risk of ransomware and data-theft operations against United States telecommunications carriers and managed service providers (MSPs) over the next two weeks. The report notes that several ransomware groups have expanded affiliate recruiting and are prioritizing service providers with downstream critical infrastructure (CI) customers. This development is highly relevant to Florida, as the state’s extensive network of MSPs provides foundational support for municipal utilities and local government services, making these providers prime targets for “cascading” attacks designed to disrupt multiple downstream entities simultaneously.

Communications Sector Recommendations:

  • Enforce strict multi-factor authentication and the principle of least privilege on all managed service provider remote access connections to prevent adversaries from pivoting into downstream municipal utility networks.
  • Monitor telecommunications and managed service provider environments continuously for unauthorized affiliate activity or staging of data exfiltration tools that typically precede ransomware deployment.
  • Prepare contingency plans to immediately sever or isolate administrative access from managed service providers if anomalous activity or cascading ransomware attempts are detected.
  • Back up all critical configuration files and operational data to secure, offline storage to ensure rapid recovery capabilities for downstream local government services during a data-theft or encryption event.
Critical Manufacturing Sector

Stelia Aerospace Targeted in Apparent Ransomware Attack Impacting Industrial Operations Stelia North America, a major Airbus Atlantic subsidiary specializing in aerostructures, reportedly experienced a ransomware attack that disrupted its internal information technology (IT) systems. While the company stated that the incident was strictly contained to the Stelia North America IT environment and does not impact the broader Airbus Atlantic network, the breach highlights the persistent targeting of the aerospace supply chain by financially motivated actors. Rhysida, the ransomware group responsible, issued a $2.07 million ransom demand and claimed to possess 10 TB of data, including records associated with defense contractors such as Lockheed Martin, Northrop Grumman, Sikorsky, and Boeing. This incident is highly relevant to Florida’s extensive aerospace and defense technology clusters, particularly in the Space Coast and Northwest Florida regions. Relevant production data are often exfiltrated during these intrusions to pressure victims into payment. Manufacturers must prioritize hardening remote access gateways and implement immutable, offline backups of all critical engineering workstations and design files.

Critical Manufacturing Sector Recommendations:

  • Harden remote access gateways to prevent initial unauthorized access by financially motivated threat actors targeting the aerospace supply chain.
  • Implement immutable, offline backups for all critical engineering workstations and design files to ensure resilience against ransomware encryption and data extortion.
  • Monitor internal information technology systems for unauthorized data exfiltration activities that frequently precede ransomware deployment and operational disruption.
  • Segment critical manufacturing operations from internal information technology networks to prevent lateral movement and maintain operational resilience during a breach.
Dams Sector

No sector-specific incidents, advisories, or tactically relevant reporting were identified during this biweekly reporting period.

Defense Industrial Base Sector (Updated)

Critical API Flaw In Defense Contractor Platform Exposes Military Data A high-severity vulnerability was identified in an application programming interface (API) used by a DoD contractor, which could have allowed unauthorized access to sensitive military logistics data. The flaw involved improper authentication handling, which allowed unprivileged users to query restricted records. This incident is highly relevant to Florida’s extensive defense industrial base, as many regional contractors utilize similar third-party APIs for automated data exchange, necessitating immediate audits of all external-facing service points.

Pentagon Changing Cybersecurity Training Requirement to Focus on Continuous Assessment The Pentagon is transitioning its cybersecurity training requirements from periodic annual certifications to a model of continuous, hands-on technical assessment. This change is designed to ensure the defense workforce remains proficient against rapidly evolving threats like AI-assisted exploitation. Florida-based defense contractors should anticipate updated compliance mandates that prioritize active defense skills and verified technical competency over traditional awareness training

Army Integrates Defense Industry Hackathon To Identify Supply Chain Flaws The United States Army has launched a new initiative to integrate defense industry partners into collaborative “hackathons” designed to identify vulnerabilities in the military supply chain. These events allow security researchers to probe contractor systems for weaknesses in a controlled environment. This development is significant for Florida contractors as it provides a proactive avenue to identify and remediate flaws before they can be exploited by advanced persistent threats (APTs).

Defense Industrial Base Sector Recommendations:

  • Audit all external-facing APIs and service points to identify and remediate improper authentication handling.
  • Transition internal training models to prioritize continuous technical assessments and hands-on skills over traditional annual awareness certifications.
  • Incorporate high-speed data processing and AI-driven trajectory prediction into defense-related software to align with future command-and-control procurement standards.
Emergency Services Sector

No sector-specific incidents, advisories, or tactically relevant reporting were identified during this biweekly reporting period.

Energy Sector

Operational Technology Information Sharing and Analysis Center Flags Rising Cyber Risk to Energy Environments The Operational Technology Cybersecurity Information Sharing and Analysis Center (OT-ISAC) issued an advisory regarding escalating risks to energy-sector operational technology. This warning cites recent destructive attacks abroad and the ongoing exploitation of internet-facing programmable logic controllers (PLCs) by Iranian-affiliated actors. Groups such as CyberAv3ngers are specifically refining attacks against Rockwell Automation and Allen-Bradley devices used in power generation. This development is relevant to Florida, where municipal power utilities rely on these specific controller types. Relevant telemetry data are often targeted to cause localized disruptions. Operators should verify that all OT assets are removed from the public internet.

Destructive Lotus Wiper Malware Targets Regional Energy Providers and Utilities Security researchers identified a new destructive malware variant, dubbed “Lotus,” utilized in targeted attacks against energy providers and utilities in Venezuela. The wiper is specifically engineered to permanently delete critical system files and master boot records (MBR), rendering affected systems permanently inoperable and unrecoverable. While this specific campaign is regional, the tradecraft used to bypass industrial security controls represents a significant “transferable risk” to United States energy infrastructure. Unlike ransomware, Lotus Wiper contains no payment demand or extortion mechanism. The sole objective is permanent, irreversible system destruction—indicating state-sponsored targeting rather than financial motivation. Standard ransomware response protocols do not apply. This news is relevant to Florida because state utility operators use similar industrial control systems (ICS) that could be targeted by malicious actors during periods of geopolitical escalation. Relevant telemetry data are essential for identifying unauthorized changes to system logic files. Energy providers should ensure that all critical configurations and backups for operational technology (OT) are stored in an immutable, offline format to ensure rapid recovery.

Itron Hackers Accessed Critical Infrastructure Operators Hackers breached Itron, a major provider of smart meters and grid management systems, though he breach was confined to Itron’s own corporate IT network and no unauthorized activity was observed in the customer-hosted portion of its systems and operations continued without material disruption. The full scope of the breach—including what data may have been accessed—remains under investigation. Given Itron’s role as a foundational supplier to energy and water utilities, this incident represents a significant third-party supply chain risk for Florida operators who rely on Itron’s platforms. While operational disruption to the grid has not been confirmed, the access granted to attackers potentially provided control over energy distribution endpoints. This is highly relevant to Florida’s Energy and Water sectors, which rely on similar AMI deployments. Florida operators should audit all third-party service account permissions and monitor for anomalous remote access activity originating from vendor-managed gateways.

Iranian-Linked Actors Continue OT Targeting Of U.S. Energy Sector A May 3, 2026, legal-sector brief reiterates that Iranian-linked cyber actors are actively probing and exploiting internet-facing OT used in United States energy facilities. These actors focus on insecure remote access, misconfigurations, and limited OT visibility to enable disruptive physical effects rather than pure data theft. This activity remains highly relevant to Florida as state energy providers rely heavily on internet-connected industrial hardware, making them susceptible to targeted efforts designed to cause operational downtime during periods of geopolitical escalation.

DOE’s Skyfall Testbed Highlights U.S. Preparation for Power-Grid Cyberattacks Lawrence Livermore National Laboratory (LLNL) publicized its Skyfall facility, a platform for modeling malware-driven attacks on power-grid ICS. The testbed is designed to evaluate defenses against Ukraine-style grid intrusions that could be replicated against United States utilities. This project is significant for Florida energy providers, as it provides a validated framework for testing the resilience of the state’s electric grid against sophisticated, state-sponsored, disruptive malware.

Nuclear Power Reaches Record 41 Percent Of Tennessee Valley Authority Generation Nuclear generation has reached a record high of 41 percent of the total power supply for the Tennessee Valley Authority (TVA), highlighting the growing reliance on nuclear energy for regional grid stability. This trend emphasizes the critical need to secure nuclear infrastructure against cyber-physical disruption. Florida’s energy providers must recognize that as nuclear generation becomes more foundational to the grid, the OT managing these facilities becomes a primary target for state-sponsored adversaries.

EPA Plan Allows Work on Data Centers and Power Plants Before Air Permits are Finalized A new Environmental Protection Agency (EPA) proposal would allow developers to begin preliminary work on data centers and power plants before final air quality permits are issued. The move aims to accelerate infrastructure growth to meet the energy demands of artificial intelligence. This development is significant for Florida’s energy sector, as it may lead to faster deployment of regional generation facilities but also necessitates a proactive approach to securing these new construction sites against physical and cyber intrusions.

PPL Corporation and Blackstone Announce Major Data Center Pipeline for Grid Stability PPL Corporation and Blackstone have announced a massive new pipeline for data center construction, highlighting the immense load growth currently challenging grid operators. The expansion focuses on facilities optimized for AI workloads, which require significantly higher power density than traditional data centers. This trend is highly relevant to Florida as the state’s own data center boom places increased strain on municipal power generation and requires coordinated load-shedding agreements with industrial consumers.

Energy Sector Recommendations:

  • Verify all OT assets, particularly Rockwell Automation and Allen-Bradley programmable logic controllers, are removed from the public internet.
  • Store all critical OT system configurations and industrial control system backups in an immutable, offline format to enable rapid recovery from destructive wiper attacks.
  • Audit third-party service account permissions and monitor vendor-managed gateways for anomalous remote access activity impacting smart meter management systems.
Financial Services Sector

Federal Bureau of Investigation Identifies Financial Services as Second-Most Targeted Critical Infrastructure Sector (Source also cited under Healthcare and Public Health) Newly released Federal Bureau of Investigation (FBI) statistics show that the financial services sector experienced 447 combined ransomware and data-breach incidents in 2025. This makes it the second-most targeted critical infrastructure sector, just behind healthcare. The sustained pressure on banks, insurers, and payment processors underscores the high value that criminal actors place on financial records. Florida has a significant financial hub in Miami, making this trend relevant to the state’s economic stability. Relevant data are frequently targeted for financial fraud or high-stakes extortion. Organizations should prioritize real-time monitoring of external data flows and more rigorous vendor management protocols.

Threat Actors Abuse Google Ads for GoDaddy and ManageWP Phishing Campaigns Hackers are utilizing malicious Google Ads to impersonate legitimate GoDaddy and ManageWP login pages, targeting website administrators with sophisticated phishing campaigns. These ads lead to “poisoned” landing pages that harvest credentials to gain access to financial and administrative portals. This development is relevant to Florida, as many small businesses and financial service providers rely on these platforms for web management, making them susceptible to account takeovers that could facilitate further financial fraud.

Financial Services Sector Recommendations:

  • Prioritize real-time monitoring of external data flows to identify and block unauthorized exfiltration of sensitive financial records.
  • Enforce phishing-resistant multi-factor authentication on all web management and administrative portals to prevent account takeovers via poisoned landing pages.
  • Implement robust AML controls and formal incident response protocols to mitigate the legal and operational risks associated with ransomware interactions.
  • Perform rigorous vendor management assessments to identify and secure vulnerabilities within the supply chain that could facilitate financial fraud.
Food and Agriculture Sector

No sector-specific incidents, advisories, or tactically relevant reporting were identified during this biweekly reporting period.

Government Services and Facilities Sector

Federal Shutdown Ends as Cybersecurity and Infrastructure Security Agency Faces Long Recovery Window Following the end of a record 75-day partial government shutdown, the Cybersecurity and Infrastructure Security Agency (CISA) is facing a significant backlog in vulnerability assessments and incident response support. The shutdown disrupted critical monitoring of state and local government networks, potentially allowing adversaries to establish persistent footholds. This development is significant for Florida as municipal agencies often rely on CISA for specialized technical support. Government facilities should conduct comprehensive audits of their perimeter hardware to identify any indicators of compromise (IOCs) that may have occurred during the reduced-oversight period.

Cyberattack Continues to Disrupt County Tax Operations In Mississippi As of May 3, 2026, a cyberattack continues to disrupt county tax operations in Adams County, Mississippi, specifically impacting the “car tag” processing system. The incident has forced officials to rely on manual workarounds, causing significant delays for residents as restoration efforts continue. While the specific attack type or actor has not been confirmed, this event serves as a tactical analog for Florida municipal government facilities, highlighting the immediate operational impact and public service strain caused by disruptions to specialized administrative tax and registration databases.

Hawaii AG Claims Someone is Impersonating the State’s CTO, a Role that Doesn’t Exist The Hawaii Department of the Attorney General issued a public warning in April 2026 that an individual named Iqbal Khowaja was fraudulently presenting himself as the ‘CTO of the State of Hawaii’ at national conferences, including the Bitcoin 2026 conference in Las Vegas, and on social media platforms. Hawaii has no state CTO position; the relevant leadership role is held by Chief Information Officer Christine Sakuda. This incident is relevant to Florida as a reminder that government officials and vendors should verify the credentials of individuals claiming to represent state technology agencies before sharing operational or organizational information.

Instructure Data Breach Highlights Risks Of School District Vendor Dependence A data breach at Instructure, the provider of the Canvas learning management system, has exposed sensitive information from multiple school districts. The breach resulted from unauthorized access to a third-party vendor environment where administrative data were stored. This incident underscores the systemic risk to Florida’s educational institutions, which rely heavily on centralized vendors for student and faculty data management, necessitating more rigorous third-party risk assessments.

Russia Operates Top-Secret Spy School For Hacking And Western Electoral Interference A joint investigation has revealed the existence of a specialized Russian intelligence facility dedicated to training operatives in advanced hacking and social engineering for Western electoral interference. The school focuses on bypass techniques for modern security software and the industrialization of “fake news” campaigns. This development is significant for Florida as the state’s political and government infrastructure remains a priority target for foreign influence and disruptive cyber operations.

San Diego Colleges Hit by Sophisticated Cyberattack Disrupting Campus Operations Several colleges in the San Diego area have experienced a major cyberattack that has disrupted campus networks, administrative systems, and student services. The incident forced the institutions to take many systems offline, impacting registration and financial aid processing. This event is a critical reminder to Florida’s higher education institutions that educational facilities are prime targets for ransomware and other disruptive attacks, necessitating robust network segmentation and off-site backups of essential academic and financial records.

Government Services and Facilities Sector Recommendations:

  • Perform comprehensive audits of perimeter hardware to identify indicators of compromise that may have occurred during periods of reduced oversight.
  • Verify mobile device management policies and ensure all government-issued hardware is strictly inventoried and secured with updated software.
  • Implement rigorous third-party risk assessments for all administrative and educational vendors to mitigate systemic supply chain vulnerabilities.
  • Conduct employee training on emerging social engineering tactics, including deepfake audio impersonation, to prevent unauthorized disclosure of network configurations.
Healthcare and Public Health Sector

Global Medical Device Manufacturer Medtronic Discloses Cyberattack on Internal Information Technology Network Medtronic, one of the world’s largest medical device manufacturers, disclosed that its internal information technology (IT) network was targeted in a sophisticated cyberattack on April 27, 2026. The company reported that while corporate systems were accessed, the intrusion did not disrupt manufacturing operations or impact the safety of patient devices. This incident highlights the persistent targeting of the medical technology supply chain by advanced persistent threat (APT) actors. This event is relevant to Florida healthcare networks because Medtronic products, including pacemakers and insulin pumps, are ubiquitous in clinical settings and widely used by the state’s large retiree population. Compromised corporate data are often utilized to identify vulnerabilities in product firmware or to facilitate social engineering against healthcare providers. Florida hospitals must prioritize vendor risk management and ensure that all medical devices are isolated on dedicated, non-routed network segments to prevent lateral movement.

FBI Urges Hospitals to Elevate Cybersecurity as a Patient Safety Priority A recent Federal Bureau of Investigation (FBI) briefing reports that the healthcare sector was the most targeted critical infrastructure sector in 2025, with 460 ransomware attacks and 182 data breaches. Organized cybercrime groups are deliberately prioritizing hospitals due to the life-or-death pressure to restore systems, prompting policy experts to call for terrorism designations for these attacks. This development is relevant to Florida’s extensive healthcare network and large retiree population, where disruptions to care can have immediate consequences. Relevant data are often exfiltrated to maximize extortion leverage. Hospitals should integrate cybersecurity into their broader clinical safety protocols and maintain redundant communication protocols for emergencies.

Sandhills Medical Foundation Discloses Ransomware Breach Affecting 170,000 Individuals Sandhills Medical Foundation confirmed a significant data breach following a ransomware attack that impacted the records of approximately 170,000 individuals. The compromised information included patient names, Social Security numbers, and clinical data. While the medical facility maintained clinical continuity, the large-scale exposure of sensitive records highlights the persistent threat to municipal healthcare systems. This incident is relevant to Florida as state medical networks and community health centers are primary targets for double-extortion campaigns. Relevant patient data are often exfiltrated before encryption to maximize extortion leverage. Healthcare providers should implement robust network segmentation and prioritize protecting diagnostic imaging and patient record systems.

Ransomware and Data-Theft Campaigns Persistent Threat to Healthcare Infrastructure Aggregated April 2026 incident reporting highlights that ransomware and data-theft campaigns against healthcare providers and medical technology firms continue to disrupt clinical operations. These attacks, which have included hospital IT outages that forced ambulance diversions and major breaches at global medical device manufacturers, expose large volumes of patient records. Ransomware remains a dominant threat to healthcare infrastructure, frequently using double-extortion tactics to pressure victims into paying. This development is relevant to Florida because the state’s large healthcare sector and major trauma centers are primary targets for sophisticated threat actors seeking high-leverage data. Relevant patient data are often exfiltrated before the encryption phase, necessitating a shift toward hardware-enforced protections. Organizations must prioritize developing clinical downtime procedures and isolating legacy medical devices to maintain life-safety services during a sustained technical outage.

U.S. Hospital Sector Launches New Cybersecurity Readiness Initiative After FBI Notes Healthcare as Top Ransomware Target In 2025 The American Hospital Association (AHA) and The Joint Commission announced a joint cybersecurity readiness effort to strengthen hospital defenses and incident response. This initiative follows the FBI’s report identifying healthcare as the leading sector for ransomware and cyber threats in 2025. Florida health systems are urged to participate in these voluntary readiness programs to align with national standards and mitigate the risks associated with high-volume ransomware attacks.

Data Breaches At Four Healthcare Providers Expose Sensitive Records In May 2026 Four major healthcare providers reported significant data breaches in early May 2026, resulting in the unauthorized exposure of patient medical records and personally identifiable information (PII). These incidents involved a mix of direct credential-stuffing attacks and the exploitation of vulnerabilities in third-party billing platforms. This trend is relevant to Florida, as the state’s large healthcare sector remains a primary target for ransomware groups seeking high-leverage data for double-extortion tactics.

Artificial Intelligence Finds Thirty-Eight Security Flaws In OpenEMR Healthcare Software Security researchers utilizing an AI-assisted software scanner identified thirty-eight previously unknown security vulnerabilities in OpenEMR, a widely used open-source electronic health record (EHR) platform. These flaws include critical remote code execution (RCE) and Structured Query Language (SQL) injection vulnerabilities that could allow unauthorized access to patients’ medical records. This development is significant for Florida, as many municipal health departments and smaller clinics utilize open-source EHR solutions for patient management. Relevant diagnostic data are at risk if APTs exploit these vulnerabilities. Organizations are urged to verify their OpenEMR versions and apply the latest security patches immediately.

Ransomware Group ‘The Gentlemen’ Claims Attack On Puerto Rico Community Hospital Caribbean Medical Center in Fajardo, Puerto Rico, disclosed a February ransomware attack claimed by “The Gentlemen,” an emerging double-extortion group. The intrusion led to the theft of data affecting approximately 92,000 patients, which was subsequently posted to the group’s leak site. This incident underscores the growing threat to regional healthcare providers and is relevant to Florida, given the close medical and social ties between the state and Puerto Rico.

Gentleman Ransomware Group Suffers Data Breach Exposing Internal Negotiator Communications In a significant turn, the “Gentleman” ransomware group, known for targeting healthcare providers, has reportedly suffered a data breach. The leak includes internal chat logs and negotiator communications, providing researchers with rare insight into the group’s operational structure and double-extortion tactics, techniques, and procedures (TTPs). This development is relevant to Florida healthcare networks as the exfiltrated data are being used to refine defensive strategies and better prepare hospital negotiators for future interactions with this specific threat cluster.

Healthcare and Public Health Sector Recommendations:

  • Isolate all medical devices, such as pacemakers and insulin pumps, on dedicated, non-routed network segments to prevent lateral movement.
  • Verify OpenEMR versions immediately and apply security patches to remediate remote code execution and SQL injection vulnerabilities.
  • Integrate cybersecurity into clinical safety protocols and develop “manual-first” downtime procedures to sustain patient care during sustained technical outages.
  • Participate in national readiness initiatives and implement phishing-resistant multi-factor authentication to protect sensitive patient records from credential-stuffing attacks.
Information Technology Sector

Malicious SAP npm Packages Compromised in Supply Chain Attack Targeting Developer Pipelines Security researchers identified several malicious packages on the npm registry that impersonate legitimate systems, applications, and product libraries (e.g., SAP) to facilitate supply chain compromises. These “poisoned” packages are designed to exfiltrate environment variables, cloud provider credentials, and Secure Shell (SSH) keys from developer workstations during installation. This incident is significant for Florida because many large-scale enterprises and municipal utilities use SAP for enterprise resource planning (ERP) and supply chain management. Relevant credential data is often stolen to facilitate further lateral movement into production environments. Florida development and operations (DevOps) teams must implement strict package verification and audit all package.json files for unauthorized dependencies.

New MOVEit Vulnerabilities Prompt Urgent Patch Warning Progress Software has issued an urgent advisory for two newly discovered vulnerabilities in its MOVEit Automation file transfer tool: CVE-2026-4670, a critical authentication bypass, and CVE-2026-5174, and improper input validation vulnerability that allows a high-severity privilege escalation. Exploitation of these flaws allows unauthorized access, administrative control, and data exposure. Scans indicate that over 1,440 internet-connected devices are running vulnerable versions, including those in state and local government agencies. o remediate these vulnerabilities, organizations must upgrade to a patched release using the full software installer, a process that requires temporarily taking the MOVEit Automation service offline. Scans indicate over 1,440 internet-connected devices are running vulnerable versions, including those in state and local government agencies. As of this bulletin’s publication, no confirmed in-the-wild exploitation has been reported. However, given the 2023 Cl0p campaign that weaponized a prior MOVEit flaw within hours of public disclosure, treating this as an imminent exploitation risk is prudent. Florida critical infrastructure entities relying on MOVEit Automation should immediately apply updates to prevent unauthorized data access.

Palo Alto PAN-OS Flaw Under Active Exploitation Leads to Remote Code Execution A critical vulnerability in Palo Alto Networks PAN-OS (CVE-2026-0300) is being actively exploited in the wild, allowing unauthenticated attackers to achieve root RCE. CISA added CVE-2026-0300 to its Known Exploited Vulnerabilities (KEV) catalog on May 6, 2026. The flaw exists in the User-ID Authentication Portal (Captive Portal) and has been used to deploy backdoors and harvest internal credentials. As of May 14, 2026, a patch has been available. This development is highly relevant to Florida’s public and private sectors, where Palo Alto firewalls are widely deployed as perimeter defenses; failure to patch immediately could result in a complete network compromise.

PyTorch Lightning Compromised in Supply Chain Attack via Python Package Index Security researchers identified a malicious version of the PyTorch Lightning library uploaded to the Python Package Index (PyPI). The compromised version contained a backdoor designed to exfiltrate developer secrets and establish persistent access to cloud environments. This supply chain attack targets the automated build pipelines of artificial intelligence (AI) developers. This news is significant for Florida’s information technology IT sector as local technology firms increasingly utilize these libraries for AI development. Relevant data are often exfiltrated through malicious environment variables, necessitating strict verification of all third-party libraries used in the software development life cycle (SDLC).

Google Remediates High-Severity Remote Code Execution Vulnerability in Gemini CLI Tool Google has issued a critical security patch to remediate a high-severity remote code execution (RCE) vulnerability in its Gemini Command-Line Interface (CLI) tool. The flaw, which received a Common Vulnerability Scoring System CVSS score of 10.0, allowed unauthenticated attackers to execute arbitrary commands within continuous integration and continuous delivery (CI/CD) pipelines. This vulnerability is highly relevant to Florida as state agency developers and municipal IT teams increasingly adopt AI-assisted automation for infrastructure management. Relevant build data may be exposed if the CLI tool remains unpatched. Organizations should immediately update all developer workstations and automated build environments to the latest version of the Gemini CLI.

Ransomware Groups Pivot to Abusing Remote-Access Pathways and SaaS Administrative Portals Ransomware intelligence reporting from the first quarter of 2026 shows that encryption-focused groups such as Inc, Akira, and Qilin are increasingly abusing remote-access pathways rather than using legacy virtual private networks (VPNs). Threat actors utilize compromised Single Sign-On (SSO), OAuth tokens, and Software-as-a-Service (SaaS) administrative access to infiltrate enterprise information technology (IT) environments. Once access is established, adversaries use extensive lateral movement to stage extortion operations against organizations that support critical infrastructure. This trend is significant for Florida because many state agencies and municipal utilities are migrating to cloud-based SaaS solutions, expanding the digital attack surface. Relevant credential data are often harvested through sophisticated phishing or by exploiting unpatched vulnerabilities in remote-access utilities. Organizations are urged to enforce phishing-resistant multi-factor authentication (MFA) and implement strict monitoring of administrative logs to detect unauthorized access to cloud-based management platforms.

National Security Agency Testing Anthropic Mythos AI Model to Identify Microsoft Software Flaws The National Security Agency (NSA) is reportedly testing Anthropic’s high-capability “Mythos” AI model to identify previously unknown vulnerabilities in Microsoft software. The model’s agentic capabilities allow it to perform complex, multi-step exploitation simulations. This development highlights a shift where AI is used to accelerate vulnerability discovery. This is relevant to Florida as the use of AI to find flaws could significantly collapse the patching window for state agencies and municipal utilities. Relevant data are being used to automate exploit discovery, necessitating that organizations move toward more rapid, automated responses to security patches.

Analysis Warns of Converging Cyber-Physical Threats to Critical Infrastructure and Agentic-AI-Driven OT Attacks An industry analysis outlined how cyber-physical threats are escalating as adversaries increasingly utilize operational technology (OT), artificial intelligence (AI) assisted tooling, and living-off-the-land (LOTL) techniques. These threats target the convergence points between OT and IT, hardening these gateway systems and auditing IT, particularly in the energy, water, and manufacturing sectors. Florida IT providers supporting critical infrastructure must prioritize hardening these gateway systems and auditing AI-assisted automation for potential prompt injection or unauthorized code execution.

OpenClaw Supply Chain Scanner Detects Backdoor in AI Agent Repositories The discovery of the “OpenClaw” backdoor in several open-source AI agent repositories highlights a significant supply-chain risk for DevOps teams. The malicious code allows for unauthorized RCE on systems where the AI agent is deployed. This is highly relevant to Florida IT providers that utilize AI-assisted automation, as failure to scan repositories could result in a complete compromise of sensitive administrative environments.

Researchers Spot Significant Uptick in Malicious Activity Targeting Vercel Infrastructure Cybersecurity researchers have identified a significant uptick in targeted attacks against Vercel infrastructure, focusing on the theft of environment variables and API keys. Attackers are leveraging “nested” supply-chain tactics to reach large-scale platform providers through smaller analytics firms. Florida IT organizations utilizing Vercel or similar CI/CD platforms should immediately rotate all production secrets and audit access logs for unauthorized activity.

Critical Security Flaws in Redis Expose Thousands of Servers to Unauthorized Access Multiple critical vulnerabilities have been disclosed in Redis, an open-source in-memory data structure store, that allow remote code execution and unauthorized data access. These flaws are being actively probed by botnets seeking to enlist servers into distributed-denial-of-service (DDoS) networks. This news is significant for Florida as Redis is widely used in the backend architectures of many state and municipal web applications, necessitating immediate patching to prevent system takeover.

Malicious NuGet Packages Distribution Campaign Targets Developer Workstations A new campaign is distributing “poisoned” NuGet packages designed to exfiltrate sensitive developer data, including SSH keys and cloud provider credentials. The packages impersonate legitimate libraries used for encryption and data processing. This attack targets the automated build pipelines of software developers, potentially allowing malware to propagate into enterprise applications. DevOps is used by software developers, potentially enabling teams to implement strict verification procedures for all third-party libraries.

DigiCert Revokes Certificates after Support Portal Hack In early April 2026, an unknown threat actor breached DigiCert’s internal support portal by infecting an analyst’s endpoint via a malicious payload disguised as a screenshot in a customer chat channel. The attackers proxy-accessed customer accounts to fraudulently obtain EV Code Signing certificates, allowing signed malware to bypass standard endpoint security controls. The campaign has been linked to GoldenEyeDog (APT-Q-27), a Chinese e-crime group associated with cryptocurrency theft. DigiCert subsequently revoked 60 certificates, including 27 explicitly linked to the attackers, that were used to sign the Zhong Stealer malware family. As a critical infrastructure-enabling vector, this breach presents supply chain risks for Florida critical infrastructure organizations that utilize DigiCert services or encounter newly signed malicious binaries.

Researchers Report Amazon SES Abused in Phishing to Evade Detection Cybersecurity researchers at Kaspersky report a significant increase in threat actors abusing the Amazon Simple Email Service (SES) to distribute convincing phishing emails that bypass standard reputation-based blocks and authentication checks. Attackers are leveraging automated bots like TruffleHog to harvest exposed Amazon Web Services (AWS), identity and access management (IAM) keys from GitHub repositories, .env files, and S3 buckets. Campaigns deliver fake document-signing notifications that imitate DocuSign and business email compromise attacks. Florida critical infrastructure organizations that utilize AWS should enforce least-privilege principles, enable multi-factor authentication, and regularly rotate IAM keys to mitigate exposure.

Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities Security researchers have disclosed two critical vulnerabilities, CVE-2026-2005 and CVE-2026-2006, affecting the pgcrypto extension in PostgreSQL databases, which are present in numerous enterprise environments. CVE-2026-2005 involves a buffer overflow in pgp_parse_pubenc_sesskey during public key decryption, while CVE-2026-2006 causes out-of-bounds reads and writes via malformed UTF-8 in symmetric decryption. Exploitation permits logged-in users with basic create privileges to execute code as the database owner. Florida critical infrastructure administrators should immediately apply patches released for branches 14.21 through 18.2, restrict extension creation, and audit logs for anomalous Pretty Good Privacy (PGP) or JavaScript Object Notation (JSON) activity.

Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited Via Debug API Threat actors are actively exploiting CVE-2026-22679, a critical unauthenticated RCE vulnerability in the Weaver E-cology enterprise office automation platform. The flaw affects versions before 20260312 and is triggered via the /papi/esearch/data/devops/dubboApi/debug/method endpoint. Attackers craft POST requests with manipulated interfaceName and methodName parameters to achieve arbitrary command execution. Observed campaigns involved dropping an MSI installer named fanwei0324.msi and executing discovery commands like whoami and ipconfig. Florida critical infrastructure networks running Weaver E-cology should immediately apply the vendor patches and restrict exposure of application programming interfaces for debugging.

New Stealthy Quasar Linux Malware Targets Software Developers via Supply Chain Attack Security researchers have identified a new variant of the Quasar Remote Access Trojan (RAT) specifically designed to target Linux environments used by software developers. The malware is distributed through compromised open-source repositories and is designed to exfiltrate SSH keys, API tokens, and cloud credentials. This trend is significant for Florida’s growing technology sector, as a compromise of a local developer could facilitate a supply-chain attack on larger enterprise or government platforms.

Argo CD ServerSideDiff Flaw Allows for Unauthorized Access to Kubernetes Environments A high-severity vulnerability in the Argo CD continuous delivery tool (CVE-2026-29014) allows unauthenticated users to gain access to sensitive information within Kubernetes environments. The flaw involves an improper implementation of the ServerSideDiff feature, which can be exploited to exfiltrate cluster configurations. This news is relevant to Florida as many state and municipal IT organizations utilize Argo CD for automated cloud deployments, necessitating immediate updates to version 2.11.0 or higher.

Poisoned Truth: The Quiet Security Threat inside Enterprise Artificial Intelligence Security researchers have disclosed a new class of threat dubbed “Poisoned Truth” attacks, which target the inference pipelines of enterprise AI models. By injecting malicious data into the model’s feedback loop, attackers can manipulate the AI to provide incorrect security guidance or bypass automated guardrails. This development is relevant to Florida’s critical infrastructure because the growing adoption of AI-assisted automation in municipal operations could be compromised, facilitating unauthorized access or operational sabotage.

SailPoint GitHub Repository Targeted in Third-Party Cyberattack Exposing Internal Tooling Identity management firm SailPoint confirmed that its GitHub repository was targeted in a cyberattack after an attacker compromised a third-party contractor’s credentials. The breach exposed internal tooling and configuration files, highlighting the persistent threat of “nested” supply chain attacks. This news is significant for Florida, as many state agencies use SailPoint for identity governance, making the security of its source code critical to regional administrative integrity.

Fake Claude Code Installer Distributes Malware Targeting Developer Credentials A malicious campaign is distributing fake installers for the “Claude Code” AI-assisted programming tool to infect developer workstations with infostealers. The installer appears legitimate but silently exfiltrates SSH keys and cloud provider tokens upon execution. This trend is relevant to Florida IT providers as local developers increasingly adopt AI-assisted coding tools, making them high-value targets for adversaries seeking access to enterprise deployment pipelines.

FCC Slightly Relaxes Foreign Router Ban to Allow Critical Software Updates Through 2029 The Federal Communications Commission (FCC) has slightly relaxed its ban on high-risk foreign routers, allowing for critical security software updates until 2029. The move aims to prevent existing hardware from becoming even more vulnerable while organizations transition to approved alternatives. This is significant for Florida’s IT sector as it provides a limited window for municipal utilities and agencies to maintain legacy perimeter hardware while planning for a comprehensive “rip-and-replace” cycle.

Information Technology Sector Recommendations:

  • Apply critical security patches for Palo Alto PAN-OS, MOVEit Automation, and Redis instances immediately to remediate remote code execution and authentication bypass vulnerabilities.
  • Implement strict package verification and audit all developer manifests for unauthorized npm, PyPI, and NuGet dependencies to prevent the exfiltration of administrative credentials.
  • Enforce phishing-resistant multi-factor authentication on all Software-as-a-Service administrative portals to mitigate the risk of account takeover via session and token theft.
  • Rotate all production secrets, including Amazon Web Services Identity and Access Management keys and Secure Shell keys, if unauthorized activity is detected in build environments.
Nuclear Reactors, Materials, and Waste Sector

No sector-specific incidents, advisories, or tactically relevant reporting were identified during this biweekly reporting period.

Transportation Systems Sector

Iran Utilizes Cyber Capabilities to Monitor and Threaten Maritime Traffic in Strait of Hormuz New analysis details how Iran is utilizing sophisticated cyber and electronic warfare capabilities to monitor and potentially disrupt maritime traffic through the Strait of Hormuz. These activities include Global Positioning System (GPS) spoofing and the interception of vessel communication systems to interfere with navigation. This development is relevant to Florida as a major maritime state, as the tradecraft used in these regional conflicts could be adapted to target Florida’s commercial ports and logistics networks during periods of geopolitical escalation.

Transportation Systems Sector Recommendations:

  • Monitor maritime traffic networks and commercial port environments for localized GPS spoofing attempts or electronic warfare interference.
  • Encrypt all vessel communication systems to prevent threat actors from intercepting sensitive navigation and logistics data.
  • Implement redundant positioning, navigation, and timing systems to maintain safe maritime operations if primary GPS signals are disrupted.
  • Establish manual navigation fallback protocols and drill operational contingencies for commercial ports facing targeted electronic interference.
Water and Wastewater Systems Sector

Dragos Intelligence Brief Details AI-Assisted Cyberattack on Water Infrastructure A tactical intelligence brief from Dragos detailed a sophisticated cyberattack targeting water infrastructure, in which threat actors used artificial intelligence (AI) to identify and exploit vulnerabilities in programmable logic controllers (PLCs). The attack resulted in the unauthorized manipulation of water pressure and treatment levels. This event provides a tactical analog for Florida water utilities, as the use of AI to automate vulnerability discovery significantly compresses the window for patching and defensive hardening of municipal water supplies.

UK Water Company Fined After Hackers Lurked Undetected for Nearly Two Years A major United Kingdom water utility was fined after the Cl0p ransomware group maintained undetected access to its IT network for nearly two years, exposing the personal data of over 630,000 individuals. The attackers exploited critical unpatched vulnerabilities, legacy operating systems, and excessive domain administrator privileges. This incident serves as a critical tactical analog for Florida water utilities, highlighting the need for comprehensive security operations center coverage, continuous vulnerability scanning, and strict enforcement of least privilege principles.

Water and Wastewater Systems Sector Recommendations:

  • Prioritize the patching and defensive hardening of programmable logic controllers to defend against rapid, automated vulnerability discovery, and strictly monitor for unauthorized manipulations of water pressure or treatment levels.
  • Execute deep behavioral monitoring across operational networks to detect adversaries utilizing living-off-the-land tactics that intentionally blend in with legitimate administrative activity.
  • Remove all stale administrative accounts immediately and continuously audit administrative privileges to prevent state-sponsored actors from establishing and maintaining long-term persistent access.
CI Bulletin Vol 2, Issue 7 May 19, 20262026-05-19T10:47:19-04:00

Romance Scams Informational Report

One of today’s most pervasive threats, romance scams build fake trust and affection to defraud victims. McAfee’s 2026 report found 1 in 7 American adults lost money to online dating or romance scams, and the FTC reports a median loss of $2,000 per victim — $1.14 billion in 2023.

This Cyber Florida Security Operations Center report explains what romance scams are, as well as common tactics, prevention tips, and points to resources for reporting and recovery.

Romance Scams Informational Report2026-07-23T14:00:47-04:00