Bharat Threat FeedGlobal threats, decoded for Indian defenders
Government & Defence Sector Edition · August 2026

Government & Defence Sector Edition — August 2026

Four internet-facing management planes were pulled into active exploitation over the past three weeks — an SD-WAN orchestrator, an SSL-VPN gateway pair, a firewall manager, and a wave of exposed water-utility controllers in the United States — and every one of those product families sits inside Indian power, oil and gas, telecom, and transport estates. Add a pending Bill on critical-infrastructure accountability and a CERT-In push on AI-accelerated exploitation, and August opens with the sector's remote-access layer as the defining risk.

1. Sector snapshot

The pattern across July was consistent: attackers went after the systems that manage other systems, not end-user endpoints. SD-WAN orchestrators, SSL-VPN concentrators, and firewall management consoles gained three separate CISA Known Exploited Vulnerabilities entries in the last ten days of July, while a joint FBI-CISA-EPA advisory tracked hands-on-keyboard intrusion into internet-exposed PLCs at water utilities. None of these incidents named an Indian victim. All of them depend on product families and exposure patterns that are common in Indian CI operators' estates, which is the lens this issue applies throughout.

2. Threats targeting Critical Infrastructure

1CriticalCVSS 10.0

Arista VeloCloud Orchestrator CVE-2026-16812 (CVSS 10.0) — unauthenticated command injection, active exploitation

An unauthenticated attacker with network access to the on-premises VeloCloud Orchestrator web interface can run arbitrary operating-system commands, giving full control of the SD-WAN fabric it manages. No credentials are required and internet exposure is the appliance's default posture.

India exposuretelecom carriers, power utilities, and multi-site industrial operators using on-prem VCO to manage branch and substation SD-WAN links.
Actionpatch to 5.2.3.14 / 6.1.3.4 / 6.4.2.4 / 7.0.0.1 or later immediately; if patching is delayed, remove VCO from direct internet exposure and review edge configuration for unauthorised changes.
SourceArista PSIRT; BleepingComputer; The Register (27–28 Jul 2026).
2CriticalCVSS 10.0

SonicWall SMA1000 CVE-2026-15409 (CVSS 10.0 SSRF) chained with CVE-2026-15410 (CVSS 7.2 code injection) — SSL-VPN gateways compromised in the wild

The unauthenticated SSRF flaw in the Work Place interface gives initial access; chained with the post-authentication injection bug, it yields full appliance compromise and credential theft. SonicWall and CISA confirmed active exploitation.

India exposureany CI operator using SMA1000 as the remote-access front door for OT vendors, contractors, or distributed field staff.
Actionapply firmware 12.4.3-03453 / 12.5.0-02835 or later now; rotate all SMA1000 admin and Work Place credentials and enforce MFA regardless of patch status.
SourceSonicWall PSIRT; Arctic Wolf; Canadian Centre for Cyber Security (14–15 Jul 2026).
3

Cisco Secure Firewall Management Center CVE-2026-20316 — hard-coded low-privilege credential, actively exploited

A built-in account with a static credential lets an unauthenticated attacker log in to FMC and read sensitive configuration data; Cisco rates it High severity because it can be chained with other FMC flaws to escalate privilege over firewall policy.

India exposureany operator centralising firewall policy for CI segments through FMC, including managed-security arrangements.
Actionapply Cisco's hotfix across 7.0–7.7 and 10.0 branches; hunt for the account's use via FMC license and access logs.
SourceCisco PSIRT; The Hacker News; CISA KEV (29–30 Jul 2026).
4

Suspected Iran-linked actor exploiting exposed water-utility PLCs across multiple US states — a global TTP, not an India-targeting claim

Actors believed by investigators to be CyberAv3ngers (also tracked as Storm-0784, Bauxite, UNC5691) accessed internet-facing Rockwell/Allen-Bradley, Schneider Electric, and Siemens PLCs, changed device passwords and IP addresses to lock out operators, and altered HMI displays; over thirty Minnesota systems and utilities in at least a dozen states were affected, forcing several back to manual operation. No ransom demand was made.

India exposurethe same PLC brands and internet-exposed-controller pattern are present in Indian water treatment, power distribution, and manufacturing OT; the technique, not the target, is the transferable risk.
Actioninventory every internet-facing PLC; remove direct exposure, restrict engineering-workstation access, and rehearse a manual-operations fallback.
SourceCISA/FBI/EPA advisory AA26-097A; Tenable (22, 28 Jul 2026).

3. Sector tech & exposures

- Management-plane concentration risk. All three July KEV additions above are administrative interfaces, not user-facing services — a single compromised orchestrator, VPN gateway, or firewall manager gives an attacker control over an entire fleet of devices at once, a disproportionate return for one exploit chain. - OT threat-actor growth. Dragos now tracks 26 distinct OT-focused threat groups worldwide, 11 confirmed active through 2025, alongside a documented rise in ransomware reaching industrial operators; the same report flagged over 100 internet-exposed battery energy storage system inverters, a device class expanding fast in India's renewable rollout. Source (with date): Dragos 2026 OT Cybersecurity Year in Review (17 Feb 2026). - Pakistan-nexus APT36/SideCopy continue cross-platform RAT campaigns, now spanning Linux as well as Windows hosts, against Indian defence, government, and CI-adjacent targets — a standing backdrop rather than a new incident this cycle. Source (with date): The Hacker News (11 Feb 2026).

4. Regulatory & compliance watch

- CERT-In frontier-AI exercises and OEM directive. Between June and July 2026, CERT-In ran ten drills on defending against AI-accelerated exploitation, with 1,470 participants from 345 organisations spanning power, telecom, and BFSI, and issued a June directive requiring OEMs and technology providers to build in AI-assisted security testing and faster patch response. Source (with date): CERT-In; The News Mill (30 Jul 2026). - Critical Infrastructure (Resilience, Protection and Accountability) Bill, 2026 remains a pending private member's Bill in the Rajya Sabha, proposing criminal liability for negligent CI failures, a national CI classification framework, and mandatory monitoring dashboards for power grids, dams, ports, and transit systems; it has not yet been taken up for passage. Source (with date): ANI (6 Feb 2026); OpIndia (Jul 2026). - NCIIPC/CERT-In baseline obligations — annual third-party audit for Protected Systems, six-hour incident reporting, and 180-day in-India log retention under the CERT-In Cyber Security Directions, 2022 — are the practical test bench the July water-utility incident argues for rehearsing now, before an equivalent event, not after. Source (with date): CERT-In Cyber Security Directions, 2022, issued under Section 70B(6) IT Act (28 Apr 2022).

5. Actor in focus

CyberAv3ngers (Storm-0784 / Bauxite / UNC5691) — attribution suspected, not independently confirmed. Publicly tracked as an Iran-linked, IRGC-associated cluster, CyberAv3ngers' hallmark is opportunistic compromise of internet-exposed industrial controllers rather than a single software vulnerability: default or reused credentials, direct PLC web-interface access, and manipulation of device configuration to disrupt rather than destroy. The late-July water-utility campaign fits that pattern and again avoided a ransom demand, consistent with a disruption or messaging motive over financial gain. For Indian CI operators the relevance is the access pattern: any PLC or RTU reachable from the open internet without compensating controls is a candidate for the same opportunistic compromise, regardless of who is behind the next attempt. Source (with date): CISA/FBI/EPA advisory AA26-097A; Tenable (22, 28 Jul 2026).

6. IOC pack

Only public, attributed indicators; defang before operational use and pull exact values from the primary advisories. - CVE-2026-16812 (Arista VCO): exploitation source IPs from Arista's security advisory — 8[.]19[.]75[.]217, 206[.]72[.]242[.]124, 206[.]72[.]242[.]162 (Arista Security Advisory 0144, Jul 2026). - CVE-2026-15409/15410 (SonicWall SMA1000): extraweb_access.log entries showing /wsproxy requests with suspicious localhost or loopback host parameters returning HTTP 101, and rogue /__api__/login or /__api__/logout routes inside /var/lib/unit/conf.json (SonicWall PSIRT; Rapid7, Jul 2026). - CVE-2026-20316 (Cisco FMC): unexplained entries referencing /var/tmp/license.tmp in /var/log/messages (Cisco/The Hacker News, 30 Jul 2026). - AA26-097A PLC intrusions: unscheduled PLC password/IP changes, altered Add-On Instruction code modules, and HMI display values inconsistent with field readings — full indicator set in the CISA advisory (22 Jul 2026 update).

7. Tiered actions (Board / CISO / SOC)

Board: Commission a 72-hour inventory of every internet-facing management interface — SD-WAN orchestrator, SSL-VPN, firewall manager, PLC/HMI remote access — across CI estates, and track the pending CI Accountability Bill for governance implications.

CISO: Patch CVE-2026-16812, CVE-2026-15409/15410, and CVE-2026-20316 on an emergency track; rotate all SonicWall and Arista admin credentials; commission compromise assessments wherever vulnerable versions were internet-facing; align vulnerability SLAs to CERT-In's AI-accelerated exploitation guidance.

SOC: Hunt the published Arista VCO IPs and SonicWall log artefacts; audit every PLC/RTU for direct internet exposure and unscheduled configuration changes; validate MFA on OT remote-access paths; confirm 180-day log retention and rehearse manual-operations fallback for at least one CI process line.

8. Source index

Arista PSIRT / Security Advisory 0144, CVE-2026-16812 · BleepingComputer (27 Jul 2026) · The Register (28 Jul 2026) · cybersecuritynews.com (3 Aug 2026) · SonicWall PSIRT, CVE-2026-15409/15410 · Arctic Wolf (15 Jul 2026) · Canadian Centre for Cyber Security AV26-699 (14 Jul 2026) · Cisco PSIRT, CVE-2026-20316 · The Hacker News (30 Jul 2026) · CISA KEV catalog (27, 29 Jul 2026) · CISA/FBI/EPA advisory AA26-097A (7 Apr 2026, updated 22 Jul 2026) · Tenable (28 Jul 2026) · Dragos 2026 OT Cybersecurity Year in Review (17 Feb 2026) · The Hacker News, APT36/SideCopy (11 Feb 2026) · CERT-In; The News Mill (30 Jul 2026) · ANI (6 Feb 2026) · OpIndia (Jul 2026) · CERT-In Cyber Security Directions, 2022 (28 Apr 2022).

9. Byline

Nirad Threat Research

Nirad Bharat Threat Feed — Critical Infrastructure Edition | Bharat-first threat intelligence