Last Updated On

CCTTII--22002266--00773311
IInnffoorrmmaattiioonnaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

When AI Escapes the Lab and City Water Controls Fail

Between July 26 and July 30, 2026, threat actors launched targeted attacks against operational technology in water and wastewater systems across Minnesota while actively exploiting critical vulnerabilities in enterprise Cisco and Palo Alto Networks firewalls. Attackers manipulated exposed programmable logic controllers, altered network settings, and bypassed authentication mechanisms on edge appliances to gain unauthorized access.

These concurrent incidents underscore a critical threat across both IT and OT environments, where unpatched perimeter systems and exposed industrial controllers invite immediate compromise. Security teams must instantly isolate all internet-connected controllers, enforce multi-factor authentication, and apply essential vendor updates to protect core networks and essential utilities.

10

CVSS Score

15

IOC Count

6

Source Count

80

Confidence Score

CVEs

CVE-2026-20316, CVE-2026-20079, CVE-2026-0257

Actors

CyberAv3ngers, Handala, Under Attribution

Sectors

Water and Wastewater Utilities, Critical Infrastructure, Information Technology, Networking, Enterprise Security

Regions

North America, United States, Global

Chapter 01 - Executive Overview

In late July 2026, threat actors targeted both operational technology in critical infrastructure and enterprise perimeter network devices. Coordinated intrusions disrupted water and wastewater operations across over 30 Minnesota communities by compromising internet exposed programmable logic controllers. Concurrently, active in the wild exploitation was confirmed for major edge firewall flaws in Cisco Secure Firewall Management Center and Palo Alto Networks PAN-OS GlobalProtect. These concurrent events underscore a severe combined risk targeting critical infrastructure operational technology and enterprise perimeter defenses.

Water Utilities PLC Compromise — High — Water and Wastewater Utilities

  • Threat overview: Threat actors accessed exposed programmable logic controllers across Minnesota water utilities using trusted engineering software, locking operators out by altering controller passwords and IP configurations.

  • Strategic risk context: Disruption of operational technology in water facilities threatens basic municipal services, requiring rapid shift to manual overrides to prevent physical supply interruption.

  • Severity and business impact: High operational impact requiring physical intervention by field personnel, alongside potential regulatory scrutiny and systemic risk across public works.

  • Confidence in available intelligence: High confidence in technical events and operational impacts; low confidence in threat actor attribution.

  • Urgent decision: Leadership must immediately order an immediate audit to remove or isolate all internet connected programmable logic controllers and SCADA interfaces behind secure jump servers with multi factor authentication.

Cisco Secure FMC Vulnerabilities — High — Information Technology and Enterprise Security

  • Threat overview: Active exploitation of static credentials in Cisco Secure FMC web interface allows remote low privilege access, with risks of escalation when chained with administrative web bypass bugs.

  • Strategic risk context: Centralized firewall management systems represent high value targets; compromising them enables visibility and potential control over core network defenses.

  • Severity and business impact: High risk of administrative compromise, unauthorized internal access, and network wide security policy manipulation.

  • Confidence in available intelligence: High confidence supported by direct Cisco advisories and CISA Known Exploited Vulnerabilities catalog updates.

  • Urgent decision: Leadership must mandate emergency hotfix installation on all Cisco FMC instances within 24 hours per government binding directives.

Palo Alto PAN-OS GlobalProtect Auth Bypass — High — Enterprise Infrastructure and Networking

  • Threat overview: Authentication bypass vulnerability in GlobalProtect portal and gateway allows unauthenticated remote adversaries to forge session cookies and gain unauthorized VPN network entry.

  • Strategic risk context: Exposed VPN endpoints allow threat actors to bypass perimeter controls entirely and establish persistent internal network access.

  • Severity and business impact: High risk of network infiltration leading to lateral movement, data exfiltration, or secondary ransomware deployment.

  • Confidence in available intelligence: High confidence backed by vendor research and CISA Known Exploited Vulnerabilities catalog listings.

  • Urgent decision: Leadership must direct immediate patching of PAN-OS firewalls and force re-authentication for all active GlobalProtect VPN sessions.

Today's Intelligence Quality

Intelligence quality across today's brief is high for technical details and vulnerability metrics, backed by authoritative vendor advisories and CISA alerts. Attribution for the water sector attacks remains unconfirmed, with Iranian affiliated threat actors suspected but not definitively linked.

Chapter 02 - Threat & Exposure Analysis

Critical infrastructure systems and edge networking hardware are facing synchronized targeting, combining operational technology exploitation with remote pre-authentication firewall compromises.

Minnesota Water Utilities: Internet-Exposed PLC Intrusion Operations

  • Attack progression: Threat actors gained unauthorized network access to internet-connected programmable logic controllers across Minnesota water facilities by utilizing legitimate engineering software, subsequently modifying operator credentials and IP network configurations to lock out local engineers.

  • Exploitability: Exploitation required direct network access to exposed operational technology ports without requiring complex local exploits, relying instead on exposed interfaces and static or default credential structures.

  • Campaign indicators: Observed techniques include unauthorized modification of controller logic, clearing or changing administrative access accounts, and altering controller tasking to sever human-machine interface communication channels.

  • Threat actor identity and aliases: Unconfirmed direct evidence, though tactics align with Iranian-affiliated operational technology threat groups such as CyberAv3ngers and Handala.

  • Infrastructure fingerprinting: Direct connections established against industrial control system protocols (such as Modbus and DNP3) over public internet routing paths.

  • Sector exposure: Water and Wastewater Utilities, Critical Infrastructure.

  • Geographic exposure: North America, United States (Minnesota).

  • MITRE ATT&CK tactics: Initial Access, Execution, Impact.

CVE-2026-20316 & CVE-2026-20079: Cisco Secure FMC Static Credential and Auth Bypass Exploitation

  • Attack progression: Attackers target the web-based management interface of Cisco Secure FMC by authenticating via static low-privilege system credentials (CVE-2026-20316) to access configuration data, or exploiting unauthenticated web request processing (CVE-2026-20079) to obtain root system shell access.

  • Exploitability: High to Critical. CVE-2026-20316 carries a CVSS score of 5.3, while CVE-2026-20079 carries a maximum CVSS score of 10.0. Both require unauthenticated HTTP or HTTPS access to the targeted management interface.

  • Campaign indicators: Observed deployment of file artifacts located at specific system paths, notably /var/tmp/license.tmp, alongside unauthorized execution of system administration scripts.

  • Threat actor identity and aliases: Under Attribution.

  • Infrastructure fingerprinting: Scanning and exploitation originate from external anonymous hosting infrastructure targeting publicly accessible management ports.

  • Sector exposure: Information Technology, Enterprise Security, Critical Infrastructure.

  • Geographic exposure: Global.

  • MITRE ATT&CK tactics: Initial Access, Execution.

CVE-2026-0257: Palo Alto Networks PAN-OS GlobalProtect Portal Auth Bypass

  • Attack progression: Remote unauthenticated threat actors submit forged authentication cookies to GlobalProtect portals or gateways, bypassing underlying access controls and establishing active authenticated VPN sessions without valid user credentials.

  • Exploitability: Critical, with a CVSS base score of 9.1. Exploitation requires remote network access to the GlobalProtect interface. Active in-the-wild exploitation confirmed by CISA and Unit42.

  • Campaign indicators: Generation of pre-authenticated user session tokens originating from untrusted public IP infrastructure.

  • Threat actor identity and aliases: Under Attribution.

  • Infrastructure fingerprinting: Observed attacker infrastructure includes specific public IPv4 nodes: 23.128.228.6, 104.207.144.154, 146.19.216.119, 146.19.216.120, 146.19.216.125, 179.43.172.213, 185.195.232.139, 198.12.106.60, and 202.144.192.47.

  • Sector exposure: Cross-Sector, Networking, Enterprise Infrastructure.

  • Geographic exposure: Global.

  • MITRE ATT&CK tactics: Initial Access, Persistence.

Cross-Incident Pattern Analysis

A clear convergence is observable between edge security boundary degradation and critical infrastructure targeting. Threat actors actively seek pre-authentication access bypasses in enterprise security gateways to establish persistent internal footholds while simultaneously scanning for internet-exposed industrial control system interfaces to disrupt physical operations.

Chapter 03 - Operational Response

Defenders must prioritize the immediate removal of operational technology devices from public routing alongside mandatory patch deployment for perimeter management appliances.

Minnesota Water Utilities: Immediate Response & Containment

Containment Priorities:

  1. Disconnect all internet-facing programmable logic controllers, human-machine interfaces, and SCADA control assets immediately.

  2. Switch affected utility operations to manual override and mechanical safety controls to preserve physical water distribution integrity.

  3. Force a complete reset of all administrative credentials across engineering software applications (such as Studio 5000, EcoStruxure, and TIA Portal).

Security Hardening Actions:

  • Place all operational technology interfaces behind isolated jump servers protected by multi-factor authentication.

  • Audit controller configurations to identify and revert unauthorized IP or password modifications.

Internal Security Coordination:

  • Notify operational technology site supervisors, municipal administration, and regulatory bodies immediately upon detecting unauthorized logic changes.

  • Escalate to national infrastructure response teams (such as CISA) if operational control is compromised.

Cisco Secure FMC: Immediate Response & Containment

Containment Priorities:

  1. Restrict management interface exposure by placing Cisco Secure FMC instances behind internal management network boundaries.

  2. Apply official Cisco hotfixes resolving CVE-2026-20316 and updates addressing CVE-2026-20079.

  3. Rotate all device credentials, static passwords, and SSL certificates across managed appliances.

Security Hardening Actions:

  • Scan local filesystem directories for exploit artifacts, specifically monitoring for /var/tmp/license.tmp.

  • Enforce strict network access control lists allowing management traffic only from trusted administrator IP blocks.

Internal Security Coordination:

  • Coordinate emergency maintenance windows between network engineering and SOC operations teams.

  • Escalate any evidence of system shell execution to the incident response team.

Palo Alto PAN-OS GlobalProtect: Immediate Response & Containment

Containment Priorities:

  1. Upgrade Palo Alto Networks PAN-OS GlobalProtect gateways and portals to patched release versions fixing CVE-2026-0257.

  2. Terminate all active GlobalProtect VPN user sessions to invalidate potentially forged authentication tokens.

  3. Block known malicious IP addresses at the perimeter firewall layer.

Security Hardening Actions:

  • Enforce multi-factor authentication re-validation for all connecting endpoints.

  • Review GlobalProtect access logs for suspicious client hostnames or anomalous authentication patterns.

Internal Security Coordination:

  • Alert service desk teams regarding forced session logouts and potential user re-authentication inquiries.

  • Escalate unrecognized gateway session originations directly to threat hunting teams.

Defender Priority Order (Today)

  1. Disconnect public internet-exposed PLCs and SCADA assets to prevent direct physical control loss.

  2. Deploy hotfixes for Cisco Secure FMC instances to prevent administrative takeover.

  3. Update PAN-OS GlobalProtect interfaces and terminate active gateway sessions to clear forged credentials.

Minnesota Water Systems PLC Compromise — Timeline

2026-07-26 — Initial unauthorized access observed across Minnesota municipal water systems targeting exposed PLCs. 2026-07-27 — OT teams disconnect affected PLCs, observe modified administrative credentials, and shift operations to manual controls. 2026-07-29 — CISA issues Alert AA26-097A detailing active exploitation of critical infrastructure control devices.

Cisco Secure FMC Vulnerabilities — Timeline

2026-03-15 — Cisco releases initial patches addressing web authentication bypass CVE-2026-20079. 2026-07-29 — CISA adds Cisco FMC CVE-2026-20316 to the Known Exploited Vulnerabilities catalog with active exploitation confirmed. 2026-07-30 — Cisco updates advisory confirming active in-the-wild exploitation of static credential flaw CVE-2026-20316.

Palo Alto PAN-OS GlobalProtect Auth Bypass — Timeline

2026-05-29 — CISA adds Palo Alto PAN-OS CVE-2026-0257 to the Known Exploited Vulnerabilities catalog. 2026-07-30 — Unit42 and industry researchers observe ongoing active exploitation campaigns leveraging forged authentication tokens.

Chapter 04 - Detection Intelligence

CVE-2026-20316 & CVE-2026-20079: Cisco Secure FMC Exploitation Mechanics

  • Attack vector: Network-based unauthenticated HTTP/HTTPS requests targeting management web interfaces.

  • Exploitation mechanism: CVE-2026-20316 relies on built-in static credentials present in the FMC low-privilege user database. CVE-2026-20079 leverages improper input validation in HTTP request processing to bypass web authentication routines.

  • Observed behavior: Successful exploitation yields low-privilege administrative access via static credentials or grants an unauthenticated root system shell on the underlying operating system.

  • Vulnerability details: Static account handling and unauthenticated HTTP web service handlers within Cisco Secure FMC management software.

  • CVE technical context: CVE-2026-20316 (CVSS 5.3), CVE-2026-20079 (CVSS 10.0).

  • Patch status: Vendor hotfixes and updates available.

CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass

  • Attack vector: Network-based HTTP/HTTPS traffic directed at GlobalProtect portals or gateways.

  • Exploitation mechanism: Flawed cookie verification logic allows malicious unauthenticated actors to craft valid authentication tokens without presenting credentials.

  • Observed behavior: Bypasses authentication mechanisms to establish full VPN tunnel access as a legitimate network client.

  • Vulnerability details: Logic error in PAN-OS GlobalProtect portal authentication handling routines.

  • CVE technical context: CVE-2026-0257 (CVSS 9.1).

  • Patch status: Fixed in updated PAN-OS release builds.

Minnesota Water Utilities: Industrial Controller Logic Manipulation

  • Attack vector: Direct network protocol connections over public internet interfaces.

  • Exploitation mechanism: Abuse of standard vendor engineering software protocols to interact directly with exposed PLC management ports.

  • Observed behavior: Password parameters are overwritten, IP addressing structures are changed, and internal PLC logic tasking is modified to disable control access.

  • Vulnerability details: Unauthenticated or weakly authenticated exposed industrial control interfaces.

  • CVE technical context: N/A (Direct protocol misuse and exposed asset compromise).

  • Patch status: Network architecture isolation required.

PAN-OS & Cisco FMC — Indicators & Infrastructure

Indicators of Compromise:

Type

Value

Context

Verdict

IP Address

23.128.228.6

PAN-OS Exploit Origin

Pending

IP Address

104.207.144.154

PAN-OS Exploit Origin

Pending

IP Address

146.19.216.119

PAN-OS Exploit Origin

Pending

IP Address

146.19.216.120

PAN-OS Exploit Origin

Pending

IP Address

146.19.216.125

PAN-OS Exploit Origin

Pending

IP Address

179.43.172.213

PAN-OS Exploit Origin

Pending

IP Address

185.195.232.139

PAN-OS Exploit Origin

Pending

IP Address

198.12.106.60

PAN-OS Exploit Origin

Pending

IP Address

202.144.192.47

PAN-OS Exploit Origin

Pending

Host / MAC

aa:bb:cc:dd:ee:ff

GlobalProtect Client Identifier

Pending

Host / MAC

00:11:22:33:44:55

GlobalProtect Client Identifier

Pending

Host / MAC

GP-CLIENT

GlobalProtect Client Hostname

Pending

Host / MAC

DESKTOP-GP01

GlobalProtect Client Hostname

Pending

Host / MAC

WINDOWS-LAPTOP-001

GlobalProtect Client Hostname

Pending

File Path

/var/tmp/license.tmp

Cisco FMC Exploit Artifact

Pending

Cisco FMC Static Credentials and Auth Bypass: Detection Opportunity

Detection Engineering Opportunities:

  • Immediate detection action: Deploy log detection rules searching for the string /var/tmp/license.tmp across all Cisco FMC log archives within 24 hours.

  • Hunt this week: Inspect web server logs for unauthenticated administrative shell initiation patterns or unexpected system execution commands.

Detection Context Quality:

  • Data source requirements: Cisco FMC web system logs, process execution telemetry, and host audit logs.

  • Known detection gaps: Direct HTTP exploitation may bypass perimeter inspection if management interface traffic is encrypted and uninspected.

Threat Hunting Hypotheses:

  • Hypothesis: Threat actors are executing commands on Cisco FMC interfaces by staging payloads in temporary system storage.

  • Evidence target: File creation events or string matches referencing /var/tmp/license.tmp.

SIEM, EDR, and Network Monitoring Signals:

Sigma Rule (Cisco FMC):

title: Cisco FMC License Exploit Attempt  
logsource:  
  product: cisco
  service: fmc
detection:  
  selection:  
    Message: "*license.tmp*"  
  condition: selection

YARA Rule (Cisco FMC):

rule Cisco_FMC_LicenseTmp  
{  
  strings:  
    $s1 = "/var/tmp/license.tmp"  
  condition: any of them  
}

PAN-OS GlobalProtect Auth Bypass: Detection Opportunity

Detection Engineering Opportunities:

  • Immediate detection action: Deploy SIEM rules to detect GlobalProtect authentication bypass attempts from known malicious IP infrastructure.

  • Hunt this week: Audit VPN gateway session logs for pre authenticated token generation originating from unfamiliar hostnames or client MAC addresses.

Detection Context Quality:

  • Data source requirements: PAN-OS GlobalProtect gateway logs and WAF threat log streams.

  • Known detection gaps: Valid looking forged session cookies can blend in with legitimate user VPN connections without endpoint telemetry cross verification.

Threat Hunting Hypotheses:

  • Hypothesis: Adversaries are generating pre authenticated VPN tunnel sessions without submitting user credentials.

  • Evidence target: Gateway session establishment logs associated with generic hostnames like GP CLIENT or DESKTOP GP01.

SIEM, EDR, and Network Monitoring Signals:

Splunk Query (PAN-OS):

index=panw_logs sourcetype="pan:waf_threat"  
src_ip IN (23.128.228.6, 104.207.144.154, 146.19.216.119, 146.19.216.120, 146.19.216.125, 179.43.172.213, 185.195.232.139, 198.12.106.60, 202.144.192.47)  
AND (application="globalprotect")  
| stats count by src_ip, src_user

Minnesota Water Utilities PLC Attacks: Detection Opportunity

Detection Engineering Opportunities:

  • Immediate detection action: Implement industrial intrusion detection signatures to flag unexpected logic writes or credential changes on industrial controllers.

  • Hunt this week: Analyze Modbus and DNP3 network traffic patterns for unauthorized IP addresses communicating directly with OT devices.

Detection Context Quality:

  • Data source requirements: Network switch mirror ports, industrial IDS traffic captures, and engineering workstation command logs.

  • Known detection gaps: Native PLC control traffic often lacks encrypted authentication, making malicious write commands indistinguishable from legitimate engineer traffic without context baseline analysis.

  • T1190 Exploit Public Facing Application: Adversaries exploited web management interfaces on Cisco FMC and Palo Alto PAN-OS GlobalProtect portals to gain initial network entry.

  • T1078 Valid Accounts: Threat actors leveraged hardcoded default system credentials in Cisco FMC under CVE-2026-20316 to obtain unauthorized access.

  • ICS-052 Modify Controller Tasking: Attackers modified underlying logic tasking on water utility programmable logic controllers, disrupting standard automated water management.

  • ICS-102 Denial of Control: Threat actors changed administrative passwords on industrial controllers, locking out human operators and preventing control actions.

  • ICS-110 Manipulation of Control: Adversaries changed IP configuration settings and operating logic on exposed water sector controllers to disrupt operations.

Chapter 05 - Governance, Risk & Compliance

Minnesota Water Utilities: Regulatory & Business Risk Exposure

  • Regulatory exposure: Critical infrastructure operations face strict oversight regarding physical safety and emergency reporting mandates. Loss of operational control triggers immediate regulatory notifications to federal infrastructure protection bodies.

  • Business risk impact: Severe operational disruption risk requiring manual field overrides to prevent public service outages. Reputational risk remains high due to public interest in safe municipal water distribution.

  • Threat actor attribution: CyberAv3ngers and Handala are suspected based on operational patterns, but formal attribution remains under investigation.

  • CISO Risk Decision: Escalate. Immediately mandate isolation of all internet exposed industrial controllers behind secure jump hosts with multi factor authentication.

Cisco Secure FMC Vulnerabilities: Regulatory & Business Risk Exposure

  • Regulatory exposure: Federal binding directives require federal agencies and critical sector operators to patch vulnerabilities listed on the CISA KEV catalog within specified deadlines.

  • Business risk impact: Administrative takeover of centralized firewall management infrastructure compromises network wide security policy enforcement, leading to secondary breaches.

  • Threat actor attribution: No confirmed threat group attribution available at this time.

  • CISO Risk Decision: Escalate. Mandate emergency deployment of vendor hotfixes for Cisco FMC within 24 hours.

Palo Alto PAN-OS GlobalProtect Auth Bypass: Regulatory & Business Risk Exposure

  • Regulatory exposure: Unauthorized perimeter network access creates data breach risks subject to international privacy frameworks and mandatory incident disclosure requirements.

  • Business risk impact: Pre authenticated access bypasses edge security controls, exposing internal corporate networks to ransomware deployment and data exfiltration.

  • Threat actor attribution: Active exploitation confirmed in the wild, but actor identity remains unattributed.

  • CISO Risk Decision: Escalate. Force re authentication of all active VPN user sessions after applying vendor updates.

Board-Level Risk Summary

Concurrently exposed perimeter security appliances and internet connected industrial controllers present an acute dual threat to critical operations. Perimeter management systems require emergency hotfix application, while operational technology assets must be disconnected from public internet routing immediately to prevent operational disruption.

Chapter 06 - Adversary Emulation

Minnesota Water Utilities: Validation & Purple Team Scenarios

  • Detection Validation Scenarios: Deploy a lab industrial controller with standard vendor engineering software reachable. Simulate an unauthorized session where an engineer password is changed and controller network settings are modified to test industrial IDS alerting.

  • Purple Team Exercise Suggestions: Test blue team response timelines when an industrial asset loses communication due to unauthorized IP modification.

  • ATT&CK-Aligned Security Testing: ICS-102 Denial of Control. Safely emulate password rotation scripts against non production PLCs to verify operational technology alert generation.

Cisco FMC & PAN-OS Firewall Exploits: Validation & Purple Team Scenarios

  • Detection Validation Scenarios: Install vulnerable virtual instances of security management software in an isolated test subnet. Execute proof of concept bypass scripts and verify whether SIEM rules flag artifact creation like /var/tmp/license.tmp or anomalous GlobalProtect gateway logins.

  • Purple Team Exercise Suggestions: Conduct a purple team drill simulating perimeter VPN access using pre authenticated session tokens to evaluate internal EDR detection effectiveness.

  • ATT&CK-Aligned Security Testing: T1190 Exploit Public Facing Application. Safely probe perimeter management web endpoints to confirm patch deployment and vulnerability remediation.

Intelligence Confidence80%


Assessment Factor

Evaluation

Detail

Technical Evidence Quality

High

Vendor advisories from Cisco and Palo Alto Networks provide authoritative technical details.

Active Exploitation Confirmation

Confirmed

CISA KEV listings confirm in the wild exploitation for edge appliance flaws.

Operational Impact Evidence

Verified

Field reports confirm physical water utility intrusions and operator lockouts in Minnesota.

Threat Actor Attribution

Low

Linkages to Iranian groups like CyberAv3ngers remain unconfirmed and marked under attribution.

Overall Confidence Score

80%

High technical and operational certainty offset by unconfirmed threat actor attribution.