Florida Critical Infrastructure Cybersecurity Intelligence
This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.
Situational Awareness Bulletin
Cyber Threat Outlook
Florida’s critical infrastructure operators face an increasingly volatile cyber threat environment characterized by machine-speed exploitation of vulnerabilities, persistent poisoning of the software supply chain, and early yet rapidly evolving use of AI agents in offensive operations. Over the next six to nine months, organizations should expect adversaries to increasingly experiment with autonomous AI agents for reconnaissance and exploitation; while one recent campaign showed these agents independently enumerating targets and attempting exploits, confirmed data theft in that case still required manual, human-directed exploitation — a distinction that matters for realistic defensive planning. Cyber threat actors are accelerating initial access by deploying adversary-in-the-middle (AiTM) phishing frameworks to bypass multi-factor authentication (MFA) and exploiting zero-day vulnerabilities in edge networking appliances, remote monitoring and management (RMM) platforms, and identity infrastructure within hours of disclosure. Internet-exposed programmable logic controllers (PLCs) across water and energy networks also remain under sustained attack; federal agencies have linked some of this activity to Iranian-affiliated actors in prior advisories, though the most recent water-sector campaign has not been formally attributed. Because Florida’s critical infrastructure sectors maintain highly interconnected technology stacks, shared cloud environments, and extensive third-party vendor relationships, operators must prioritize rapid vulnerability remediation, enforce phishing-resistant multi-factor authentication, strictly isolate OT perimeters, and continuously validate business continuity frameworks.
Confidence Assessment: High
Executive Summary
-
All Sectors: Cyber threat actors aggressively targeted edge infrastructure, identity services, and developer pipelines. Key threats included active zero-day exploitation of Cisco, Arista, and Fortinet appliances, mass password spraying against cloud environments, sophisticated Microsoft Teams social-engineering campaigns, and early signs of AI-agent-assisted reconnaissance and exploitation attempts.
- Commercial Facilities: Russian cyber threat actors are executing a global campaign targeting Wi-Fi gateways on hospitality networks at hotels and conference centers.
- Communications: There is a joint cybersecurity advisory warning of active phishing campaigns conducted by Russian state-sponsored cyber threat actors (LAUNDRY BEAR) targeting the Zimbra Collaboration Suite.
- Defense Industrial Base: State-sponsored cyber threat actors deployed custom backdoors and AI-assisted prompt-injection attacks targeting defense personnel, while joint federal advisories established new minimum standards for Software Bill of Materials (SBOM) supply chain governance.
- Energy: A cybersecurity trend analysis reveals a 56% reduction in internet-exposed automatic tank gauge (ATG) systems across U.S. fuel distribution networks following federal security warnings.
- Financial Services: Coordinated voice phishing (vishing) and social engineering campaigns targeted high-value financial institutions.
- Healthcare and Public Health: Extortion groups intensified data-theft operations against healthcare providers by targeting cloud Software-as-a-Service (SaaS) integration partners, Open Authorization (OAuth) tokens, and electronic medical record (EMR) vendor platforms.
- Information Technology: The IT sector experienced five critical cybersecurity threats demanding immediate attention and patching. There are three vulnerabilities being actively exploited in the wild affecting Arista VeloCloud Orchestrator, Cisco Secure Firewall Management Center, and N-able N-central remote monitoring and management (RMM) platform. Additionally, VMware released emergency patches for three critical vulnerabilities. Finally, DevOps teams face a supply chain threat from “ChainDrop.”
- Transportation Systems: A logistics provider left a cloud storage container publicly exposed, revealing over 840 million records, while a cyberattack on North Carolina’s port authority disrupted gate operations at three facilities.
- Water and Wastewater Systems: Joint federal advisories from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA) warned of an active, multi-state cyberattack campaign exploiting internet-facing PLCs and causing operational disruptions across municipal water treatment facilities.
All Sectors
Hackers Target US Firms in FastJson Zero-Day Attacks Cyber threat actors are actively exploiting a critical remote code execution (RCE) zero-day vulnerability in the FastJson open-source Java library (versions 1.2.68 through 1.2.83). Unauthenticated attackers send specially crafted JavaScript Object Notation (JSON) payloads to execute arbitrary operating system (OS) commands on host servers. Imperva reports that FastJson 1.x is no longer actively maintained, so it is unlikely to receive a security update. Because FastJson is a foundational dependency embedded across enterprise Java applications in Florida’s financial, healthcare, and commercial sectors, organizations should immediately audit application manifests and deploy vendor patches.
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor A sophisticated social engineering campaign is targeting enterprise users via Microsoft Teams. Cyber threat actors impersonate internal IT helpdesk personnel via Microsoft Teams voice calls and persuade employees to approve a Quick Assist remote-support session, after which PowerShell staging scripts deploy a custom Go-based backdoor (GoGRPC) that blends its command-and-control traffic with legitimate enterprise traffic. Because Microsoft Teams is universally deployed across Florida’s critical infrastructure perimeters, security teams should update employee awareness training and enforce strict authentication policies for internal IT communications.
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks. Palo Alto Networks Unit 42 identified an operational shift in which a Chinese-speaking threat actor deployed autonomous artificial intelligence (AI) agent frameworks to execute end-to-end attack chains. The AI agent autonomously performed reconnaissance and attempted exploitation across seven vulnerabilities, but these autonomous attempts did not achieve compromise; confirmed data exfiltration resulted from separate, manually directed exploitation of a Citrix NetScaler vulnerability. This development signals a narrowing window for defender intervention across all critical infrastructure perimeters in Florida, requiring automated detection and response capabilities.
CISA, NSA, and FBI Release 2026 Minimum Elements for a Software Bill of Materials & Open Source Software Security Principles The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) issued joint authoritative guidance establishing updated minimum elements for Software Bill of Materials (SBOM) and open-source software (OSS) risk management. The guidelines provide an operational framework for identifying nested open-source dependencies, verifying code provenance, and managing third-party software risk. Florida critical infrastructure operators should update vendor procurement contracts and software governance policies to mandate compliance with these federal supply chain standards.
All Sectors Recommendations:
- Deploy, verify, and maintain emergency security updates across all enterprise web applications and edge network appliances to remediate unauthenticated remote code execution (RCE) paths.
- Enforce, validate, and monitor phishing-resistant Fast IDentity Online 2 (FIDO2) hardware tokens and device-bound passkeys across all cloud, single sign-on (SSO), and remote management portals to mitigate adversary-in-the-middle (AiTM) session theft.
- Identify, isolate, and disable direct internet exposure for all operational technology (OT) assets, specifically industrial programmable logic controllers (PLCs) and human-machine interfaces (HMIs) managing critical public utilities.
- Update, educate, and test employee security awareness training to recognize internal Microsoft Teams helpdesk impersonation, social engineering lures, voice phishing (vishing) calls, and prompt injection attempts.
- Harden, tune, and audit Software Bill of Materials (SBOM) procurement requirements, open-source dependency manifests, and third-party vendor access boundaries in accordance with joint CISA, NSA, and FBI supply chain standards.
Chemical Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Commercial Facilities Sector
Midnight Blizzard Deploys CaptiveCrunch AiTM Infrastructure to Target Travelers Russian state-sponsored group Midnight Blizzard (Advanced Persistent Threat 29 [APT29]) is executing a global campaign targeting hospitality networks, hotels, and conference centers. The actors compromise captive-portal Wi-Fi gateways to deploy “CaptiveCrunch” adversary-in-the-middle (AiTM) infrastructure, serving custom malware (CornFlake and ChocoShell) and harvesting corporate Microsoft 365 credentials from business travelers. Because Florida’s hotel and convention-center industry hosts a high volume of business travelers, corporate security teams should treat hotel and conference Wi-Fi as untrusted statewide.
Commercial Facilities Sector Recommendations:
- Audit, secure, and monitor public-facing Wi-Fi captive portals and venue gateway hardware against “CaptiveCrunch” adversary-in-the-middle (AiTM) redirection, Domain Name System (DNS) poisoning, and certificate-spoofing attacks.
- Mandate, enforce, and verify compulsory Virtual Private Network (VPN) usage and phishing-resistant multi-factor authentication (MFA) for all corporate employees connecting to public, hotel, or conference Wi-Fi networks.
- Isolate, segment, and protect commercial building automation systems (BAS / KNX protocol), smart lighting, physical access hardware, and guest Wi-Fi networks from core corporate administration plans.
- Patch, update, and validate enterprise resource planning (ERP) systems, including Oracle E-Business Suite and control panel (cPanel) web environments, to protect client personal data, financial records, and reservation systems.
Communications Sector
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Zimbra The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA) issued a joint cybersecurity advisory warning of active phishing campaigns conducted by Russian state-sponsored cyber threat actors (LAUNDRY BEAR) targeting the Zimbra Collaboration Suite. The cyber threat actors exploit zero-day vulnerability CVE-2025-66376, deploying an automated payload (Ulej) that executes when an email is viewed in the webmail portal. Florida telecommunications providers and regional Internet Service Providers (ISPs) utilizing Zimbra must remain vigilant against these zero-click webmail threats.
Communications Sector Recommendations:
- Patch, update, and inspect all Zimbra Collaboration Suite and webmail installations immediately to remediate zero-click email exfiltration flaws (CVE-2025-66376) and hunt for custom Ulej backdoor artifacts.
- Perform, review, and document comprehensive security audits on regional Internet Service Provider (ISP) routing infrastructure, telecommunications data centers, and subsea cable landing stations to block session hijacking.
- Deploy, update, and verify immediate vendor patches for enterprise video conferencing clients (such as Zoom CVE-2026-53412) to remediate unauthenticated account takeover and privilege escalation risks.
- Establish, test, and maintain redundant, out-of-band communication channels and manual fallback workflows to sustain critical Emergency Alert System (EAS), Wireless Emergency Alerts (WEA), and public safety voice services during network outages.
Critical Manufacturing Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Dams Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Defense Industrial Base Sector
2026 Minimum Elements for a Software Bill of Materials (SBOM) The Cybersecurity and Infrastructure Security Agency (CISA), alongside the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international partners, released the updated 2026 Minimum Elements for a Software Bill of Materials (SBOM). Superseding the 2021 baseline, this comprehensive update expands the scope of software supply chain transparency to explicitly include artificial intelligence (AI) software, open-source software, and Software-as-a-Service (SaaS). By introducing new data fields—such as cryptographic component hashes, licensing details, and generation context—the guidance shifts SBOMs from static compliance documents into dynamic, machine-readable records. These enhancements are designed to facilitate machine-speed automated analysis, empowering organizations to better identify, assess, and mitigate risks across their software ecosystems. Defense contractors operating near Florida’s major military installations must integrate these updated SBOM elements into their software procurement pipelines.
Defense Industrial Base Sector Recommendations:
- Audit, integrate, and mandate compliance with Cybersecurity and Infrastructure Security Agency (CISA) 2026 Software Bill of Materials (SBOM) minimum elements across all defense contractor software development and procurement pipelines.
- Enforce, segment, and verify strict, air-gapped least-privilege divisions between supplier-administered Information Technology (IT) networks and classified defense software assembly lines.
- Sanitize, restrict, and monitor connected generative AI coding assistants to low-privilege environments and scrub untrusted user comments in GitHub pull requests to prevent prompt injection.
Emergency Services Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Energy Sector
BitSight Reports 56% Decline in Exposed Automatic Tank Gauge Systems A cybersecurity trend analysis reveals a 56% reduction in internet-exposed automatic tank gauge (ATG) systems across U.S. fuel distribution networks following federal security warnings. While this indicates improved perimeter hygiene, unmanaged fuel monitoring systems remain a target for Iranian state-sponsored cyber threat actors seeking operational intelligence. Florida’s fuel distribution networks and port authorities must ensure their automatic tank gauge systems are not exposed to the public internet to prevent operational disruptions.
Energy Sector Recommendations:
- Identify, isolate, and remove all automatic tank gauge (ATG) systems, fuel monitoring sensors, and smart grid meters from direct exposure on the public internet.
- Deploy, configure, and test vendor mitigations for Rockwell Automation 1715-AENTR EtherNet/IP adapters and Allen-Bradley programmable logic controllers (PLCs) in accordance with joint advisories from the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA).
- Isolate, segment, and audit operational energy management networks, Supervisory Control and Data Acquisition (SCADA) systems, and renewable generation gateways from corporate administrative Information Technology (IT).
- Coordinate, monitor, and investigate regional data center operators to detect anomalous power draw patterns or high-frequency Graphics Processing Unit (GPU) workloads indicative of potential “Bit2Watt” grid manipulation.
Financial Services Sector
Extortion Group UNC6671 Targets Major Financial Institutions via Vishing Financial sector intelligence reports highlight an active campaign by extortion group UNC6671 (linked to BlackFile) targeting high-value financial institutions and hedge funds. The cyber threat actors impersonate IT helpdesk staff and contact employees directly, often via personal mobile devices, under the pretext of urgent security migrations, redirecting them to spoofed login portals where adversary-in-the-middle (AiTM) infrastructure intercepts credentials and MFA tokens. Florida-based financial institutions and wealth management firms face a high risk from these targeted social engineering and vishing campaigns.
Also, see “#StopRansomware: Gunra Ransomware” under Healthcare and Public Health Sector
Financial Services Sector Recommendations:
- Enforce, mandate, and verify strict out-of-band identity verification procedures for all helpdesk credential resets, wire transfers, and multi-factor authentication (MFA) device registrations.
- Monitor, detect, and revoke unauthorized Open Authorization (OAuth) 2.0 token grants, spoofed client Identification (ID) credentials, and anomalous session activity across cloud-hosted financial applications and corporate Software-as-a-Service (SaaS) portals.
- Harden, test, and audit macOS and Windows developer workstations against custom infostealers (e.g., JINX-0164 malware) delivered via fake job recruiter lures on professional networking sites.
- Review, segment, and isolate network connections between parent corporate architectures and local subsidiary lending networks to block lateral ransomware propagation.
Food and Agriculture Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Government Services and Facilities Sector
See “#StopRansomware: Gunra Ransomware” under Healthcare and Public Health Sector
Healthcare and Public Health Sector
Health-ISAC Warns of Rising ShinyHunters Data Theft Attacks on Healthcare The Health Information Sharing and Analysis Center (Health-ISAC) issued a threat advisory warning healthcare providers of escalating data extortion campaigns by ShinyHunters. The group focuses on compromising third-party cloud Software-as-a-Service (SaaS) integration partners, abusing Open Authorization (OAuth) consent tokens, and exfiltrating patient records without deploying ransomware encryption. Florida health systems must audit third-party cloud permissions to mitigate data leakage.
Intrusion at US Healthcare Software Provider Puts 3.8M People’s Data at Risk A US healthcare software provider admitted that hackers may have compromised sensitive data belonging to 3.8 million individuals. This incident, marked as the largest healthcare breach reported to regulators so far this year, underscores the severe supply chain risks facing Florida’s healthcare sector.
#StopRansomware: Gunra Ransomware A joint U.S.–South Korea advisory warned of Gunra ransomware, a Conti-derived double-extortion variant. Separate South Korean research has identified overlapping attack infrastructure between some Gunra incidents and tools associated with North Korea’s Lazarus Group, though a direct operational relationship has not been confirmed. This actively targets the healthcare/public health, financial services, government facilities, critical manufacturing, transportation, and utilities sectors.
Healthcare and Public Health Sector Recommendations:
- Audit, review, and revoke unvetted third-party Open Authorization (OAuth) consent grants, Application Programming Interface (API) integrations, and Software-as-a-Service (SaaS) vendor permissions across healthcare cloud environments to prevent data exfiltration.
- Implement out-of-band verification and a ‘no same-call’ policy for all helpdesk password and MFA resets.
- Isolate, segment, and protect Electronic Health Record (EHR) systems, medical diagnostic portals (e.g., Abbott LabCentral), and clinical Internet of Things (IoT) devices on dedicated, non-routed virtual local area networks (VLANs).
- Integrate, practice, and maintain “manual-first” clinical downtime procedures to sustain life-safety services and patient care during cloud outages or ransomware events.
- Enforce, audit, and monitor strict Health Insurance Portability and Accountability Act (HIPAA) compliance rules, access logging, and Data Loss Prevention (DLP) tools across internal analytics platforms.
Information Technology Sector
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day A maximum-severity command injection zero-day vulnerability in Arista VeloCloud Orchestrator is under active in-the-wild exploitation. Unauthenticated remote attackers can send crafted Hypertext Transfer Protocol (HTTP) requests to execute arbitrary operating system (OS) commands with root privileges on central network management servers. CISA added this flaw, along with the Fortinet FortiOS vulnerability CVE-2025-68686, to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation.
Cisco FMC Static Credential Zero-Day Flaw Exploited in Attacks (CVE-2026-20316 – CISA KEV Addition): Cisco warned of active zero-day exploitation targeting Cisco Secure Firewall Management Center (FMC). The flaw involves hard-coded credentials for a low-privilege built-in account, allowing unauthenticated remote attackers to log in and access sensitive data. Cisco warns that this access could potentially be chained with other, undisclosed FMC vulnerabilities to escalate privileges. Organizations running Cisco FMC must deploy vendor patches immediately and audit administrative accounts for rogue entries. Because Cisco Secure FMC is widely deployed to centrally manage perimeter firewalls across Florida’s critical infrastructure sectors, operators using it should treat patching as urgent regardless of organization size.
VMware Fixes Three Critical Flaws Allowing Auth Bypass and VM Escapes VMware released emergency security patches for vCenter Server, ESXi, and Cloud Foundation. The updates resolve three critical vulnerabilities: an authentication bypass in vCenter’s Directory Service (CVE-2026-59309) and a directory traversal flaw enabling remote code execution (CVE-2026-59310), both exploitable by an unauthenticated attacker with network access to vCenter; and an out-of-bounds write in the VMXNET3 adapter (CVE-2026-47876) that lets an attacker who already holds local administrative privileges inside a VM escape to the ESX host. IT administrators should apply these updates immediately.
N-able N-central RMM Server Authentication Bypass Exploited in the Wild N-able confirmed active in-the-wild exploitation of an authentication bypass vulnerability affecting its N-central Remote Monitoring and Management (RMM) platform. Attackers bypass authentication to take over N-central servers and push malicious software to downstream managed clients. Managed Service Providers (MSPs) must update N-central to version 2026.3.1.7 or higher immediately.
ChainDrop npm Supply Chain Worm Targets CI/CD Pipelines via Bun Runtime Security researchers uncovered “ChainDrop,” a self-propagating supply chain worm affecting the Node Package Manager (npm) registry. The worm infects developer environments, utilizes the Bun JavaScript runtime to execute hidden preinstall scripts, and exfiltrates cloud credentials to an Ethereum blockchain dead-drop resolver. Development and Operations (DevOps) teams must audit package manifests (including keyv and flat-cache) and revoke exposed deployment tokens
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks A newly disclosed Windows zero-day (CVE-2026-68820, an afd.sys use-after-free) allowed Lazarus Group (North Korea) to gain SYSTEM-level control and deploy the ‘ForestTiger’ backdoor as part of the ongoing ‘Operation Dream Job’ campaign, which targets defense, aerospace, and aviation organizations through fraudulent recruiter outreach. Microsoft patched the flaw on August 11 as part of Patch Tuesday.
AI Failed to Properly Patch Software Flaws 74% of the Time, 1Password’s Study Warns A study by Off-By-1-Labs and 1Password revealed that frontier AI models failed to properly patch software flaws 74% of the time. Florida IT teams utilizing AI coding assistants for vulnerability remediation must enforce rigorous human oversight and manual code reviews. Florida MSPs and IT administrators should require a mandatory human security review of any AI-generated patch before it reaches production, particularly for downstream client environments.
Information Technology Sector Recommendations:
- Apply, test, and verify emergency security updates for Arista VeloCloud Orchestrator (CVE-2026-16812), Cisco FMC (CVE-2026-20316), VMware vCenter, and N-able N-central (CVE-2026-18577).
- Audit, scan, and clean open-source package dependencies (npm, Python Package Index [PyPI]) and developer manifests for poisoned-supply-chain scripts (ChainDrop worm) and hallucinated packages.
- Rotate, invalidate, and secure exposed cloud access keys, Amazon Web Services (AWS) Identity and Access Management (IAM) tokens, Secure Shell (SSH) keys, and database credentials across all Continuous Integration/Continuous Deployment (CI/CD) build environments and code repositories.
- Restrict, isolate, and monitor Remote Monitoring and Management (RMM) tools (ScreenConnect, N-central) and hypervisor consoles from direct public internet exposure.
- Enforce, validate, and audit strict application whitelisting, secrets scanning tools, and memory isolation for enterprise artificial intelligence (AI) coding assistants and cloud AI gateways.
Nuclear Reactors, Materials, and Waste Sector
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Transportation Systems Sector
Delivery mega leak: 840M+ files exposed as US delivery company leaks massive file storage Last-mile delivery provider SpeedX left an unsecured Microsoft Azure cloud storage container publicly accessible, exposing more than 840 million customer and driver records, including home addresses, shipping labels, parcel delivery photos, and driver’s license images. SpeedX handles deliveries for major e-commerce platforms, including Shein, Temu, Amazon, and TikTok Shop; researchers found no evidence of prior malicious access but warned the exposed data could fuel large-scale, delivery-themed phishing campaigns. Because SpeedX and similar last-mile carriers operate throughout Florida, transportation and logistics operators statewide should audit their own cloud storage configurations for comparable misconfigurations.
North Carolina Ports Cyberattack Disrupts Three Locations A cyberattack targeting North Carolina ports was reported as “contained” on August 6, with the U.S. Coast Guard and state officials actively investigating the incident’s scope and origin. Florida’s maritime and freight logistics hubs should review network segmentation between administrative IT systems and terminal gate operations, and validate manual fallback procedures to sustain cargo processing during an IT outage.
Transportation Systems Sector Recommendations:
- Audit, secure, and restrict permissions for cloud storage buckets, object-level access controls, and database containers across all maritime and freight logistics platforms.
- Harden, monitor, and test public-facing web applications, passenger check-in portals, and booking infrastructure against Distributed Denial of Service (DDoS) attacks.
- Establish, test, and document out-of-band backup communication workflows and manual tracking protocols to ensure continuity of freight logistics operations during network outages.
- Train, educate, and test maritime logistics staff to identify RedLine Stealer phishing lures, Business Email Compromise (BEC) invoice fraud, and Global Positioning System (GPS) spoofing anomalies.
Water and Wastewater Systems Sector
CISA, FBI, and EPA Issue Joint Warning on Active Cyberattacks Targeting Water Sector PLCs & FBI/EPA Public Service Announcement (Synthesized Threat Profile) The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA) issued urgent joint advisories warning of an active, multi-state cyberattack campaign targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems Sector. Iranian-affiliated actors are actively exploiting internet-exposed Rockwell Automation and Allen-Bradley PLCs (specifically MicroLogix 1100 and 1400 models) via the EtherNet/IP protocol. The intrusions have caused pressure loss and flooding, forced manual workarounds, and triggered boil-water advisories across utilities in at least 12 states. Security scans reveal that over 4,000 industrial controllers remain exposed online nationwide. Florida water utilities must urgently inspect operational technology (OT) perimeters and disconnect PLCs from public networks.
Although the original CISA alert itself does not name any states, based on multiple corroborating reports (SecurityWeek, Cybernews, NBC News, Newsweek), six states have been publicly named as affected by this campaign (others remain unnamed):
- Minnesota — hit hardest, 30+ community water systems targeted July 26–27
- Michigan — a “small number” of communities (Michigan EGLE later specified 9+ systems)
- Georgia — Clayton County Water Authority, serving ~300,000 customers near Atlanta, caused a pressure drop and a boil-water advisory
- South Dakota — Rapid City, involving a wastewater lift station
- New Jersey — Cape May and Woodbine water systems (targeted July 27; only phone systems disrupted)
- Alabama — Childersburg Water, Sewer, and Gas system (targeted July 27; ICS targeted, no service disruption)
Water and Wastewater Systems Sector Recommendations:
- Identify, isolate, and disconnect all Rockwell Automation, Allen-Bradley (MicroLogix 1100/1400), and third-party programmable logic controllers (PLCs) from direct public internet exposure.
- Audit, restrict, and secure Ethernet/IP protocol interfaces, port 10000 Real-Time Kinematic Base (RTKBase) mapping portals, and remote-access pathways behind hardware-enforced firewalls and Virtual Private Networks (VPNs).
- Conduct, perform, and document routine integrity checks on Supervisory Control and Data Acquisition (SCADA) logic configurations, treatment parameter setpoints, and manual operational fallback playbooks.
- Maintain, test, and validate offline, out-of-band configuration backups for all water treatment controllers to enable rapid recovery during cyber-physical incidents.
Supplement:
Critical Infrastructure Adversary Watch
This is a periodic operational intelligence analytic product for Florida’s Critical Infrastructure (CI) Managers, Planners, and CISOs to provide an integrated synthesis of recent CI-focused Threat Actors and their campaign activity. This issue covers trends in the period July 15-August 14, 2026.
1. China-Nexus Adversaries: Long-Term Espionage, Supply Chain Hijacking, and AI Integration
- Strategic Intent & Activity: Chinese state-sponsored threat actors are engaged in long-term strategic pre-positioning and deep espionage within telecommunications, defense, and government networks. A primary operational group, Salt Typhoon, successfully breached U.S. mobile carriers by exploiting routine network pathways connected to state-owned telecom firms, seeking to permanently embed itself inside the U.S. internet ecosystem to monitor and potentially weaponize communications.
- Sustained Capabilities: Groups like GoldenEyeDog and Mustang Panda target critical software supply chains—GoldenEyeDog breached DigiCert to hijack code-signing certificates, while Mustang Panda compromised network acceleration tools to deploy custom backdoors. China-nexus actors are also aggressively integrating artificial intelligence into their playbooks. They employ autonomous, multi-agent AI systems (using frameworks such as Hermes and OpenClaw) capable of executing end-to-end intrusion campaigns by independently scanning, cracking credentials, and deploying backdoors at machine speed without human intervention. Furthermore, these actors utilize “model distillation” of advanced Western models to train domestic AI models for offensive cyber applications.
2. Iran-Nexus Adversaries: Coercive Disruption, OT Probing, and Asymmetric AI Weaponization
- Strategic Intent & Activity: Iranian state-aligned cyber actors have functionally realigned their operations with Tehran’s broader regional and military objectives, executing aggressive cyber-espionage and coercive disruption against civilian critical infrastructure. Resuming operations after a brief period of dormancy, the prominent group Handala explicitly targets the municipal water, fuel distribution, transportation, and food sectors.
- Sustained Capabilities: Alongside CyberAv3ngers, these actors systematically target internet-facing Operational Technology (OT) and Programmable Logic Controllers (PLCs), manipulating SCADA displays, altering reusable code, and modifying administrator credentials to lock out operators—forcing numerous U.S. water facilities to transition to manual operations and issue boil-water notices. Iran-nexus groups also demonstrate highly targeted cloud and identity-focused capabilities; APT42 utilizes AI-assisted phishing and the TAMECAT backdoor to secure persistent, long-horizon access to defense cloud environments. Geopolitically, these state actors have shown a willingness to target cloud infrastructure directly, claiming responsibility for strikes on major regional data centers.
3. Russia-Nexus Adversaries: Stealthy Espionage, Edge Network Hijacking, and Tactical Manipulation
- Strategic Intent & Activity: Russian state-sponsored groups prioritize deep espionage, email harvesting, and stealthy perimeter compromise. The prominent group Sandworm has largely shifted its initial access tactics toward “ClickFix” social engineering campaigns, directing targets to compromised websites with fake security prompts designed to trick users into executing malicious code.
- Sustained Capabilities: Sandworm is actively deploying self-propagating worms designed to infect AI coding assistants within automated development workflows. Concurrently, SVR operational sub-cluster Storm-2945 hijacks hotel Wi-Fi networks and captive portal DNS resolvers to push fake browser updates that install the CornFlake surveillance remote access trojan on connected devices. For broader intelligence gathering, LAUNDRY BEAR actively targets on-premises webmail infrastructures, utilizing zero-click exploits that require no user interaction to deploy custom “Ulej” data exfiltration tools. Furthermore, groups like UAT-11795 target database administrators by poisoning legitimate database management and IT tools.
4. North Korea-Nexus Adversaries: Supply Chain Poisoning and Falsified Remote IT Identities
- Strategic Intent & Activity: North Korean state-sponsored actors conduct parallel campaigns designed to execute root-level corporate intrusions and steal digital assets to generate state revenue.
- Sustained Capabilities: Lazarus Group targets defense and aerospace professionals via highly tailored, recruitment-themed social-engineering lures on professional networks (“Operation Dream Job”) to deploy custom backdoors. To secure highly evasive command-and-control communication, Lazarus has successfully poisoned open-source package registries and utilizes the Ethereum blockchain as an immutable “dead drop” to locate subsequent server infrastructure. Additionally, North Korea is conducting a massive insider-threat campaign by deploying remote IT workers who use AI to obscure their identities and forge credentials to secure remote contracting and IT positions, establishing covert, persistent access inside Fortune 500 companies and federal agencies.
5. Cybercriminal Extortion Ecosystem: EDR Blinding and Double Extortion
- Strategic Intent & Activity: Ransomware and extortion syndicates have significantly increased the severity and efficiency of their campaigns. The Gentlemen ransomware group actively targets critical healthcare systems, exfiltrating terabytes of data, disabling networks, and aggressively hijacking victims’ official corporate social media profiles to publicly broadcast ransom demands.
- Sustained Capabilities: INC Ransomware is acting as a dominant threat actor on the network edge, compromising Secure Mobile Access appliances to pivot laterally into corporate and OT networks. Simultaneously, extortion group ShinyHunters executes sophisticated supply-chain identity attacks, stealing OAuth tokens to compromise major cloud and Software-as-a-Service (SaaS) provider environments. To ensure encryption succeeds, ransomware actors are broadly adopting “ransomware killers”—surgical in-memory tampering techniques that overwrite the memory of Endpoint Detection and Response (EDR) and Antivirus (AV) processes at runtime, disabling security alerts while leaving the applications looking normal and functioning blind.
