Originally Published August 31, 2026
This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.
Florida’s critical infrastructure operators face an increasingly volatile cyber threat environment characterized by machine-speed exploitation of vulnerabilities, persistent poisoning of the software supply chain, and early yet rapidly evolving use of AI agents in offensive operations. Over the next six to nine months, organizations should expect adversaries to increasingly experiment with autonomous AI agents for reconnaissance and exploitation; while one recent campaign showed these agents independently enumerating targets and attempting exploits, confirmed data theft in that case still required manual, human-directed exploitation — a distinction that matters for realistic defensive planning. Cyber threat actors are accelerating initial access by deploying adversary-in-the-middle (AiTM) phishing frameworks to bypass multi-factor authentication (MFA) and exploiting zero-day vulnerabilities in edge networking appliances, remote monitoring and management (RMM) platforms, and identity infrastructure within hours of disclosure. Internet-exposed programmable logic controllers (PLCs) across water and energy networks also remain under sustained attack; federal agencies have linked some of this activity to Iranian-affiliated actors in prior advisories, though the most recent water-sector campaign has not been formally attributed. Because Florida’s critical infrastructure sectors maintain highly interconnected technology stacks, shared cloud environments, and extensive third-party vendor relationships, operators must prioritize rapid vulnerability remediation, enforce phishing-resistant multi-factor authentication, strictly isolate OT perimeters, and continuously validate business continuity frameworks.
Confidence Assessment: High
Hackers Target US Firms in FastJson Zero-Day Attacks Cyber threat actors are actively exploiting a critical remote code execution (RCE) zero-day vulnerability in the FastJson open-source Java library (versions 1.2.68 through 1.2.83). Unauthenticated attackers send specially crafted JavaScript Object Notation (JSON) payloads to execute arbitrary operating system (OS) commands on host servers. Imperva reports that FastJson 1.x is no longer actively maintained, so it is unlikely to receive a security update. Because FastJson is a foundational dependency embedded across enterprise Java applications in Florida’s financial, healthcare, and commercial sectors, organizations should immediately audit application manifests and deploy vendor patches.
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor A sophisticated social engineering campaign is targeting enterprise users via Microsoft Teams. Cyber threat actors impersonate internal IT helpdesk personnel via Microsoft Teams voice calls and persuade employees to approve a Quick Assist remote-support session, after which PowerShell staging scripts deploy a custom Go-based backdoor (GoGRPC) that blends its command-and-control traffic with legitimate enterprise traffic. Because Microsoft Teams is universally deployed across Florida’s critical infrastructure perimeters, security teams should update employee awareness training and enforce strict authentication policies for internal IT communications.
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks. Palo Alto Networks Unit 42 identified an operational shift in which a Chinese-speaking threat actor deployed autonomous artificial intelligence (AI) agent frameworks to execute end-to-end attack chains. The AI agent autonomously performed reconnaissance and attempted exploitation across seven vulnerabilities, but these autonomous attempts did not achieve compromise; confirmed data exfiltration resulted from separate, manually directed exploitation of a Citrix NetScaler vulnerability. This development signals a narrowing window for defender intervention across all critical infrastructure perimeters in Florida, requiring automated detection and response capabilities.
CISA, NSA, and FBI Release 2026 Minimum Elements for a Software Bill of Materials & Open Source Software Security Principles The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) issued joint authoritative guidance establishing updated minimum elements for Software Bill of Materials (SBOM) and open-source software (OSS) risk management. The guidelines provide an operational framework for identifying nested open-source dependencies, verifying code provenance, and managing third-party software risk. Florida critical infrastructure operators should update vendor procurement contracts and software governance policies to mandate compliance with these federal supply chain standards.
All Sectors Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Midnight Blizzard Deploys CaptiveCrunch AiTM Infrastructure to Target Travelers Russian state-sponsored group Midnight Blizzard (Advanced Persistent Threat 29 [APT29]) is executing a global campaign targeting hospitality networks, hotels, and conference centers. The actors compromise captive-portal Wi-Fi gateways to deploy “CaptiveCrunch” adversary-in-the-middle (AiTM) infrastructure, serving custom malware (CornFlake and ChocoShell) and harvesting corporate Microsoft 365 credentials from business travelers. Because Florida’s hotel and convention-center industry hosts a high volume of business travelers, corporate security teams should treat hotel and conference Wi-Fi as untrusted statewide.
Commercial Facilities Sector Recommendations:
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Zimbra The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA) issued a joint cybersecurity advisory warning of active phishing campaigns conducted by Russian state-sponsored cyber threat actors (LAUNDRY BEAR) targeting the Zimbra Collaboration Suite. The cyber threat actors exploit zero-day vulnerability CVE-2025-66376, deploying an automated payload (Ulej) that executes when an email is viewed in the webmail portal. Florida telecommunications providers and regional Internet Service Providers (ISPs) utilizing Zimbra must remain vigilant against these zero-click webmail threats.
Communications Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
2026 Minimum Elements for a Software Bill of Materials (SBOM) The Cybersecurity and Infrastructure Security Agency (CISA), alongside the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), and international partners, released the updated 2026 Minimum Elements for a Software Bill of Materials (SBOM). Superseding the 2021 baseline, this comprehensive update expands the scope of software supply chain transparency to explicitly include artificial intelligence (AI) software, open-source software, and Software-as-a-Service (SaaS). By introducing new data fields—such as cryptographic component hashes, licensing details, and generation context—the guidance shifts SBOMs from static compliance documents into dynamic, machine-readable records. These enhancements are designed to facilitate machine-speed automated analysis, empowering organizations to better identify, assess, and mitigate risks across their software ecosystems. Defense contractors operating near Florida’s major military installations must integrate these updated SBOM elements into their software procurement pipelines.
Defense Industrial Base Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
BitSight Reports 56% Decline in Exposed Automatic Tank Gauge Systems A cybersecurity trend analysis reveals a 56% reduction in internet-exposed automatic tank gauge (ATG) systems across U.S. fuel distribution networks following federal security warnings. While this indicates improved perimeter hygiene, unmanaged fuel monitoring systems remain a target for Iranian state-sponsored cyber threat actors seeking operational intelligence. Florida’s fuel distribution networks and port authorities must ensure their automatic tank gauge systems are not exposed to the public internet to prevent operational disruptions.
Energy Sector Recommendations:
Extortion Group UNC6671 Targets Major Financial Institutions via Vishing Financial sector intelligence reports highlight an active campaign by extortion group UNC6671 (linked to BlackFile) targeting high-value financial institutions and hedge funds. The cyber threat actors impersonate IT helpdesk staff and contact employees directly, often via personal mobile devices, under the pretext of urgent security migrations, redirecting them to spoofed login portals where adversary-in-the-middle (AiTM) infrastructure intercepts credentials and MFA tokens. Florida-based financial institutions and wealth management firms face a high risk from these targeted social engineering and vishing campaigns.
Also, see “#StopRansomware: Gunra Ransomware” under Healthcare and Public Health Sector
Financial Services Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
See “#StopRansomware: Gunra Ransomware” under Healthcare and Public Health Sector
Health-ISAC Warns of Rising ShinyHunters Data Theft Attacks on Healthcare The Health Information Sharing and Analysis Center (Health-ISAC) issued a threat advisory warning healthcare providers of escalating data extortion campaigns by ShinyHunters. The group focuses on compromising third-party cloud Software-as-a-Service (SaaS) integration partners, abusing Open Authorization (OAuth) consent tokens, and exfiltrating patient records without deploying ransomware encryption. Florida health systems must audit third-party cloud permissions to mitigate data leakage.
Intrusion at US Healthcare Software Provider Puts 3.8M People’s Data at Risk A US healthcare software provider admitted that hackers may have compromised sensitive data belonging to 3.8 million individuals. This incident, marked as the largest healthcare breach reported to regulators so far this year, underscores the severe supply chain risks facing Florida’s healthcare sector.
#StopRansomware: Gunra Ransomware A joint U.S.–South Korea advisory warned of Gunra ransomware, a Conti-derived double-extortion variant. Separate South Korean research has identified overlapping attack infrastructure between some Gunra incidents and tools associated with North Korea’s Lazarus Group, though a direct operational relationship has not been confirmed. This actively targets the healthcare/public health, financial services, government facilities, critical manufacturing, transportation, and utilities sectors.
Healthcare and Public Health Sector Recommendations:
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day A maximum-severity command injection zero-day vulnerability in Arista VeloCloud Orchestrator is under active in-the-wild exploitation. Unauthenticated remote attackers can send crafted Hypertext Transfer Protocol (HTTP) requests to execute arbitrary operating system (OS) commands with root privileges on central network management servers. CISA added this flaw, along with the Fortinet FortiOS vulnerability CVE-2025-68686, to its Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation.
Cisco FMC Static Credential Zero-Day Flaw Exploited in Attacks (CVE-2026-20316 – CISA KEV Addition): Cisco warned of active zero-day exploitation targeting Cisco Secure Firewall Management Center (FMC). The flaw involves hard-coded credentials for a low-privilege built-in account, allowing unauthenticated remote attackers to log in and access sensitive data. Cisco warns that this access could potentially be chained with other, undisclosed FMC vulnerabilities to escalate privileges. Organizations running Cisco FMC must deploy vendor patches immediately and audit administrative accounts for rogue entries. Because Cisco Secure FMC is widely deployed to centrally manage perimeter firewalls across Florida’s critical infrastructure sectors, operators using it should treat patching as urgent regardless of organization size.
VMware Fixes Three Critical Flaws Allowing Auth Bypass and VM Escapes VMware released emergency security patches for vCenter Server, ESXi, and Cloud Foundation. The updates resolve three critical vulnerabilities: an authentication bypass in vCenter’s Directory Service (CVE-2026-59309) and a directory traversal flaw enabling remote code execution (CVE-2026-59310), both exploitable by an unauthenticated attacker with network access to vCenter; and an out-of-bounds write in the VMXNET3 adapter (CVE-2026-47876) that lets an attacker who already holds local administrative privileges inside a VM escape to the ESX host. IT administrators should apply these updates immediately.
N-able N-central RMM Server Authentication Bypass Exploited in the Wild N-able confirmed active in-the-wild exploitation of an authentication bypass vulnerability affecting its N-central Remote Monitoring and Management (RMM) platform. Attackers bypass authentication to take over N-central servers and push malicious software to downstream managed clients. Managed Service Providers (MSPs) must update N-central to version 2026.3.1.7 or higher immediately.
ChainDrop npm Supply Chain Worm Targets CI/CD Pipelines via Bun Runtime Security researchers uncovered “ChainDrop,” a self-propagating supply chain worm affecting the Node Package Manager (npm) registry. The worm infects developer environments, utilizes the Bun JavaScript runtime to execute hidden preinstall scripts, and exfiltrates cloud credentials to an Ethereum blockchain dead-drop resolver. Development and Operations (DevOps) teams must audit package manifests (including keyv and flat-cache) and revoke exposed deployment tokens
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks A newly disclosed Windows zero-day (CVE-2026-68820, an afd.sys use-after-free) allowed Lazarus Group (North Korea) to gain SYSTEM-level control and deploy the ‘ForestTiger’ backdoor as part of the ongoing ‘Operation Dream Job’ campaign, which targets defense, aerospace, and aviation organizations through fraudulent recruiter outreach. Microsoft patched the flaw on August 11 as part of Patch Tuesday.
AI Failed to Properly Patch Software Flaws 74% of the Time, 1Password’s Study Warns A study by Off-By-1-Labs and 1Password revealed that frontier AI models failed to properly patch software flaws 74% of the time. Florida IT teams utilizing AI coding assistants for vulnerability remediation must enforce rigorous human oversight and manual code reviews. Florida MSPs and IT administrators should require a mandatory human security review of any AI-generated patch before it reaches production, particularly for downstream client environments.
Information Technology Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Delivery mega leak: 840M+ files exposed as US delivery company leaks massive file storage Last-mile delivery provider SpeedX left an unsecured Microsoft Azure cloud storage container publicly accessible, exposing more than 840 million customer and driver records, including home addresses, shipping labels, parcel delivery photos, and driver’s license images. SpeedX handles deliveries for major e-commerce platforms, including Shein, Temu, Amazon, and TikTok Shop; researchers found no evidence of prior malicious access but warned the exposed data could fuel large-scale, delivery-themed phishing campaigns. Because SpeedX and similar last-mile carriers operate throughout Florida, transportation and logistics operators statewide should audit their own cloud storage configurations for comparable misconfigurations.
North Carolina Ports Cyberattack Disrupts Three Locations A cyberattack targeting North Carolina ports was reported as “contained” on August 6, with the U.S. Coast Guard and state officials actively investigating the incident’s scope and origin. Florida’s maritime and freight logistics hubs should review network segmentation between administrative IT systems and terminal gate operations, and validate manual fallback procedures to sustain cargo processing during an IT outage.
Transportation Systems Sector Recommendations:
CISA, FBI, and EPA Issue Joint Warning on Active Cyberattacks Targeting Water Sector PLCs & FBI/EPA Public Service Announcement (Synthesized Threat Profile) The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and the Environmental Protection Agency (EPA) issued urgent joint advisories warning of an active, multi-state cyberattack campaign targeting internet-exposed programmable logic controllers (PLCs) in the Water and Wastewater Systems Sector. Iranian-affiliated actors are actively exploiting internet-exposed Rockwell Automation and Allen-Bradley PLCs (specifically MicroLogix 1100 and 1400 models) via the EtherNet/IP protocol. The intrusions have caused pressure loss and flooding, forced manual workarounds, and triggered boil-water advisories across utilities in at least 12 states. Security scans reveal that over 4,000 industrial controllers remain exposed online nationwide. Florida water utilities must urgently inspect operational technology (OT) perimeters and disconnect PLCs from public networks.
Although the original CISA alert itself does not name any states, based on multiple corroborating reports (SecurityWeek, Cybernews, NBC News, Newsweek), six states have been publicly named as affected by this campaign (others remain unnamed):
Water and Wastewater Systems Sector Recommendations:
This is a periodic operational intelligence analytic product for Florida’s Critical Infrastructure (CI) Managers, Planners, and CISOs to provide an integrated synthesis of recent CI-focused Threat Actors and their campaign activity. This issue covers trends in the period July 15-August 14, 2026.
1. China-Nexus Adversaries: Long-Term Espionage, Supply Chain Hijacking, and AI Integration
2. Iran-Nexus Adversaries: Coercive Disruption, OT Probing, and Asymmetric AI Weaponization
3. Russia-Nexus Adversaries: Stealthy Espionage, Edge Network Hijacking, and Tactical Manipulation
4. North Korea-Nexus Adversaries: Supply Chain Poisoning and Falsified Remote IT Identities
5. Cybercriminal Extortion Ecosystem: EDR Blinding and Double Extortion