Bharat Threat FeedGlobal threats, decoded for Indian defenders
Government & Defence Sector Edition · October 2026

Government & Defence Sector Edition — October 2026

Between 22 September and 4 October, exploitation was confirmed in an SD-WAN manager, an SD-WAN orchestrator, a firewall management server, a secure mail gateway and a remote-access appliance. Each is a place where one unauthenticated request yields control of an estate rather than a single host. In the same weeks a State Data Centre in India carried active malware for five days and took departmental portals down with it, and a state department's website was defaced while sitting on a commercial hosting account. For Indian government and defence estates the thread is consistent: the systems that administer other systems are now the target, and most of them are not on anyone's patch calendar.

1. Sector snapshot

September pushed the exposure up a layer. CISA catalogued Check Point, Arista VeloCloud and F5 entries on 22 September, a Cisco Catalyst SD-WAN Manager authentication bypass on 30 September, Fortinet FortiMail on 1 October and a Citrix NetScaler flaw on 4 October. All of these products administer or front other systems, so a successful request buys policy control, mail flow or remote access across a department. For scale on the Indian backdrop, Seqrite's India Cyber Threat Report 2026 recorded 265.52 million detections across its own India telemetry for October 2024 to September 2025, with trojans at 88.4 million and file infectors at 71.1 million. That is Seqrite's telemetry, cited as theirs.

Source (with date): Seqrite India Cyber Threat Report 2026; CISA KEV (22 Sep, 30 Sep, 01 Oct and 04 Oct 2026).

2. Threats targeting government & defence

Cisco Catalyst SD-WAN Manager authentication bypass, CVE-2026-76504 (CVSS 9.8). Improper handling of hex and URI encoding lets an unauthenticated attacker send a crafted HTTP request to the API and obtain administrator access to vManage. Catalogued 30 September 2026 with a 3 October federal date, the eighth Cisco SD-WAN flaw added during 2026.Exposed:departments and PSUs using Catalyst SD-WAN for district and field connectivity, where the manager holds every branch configuration.Action:patch, then review service proxy and vManage logs for POST requests to /j_security_check, especially with usernames beginning viptela-reserved-.

Source (with date): CISA KEV (30 Sep 2026); The Hacker News (01 Oct 2026).

Fortinet FortiMail unauthenticated file write, CVE-2026-104286 (CVSS 9.8). Path traversal combined with improper handling of a NULL byte, allowing arbitrary file writes through crafted HTTP or HTTPS requests. Fortinet confirmed exploitation without stating when attacks began. Affected: 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9. Fixes are 8.0.2, 7.6.7 and 7.4.9, unreleased when this was reported, so mitigations are the control for now: disable identity-based encryption and take the management interface off the internet. The 7.2 branch has no listed fixed build, which makes migration the real remediation there.

Source (with date): Fortinet PSIRT; CISA KEV (01 Oct 2026); Help Net Security (02 Oct 2026).

Check Point pre-authentication code execution and management traversal, CVE-2026-85102 and CVE-2026-93616 (both CVSS 9.8). The first is improper certificate validation during VPN negotiation on Security Gateway and Spark firewalls: a crafted certificate presented before authentication completes gives code execution without credentials, and Check Point states exploitation began 12 September 2026 against Spark customers globally. The second is a pre-authentication path traversal in the Security Management web service allowing a script to be uploaded and run on the management server, with pinpointed attacks detected 23 July 2026.Action:patch both, then review logs for unusual certificate-based Mobile Access logins and for uploads to the management server.

Source (with date): Check Point advisory (22 Sep 2026); CISA KEV (22 Sep 2026).

A State Data Centre carried malware for five days. Reporting on the West Bengal State Data Centre states malware was active on the main server from 9 to 13 September 2026. Websites of several departments, including Public Works, Housing, Municipal Affairs and Urban Development, and the State Police, went down, with backend operations blocked for some. Forensic examiners were reported to fear that documents from four departments including Finance had been taken and destroyed. Treat the loss as reported and feared rather than established; the investigation was continuing and the main server had not returned to normal. The structural point: a State Data Centre is shared tenancy for dozens of departments, so one intrusion is a multi-department outage, and recovery rests on restore paths nobody rehearsed.

Source (with date): UNI India (22 Sep 2026); The Statesman (Sep 2026).

A departmental portal defaced on someone else's hosting account. The Kerala General Administration Department website was defaced on 27 September 2026, with a claim of responsibility by a group calling itself Team Blackleets, described in reporting as suspected Pakistan-based. That claim is the claimant's, not an attribution. The hosting provider suspended the account, officials said a cyber team was checking for any data breach, and the portal was still unavailable on 30 September 2026. Defacement is unsophisticated; the control gap is not. A departmental site on a commercial shared-hosting account sits outside the department's own monitoring, patching and incident-response path.

Source (with date): The Print (27 Sep 2026); Organiser (30 Sep 2026).

3. Sector tech & exposures

- The SD-WAN and access control planes, twice over. Arista VeloCloud Orchestrator CVE-2026-93952, improper input validation rated CVSS 10.0 and confirmed exploited, announced 22 September 2026 and catalogued the same day with a 25 September federal date. An attacker needs network access to the on-premises orchestrator web interface and the public portion of the VeloCloud Edge authentication certificate, but no tenant or operator credentials. Affected builds are 6.1.3.7 and below and 7.0.0.2 and below, with fixes in 5.2.3.16 and 6.4.2.8; confirm your branch has a build to move to. Alongside it, F5 BIG-IP APM CVE-2026-94127 is a heap-based buffer overflow rated CVSS 9.8 giving unauthenticated remote code execution, published 22 September 2026 with exploitation confirmed. It is not reachable in a default build: the virtual server must carry both an APM access policy and an OAuth profile, which makes this a configuration audit rather than a version check. Source (with date): CISA KEV (22 Sep 2026); BleepingComputer (23 Sep 2026). - Citrix NetScaler CVE-2026-88779, where the patch did not end the matter. A memory overflow in NetScaler ADC and Gateway rated CVSS 8.7, reachable where a customer-managed appliance is configured as a SAML service provider or identity provider. Citrix published the bulletin and fixed builds on 3 October 2026 after targeted exploitation had been observed, and CISA catalogued it on 4 October with a 7 October date. Documented impact is denial of service and repeated restart, and administrators reported crashes on appliances patched days earlier for the August and September NetScaler flaws. There is no broadly documented public proof of reliable remote code execution, so do not escalate it to that in a board paper. In government estates SAML is the single sign-on path into departmental portals, so an outage here is an authentication outage. Source (with date): Citrix security bulletin (03 Oct 2026); CISA KEV (04 Oct 2026). - Helpdesk software holds citizen data and is rarely on the patch calendar. Zammad CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4, catalogued 2 October 2026 with a 5 October federal date. Chained, session fixation gives code execution as the zammad service account and improper privilege management escalates to root. The Dutch Institute for Vulnerability Disclosure states its own systems were reached on 21 September 2026 and characterises the intrusion as driven by an agentic AI system executing each step automatically. Reported version scope varies between sources, with upgrade to version 7 the recommendation carried in that reporting, so take the affected range from the vendor rather than a summary. Government service desks and grievance-redressal portals run exactly this class of software. Source (with date): CISA KEV (02 Oct 2026); SecurityWeek (01 Oct 2026). - A shared whole-of-government platform, breached through a known medium-severity flaw. Japan's Digital Agency disclosed that roughly 246,000 record rows of government personnel data were exposed after attackers exploited a known, medium-severity VPN device vulnerability attached to the shared platform used across its ministries. India is not a victim and nothing is reproduced here. It earns its place because the architecture is ours too: on a platform shared by every department, a medium-severity rating on one appliance is not a medium-severity exposure, and severity scores should not be the thing that sets the patch queue. Source (with date): Japan Digital Agency disclosure (11 Sep 2026); TechNadu (14 Sep 2026).

4. Regulatory & compliance watch

- CERT-In's clock read against this month's catalogue. The May 2026 AI-exploitation guidance CISG-2026-02 sets an indicative expectation of 12 hours to remediate known exploited vulnerabilities on internet-exposed systems, 24 hours for critical externally exposed flaws not yet exploited, three days for critical internal high-value systems and five days for high-severity issues. This is guidance with indicative timelines, not a binding mandate, and should not be briefed as one. The binding instrument remains the directions of 28 April 2022: initial intimation within six hours, 180-day log retention within Indian jurisdiction, and clock synchronisation to NPL. A department carrying the Cisco, Fortinet, Check Point, VeloCloud or F5 entries into the second week of October is well outside that window. Source (with date): CERT-In CISG-2026-02 (May 2026); CERT-In directions (28 Apr 2022). - DPDP: one date is settled, the other is a proposal. The DPDP Rules were notified on 13 November 2025. Rule 4 applies from 13 November 2026, when registration with the Data Protection Board becomes mandatory for anyone operating as a Consent Manager in India. Separately, MeitY has proposed compressing the Significant Data Fiduciary runway from eighteen months to twelve, which would pull those obligations, including an India-based Data Protection Officer, impact assessments for high-risk processing and third-party audits, forward to 13 November 2026. That compression is a proposal discussed with stakeholders, not notified law; the baseline date for the substantive obligations remains 13 May 2027. Departments and PSUs processing citizen data are data fiduciaries, so plan against both and do not brief the proposal as settled. Source (with date): MeitY DPDP Rules (13 Nov 2025). - NCIIPC runs a second clock in parallel. NCIIPC sits under NTRO with its mandate from section 70A of the IT Act 2000 as amended in 2008, and the Central Government notifies a computer resource as a protected system under section 70(1). Each notified system needs a named system owner, a CISO and a defined nodal officer for NCIIPC coordination. Where a department operates one, NCIIPC reporting runs alongside CERT-In's six-hour path and both clocks start together, which is the detail that fails during an out-of-hours incident. Source (with date): NCIIPC guidelines; IT Act 2000 section 70A, as amended 2008.

5. Actor in focus — APT36 (Transparent Tribe), Operation RapidRust

Zscaler ThreatLabz published this on 16 September 2026. The Pakistan-nexus actor APT36 ran a campaign through August 2026 against government and defence organisations in India and Afghanistan, with most post-compromise activity between 20 August and 1 September 2026. Delivery used typosquatted domains impersonating Indian news outlets, hosting malicious PowerShell. RUSTYSHADE is a 64-bit Windows backdoor written in Rust whose command and control runs through attacker-controlled private GitHub repositories over the GitHub REST API, with AES-256-GCM encryption keyed from the SHA-256 hash of the GitHub personal access token; it handles screenshots, webcam access, file transfer and command execution. RUSTYMOVE watches for removable media and propagates. PSNATCH on Windows and BASHNATCH on Linux collect documents and archives modified within the last 120 days and exfiltrate to GitHub. Payloads were staged through Backblaze cloud storage, and command and control ran only on weekdays, roughly 04:00 to 11:00 UTC.

Three details should change a defender's configuration. GitHub REST API traffic and commercial cloud-storage downloads are allow-listed on most government networks, so this channel resembles developer activity rather than exfiltration. The removable-media component means an air gap is a control to be monitored, not a boundary to be assumed. The 120-day filter shows collection aimed at current working documents. APT36 and the aligned SideCopy cluster remain the standing espionage pressure on Indian government and defence networks, with spear-phishing delivering weaponised LNK, HTA, PPAM and ELF files; keep those detections live irrespective of this campaign.

Source (with date): Zscaler ThreatLabz (16 Sep 2026); Seqrite (2026).

6. IOC pack

Every entry below is already public in the named source and is reproduced with attribution. These are not Nirad observations. The table mixes atomic indicators with behavioural leads; the Type column says which, and the leads need tuning against your own baseline.

IndicatorTypeContextSource
theprints[.]org, indiatodays[.]org, officialinfo[.]orgDomainsAPT36 delivery, impersonating Indian news outletsZscaler ThreatLabz
C:\Users\Public\Documents\DriverInstaller.zipFile pathRapidRust stagingZscaler ThreatLabz
StandAloneOneDriveUpdater-2626Scheduled taskRapidRust persistenceZscaler ThreatLabz
GitHub REST API calls to private repositories from non-developer hostsDetection leadRUSTYSHADE command and controlZscaler ThreatLabz
Backblaze downloads followed by PowerShell executionDetection leadRapidRust payload stagingZscaler ThreatLabz
Process creation shortly after removable-media insertionDetection leadRUSTYMOVE propagationZscaler ThreatLabz
POST requests to /j_security_check, usernames beginning viptela-reserved-Log patternCisco Catalyst SD-WAN Manager exploitationCISA KEV; The Hacker News
Certificate-based Mobile Access logins with unusual certificate subjectsDetection leadCheck Point CVE-2026-85102 exploitationCheck Point
CVE-2026-76504CVECisco Catalyst SD-WAN Manager bypass, exploitedCISA KEV
CVE-2026-104286CVEFortiMail unauthenticated file write, exploitedCISA KEV
CVE-2026-85102, CVE-2026-93616CVECheck Point gateway and management flaws, exploitedCISA KEV
CVE-2026-93952CVEArista VeloCloud Orchestrator, exploitedArista; CISA KEV
CVE-2026-94127CVEF5 BIG-IP APM, exploitedF5; CISA KEV
CVE-2026-88779CVECitrix NetScaler SAML memory overflow, exploitedCitrix; CISA KEV
CVE-2026-102489, CVE-2026-102490CVEZammad chain to root, exploitedCISA KEV

7. Tiered actions

Board. Ask for one page listing which systems administer other systems and who patches each: the SD-WAN manager, the firewall management server, the mail gateway, the remote-access appliance, the helpdesk platform. Ask who owns the department's dependency on the State Data Centre and what the tested restore path is if it is unavailable for a week. Ask which departmental websites run on commercial hosting and who monitors them. Confirm the six-hour CERT-In path has been exercised out of hours and that NCIIPC reporting runs in parallel for any notified protected system. Ask for a DPDP position separating the settled 13 November 2026 Consent Manager date from MeitY's proposed compression.

CISO. Emergency-patch Cisco Catalyst SD-WAN Manager, Check Point gateway and management, Arista VeloCloud Orchestrator, F5 BIG-IP APM, Citrix NetScaler and the helpdesk estate. On FortiMail apply the mitigations now and plan branch migration where no fixed build exists. Make compromise assessment, not patch completion, the closure criterion on every internet-facing system in that list: rotate credentials, tokens and certificates, and look for administrative accounts and scheduled jobs created before the fix. Audit the F5 estate by configuration rather than version. Bring departmental sites on third-party hosting under managed hosting with logging. On defence estates, block sideloaded packages, enforce device enrolment, and monitor removable-media use on isolated networks instead of treating the air gap as sufficient.

SOC. Hunt the section 6 indicators. On the perimeter, alert on POST requests to /j_security_check with reserved-prefix usernames, on certificate-based Mobile Access logins with unexpected subjects, on file writes outside expected paths on FortiMail, and on unexplained NetScaler restarts. Inside the estate, alert on GitHub REST API traffic to private repositories from hosts with no development function, on cloud-storage downloads followed closely by PowerShell, on process creation after USB insertion, and on new administrative accounts or tokens on any management platform. Baseline administrative logins to the SD-WAN manager and orchestrator now rather than during an incident. Keep the APT36 and SideCopy lure and loader detections active.

8. Source index

Arista · BleepingComputer · CERT-In (CISG-2026-02 and directions of 28 Apr 2022) · Check Point · CISA Known Exploited Vulnerabilities catalogue · Cisco · Citrix · Dutch Institute for Vulnerability Disclosure · F5 · Fortinet PSIRT · Help Net Security · Japan Digital Agency · MeitY (DPDP Rules) · NCIIPC · Organiser · SecurityWeek · Seqrite · TechNadu · The Hacker News · The Print · The Statesman · UNI India · Zscaler ThreatLabz

9. Byline

1

Nirad Threat Research

NBTF — Government & Defence Sector Edition | 7 October 2026