Nirad Threat Research
NBTF — Government & Defence Sector Edition | 7 October 2026
September pushed the exposure up a layer. CISA catalogued Check Point, Arista VeloCloud and F5 entries on 22 September, a Cisco Catalyst SD-WAN Manager authentication bypass on 30 September, Fortinet FortiMail on 1 October and a Citrix NetScaler flaw on 4 October. All of these products administer or front other systems, so a successful request buys policy control, mail flow or remote access across a department. For scale on the Indian backdrop, Seqrite's India Cyber Threat Report 2026 recorded 265.52 million detections across its own India telemetry for October 2024 to September 2025, with trojans at 88.4 million and file infectors at 71.1 million. That is Seqrite's telemetry, cited as theirs.
Source (with date): Seqrite India Cyber Threat Report 2026; CISA KEV (22 Sep, 30 Sep, 01 Oct and 04 Oct 2026).
Cisco Catalyst SD-WAN Manager authentication bypass, CVE-2026-76504 (CVSS 9.8). Improper handling of hex and URI encoding lets an unauthenticated attacker send a crafted HTTP request to the API and obtain administrator access to vManage. Catalogued 30 September 2026 with a 3 October federal date, the eighth Cisco SD-WAN flaw added during 2026.Exposed:departments and PSUs using Catalyst SD-WAN for district and field connectivity, where the manager holds every branch configuration.Action:patch, then review service proxy and vManage logs for POST requests to /j_security_check, especially with usernames beginning viptela-reserved-.
Source (with date): CISA KEV (30 Sep 2026); The Hacker News (01 Oct 2026).
Fortinet FortiMail unauthenticated file write, CVE-2026-104286 (CVSS 9.8). Path traversal combined with improper handling of a NULL byte, allowing arbitrary file writes through crafted HTTP or HTTPS requests. Fortinet confirmed exploitation without stating when attacks began. Affected: 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9. Fixes are 8.0.2, 7.6.7 and 7.4.9, unreleased when this was reported, so mitigations are the control for now: disable identity-based encryption and take the management interface off the internet. The 7.2 branch has no listed fixed build, which makes migration the real remediation there.
Source (with date): Fortinet PSIRT; CISA KEV (01 Oct 2026); Help Net Security (02 Oct 2026).
Check Point pre-authentication code execution and management traversal, CVE-2026-85102 and CVE-2026-93616 (both CVSS 9.8). The first is improper certificate validation during VPN negotiation on Security Gateway and Spark firewalls: a crafted certificate presented before authentication completes gives code execution without credentials, and Check Point states exploitation began 12 September 2026 against Spark customers globally. The second is a pre-authentication path traversal in the Security Management web service allowing a script to be uploaded and run on the management server, with pinpointed attacks detected 23 July 2026.Action:patch both, then review logs for unusual certificate-based Mobile Access logins and for uploads to the management server.
Source (with date): Check Point advisory (22 Sep 2026); CISA KEV (22 Sep 2026).
A State Data Centre carried malware for five days. Reporting on the West Bengal State Data Centre states malware was active on the main server from 9 to 13 September 2026. Websites of several departments, including Public Works, Housing, Municipal Affairs and Urban Development, and the State Police, went down, with backend operations blocked for some. Forensic examiners were reported to fear that documents from four departments including Finance had been taken and destroyed. Treat the loss as reported and feared rather than established; the investigation was continuing and the main server had not returned to normal. The structural point: a State Data Centre is shared tenancy for dozens of departments, so one intrusion is a multi-department outage, and recovery rests on restore paths nobody rehearsed.
Source (with date): UNI India (22 Sep 2026); The Statesman (Sep 2026).
A departmental portal defaced on someone else's hosting account. The Kerala General Administration Department website was defaced on 27 September 2026, with a claim of responsibility by a group calling itself Team Blackleets, described in reporting as suspected Pakistan-based. That claim is the claimant's, not an attribution. The hosting provider suspended the account, officials said a cyber team was checking for any data breach, and the portal was still unavailable on 30 September 2026. Defacement is unsophisticated; the control gap is not. A departmental site on a commercial shared-hosting account sits outside the department's own monitoring, patching and incident-response path.
Source (with date): The Print (27 Sep 2026); Organiser (30 Sep 2026).
- The SD-WAN and access control planes, twice over. Arista VeloCloud Orchestrator CVE-2026-93952, improper input validation rated CVSS 10.0 and confirmed exploited, announced 22 September 2026 and catalogued the same day with a 25 September federal date. An attacker needs network access to the on-premises orchestrator web interface and the public portion of the VeloCloud Edge authentication certificate, but no tenant or operator credentials. Affected builds are 6.1.3.7 and below and 7.0.0.2 and below, with fixes in 5.2.3.16 and 6.4.2.8; confirm your branch has a build to move to. Alongside it, F5 BIG-IP APM CVE-2026-94127 is a heap-based buffer overflow rated CVSS 9.8 giving unauthenticated remote code execution, published 22 September 2026 with exploitation confirmed. It is not reachable in a default build: the virtual server must carry both an APM access policy and an OAuth profile, which makes this a configuration audit rather than a version check. Source (with date): CISA KEV (22 Sep 2026); BleepingComputer (23 Sep 2026). - Citrix NetScaler CVE-2026-88779, where the patch did not end the matter. A memory overflow in NetScaler ADC and Gateway rated CVSS 8.7, reachable where a customer-managed appliance is configured as a SAML service provider or identity provider. Citrix published the bulletin and fixed builds on 3 October 2026 after targeted exploitation had been observed, and CISA catalogued it on 4 October with a 7 October date. Documented impact is denial of service and repeated restart, and administrators reported crashes on appliances patched days earlier for the August and September NetScaler flaws. There is no broadly documented public proof of reliable remote code execution, so do not escalate it to that in a board paper. In government estates SAML is the single sign-on path into departmental portals, so an outage here is an authentication outage. Source (with date): Citrix security bulletin (03 Oct 2026); CISA KEV (04 Oct 2026). - Helpdesk software holds citizen data and is rarely on the patch calendar. Zammad CVE-2026-102489 and CVE-2026-102490, both rated CVSS 9.4, catalogued 2 October 2026 with a 5 October federal date. Chained, session fixation gives code execution as the zammad service account and improper privilege management escalates to root. The Dutch Institute for Vulnerability Disclosure states its own systems were reached on 21 September 2026 and characterises the intrusion as driven by an agentic AI system executing each step automatically. Reported version scope varies between sources, with upgrade to version 7 the recommendation carried in that reporting, so take the affected range from the vendor rather than a summary. Government service desks and grievance-redressal portals run exactly this class of software. Source (with date): CISA KEV (02 Oct 2026); SecurityWeek (01 Oct 2026). - A shared whole-of-government platform, breached through a known medium-severity flaw. Japan's Digital Agency disclosed that roughly 246,000 record rows of government personnel data were exposed after attackers exploited a known, medium-severity VPN device vulnerability attached to the shared platform used across its ministries. India is not a victim and nothing is reproduced here. It earns its place because the architecture is ours too: on a platform shared by every department, a medium-severity rating on one appliance is not a medium-severity exposure, and severity scores should not be the thing that sets the patch queue. Source (with date): Japan Digital Agency disclosure (11 Sep 2026); TechNadu (14 Sep 2026).
- CERT-In's clock read against this month's catalogue. The May 2026 AI-exploitation guidance CISG-2026-02 sets an indicative expectation of 12 hours to remediate known exploited vulnerabilities on internet-exposed systems, 24 hours for critical externally exposed flaws not yet exploited, three days for critical internal high-value systems and five days for high-severity issues. This is guidance with indicative timelines, not a binding mandate, and should not be briefed as one. The binding instrument remains the directions of 28 April 2022: initial intimation within six hours, 180-day log retention within Indian jurisdiction, and clock synchronisation to NPL. A department carrying the Cisco, Fortinet, Check Point, VeloCloud or F5 entries into the second week of October is well outside that window. Source (with date): CERT-In CISG-2026-02 (May 2026); CERT-In directions (28 Apr 2022). - DPDP: one date is settled, the other is a proposal. The DPDP Rules were notified on 13 November 2025. Rule 4 applies from 13 November 2026, when registration with the Data Protection Board becomes mandatory for anyone operating as a Consent Manager in India. Separately, MeitY has proposed compressing the Significant Data Fiduciary runway from eighteen months to twelve, which would pull those obligations, including an India-based Data Protection Officer, impact assessments for high-risk processing and third-party audits, forward to 13 November 2026. That compression is a proposal discussed with stakeholders, not notified law; the baseline date for the substantive obligations remains 13 May 2027. Departments and PSUs processing citizen data are data fiduciaries, so plan against both and do not brief the proposal as settled. Source (with date): MeitY DPDP Rules (13 Nov 2025). - NCIIPC runs a second clock in parallel. NCIIPC sits under NTRO with its mandate from section 70A of the IT Act 2000 as amended in 2008, and the Central Government notifies a computer resource as a protected system under section 70(1). Each notified system needs a named system owner, a CISO and a defined nodal officer for NCIIPC coordination. Where a department operates one, NCIIPC reporting runs alongside CERT-In's six-hour path and both clocks start together, which is the detail that fails during an out-of-hours incident. Source (with date): NCIIPC guidelines; IT Act 2000 section 70A, as amended 2008.
Zscaler ThreatLabz published this on 16 September 2026. The Pakistan-nexus actor APT36 ran a campaign through August 2026 against government and defence organisations in India and Afghanistan, with most post-compromise activity between 20 August and 1 September 2026. Delivery used typosquatted domains impersonating Indian news outlets, hosting malicious PowerShell. RUSTYSHADE is a 64-bit Windows backdoor written in Rust whose command and control runs through attacker-controlled private GitHub repositories over the GitHub REST API, with AES-256-GCM encryption keyed from the SHA-256 hash of the GitHub personal access token; it handles screenshots, webcam access, file transfer and command execution. RUSTYMOVE watches for removable media and propagates. PSNATCH on Windows and BASHNATCH on Linux collect documents and archives modified within the last 120 days and exfiltrate to GitHub. Payloads were staged through Backblaze cloud storage, and command and control ran only on weekdays, roughly 04:00 to 11:00 UTC.
Three details should change a defender's configuration. GitHub REST API traffic and commercial cloud-storage downloads are allow-listed on most government networks, so this channel resembles developer activity rather than exfiltration. The removable-media component means an air gap is a control to be monitored, not a boundary to be assumed. The 120-day filter shows collection aimed at current working documents. APT36 and the aligned SideCopy cluster remain the standing espionage pressure on Indian government and defence networks, with spear-phishing delivering weaponised LNK, HTA, PPAM and ELF files; keep those detections live irrespective of this campaign.
Source (with date): Zscaler ThreatLabz (16 Sep 2026); Seqrite (2026).
Every entry below is already public in the named source and is reproduced with attribution. These are not Nirad observations. The table mixes atomic indicators with behavioural leads; the Type column says which, and the leads need tuning against your own baseline.
| Indicator | Type | Context | Source |
|---|---|---|---|
theprints[.]org, indiatodays[.]org, officialinfo[.]org | Domains | APT36 delivery, impersonating Indian news outlets | Zscaler ThreatLabz |
C:\Users\Public\Documents\DriverInstaller.zip | File path | RapidRust staging | Zscaler ThreatLabz |
StandAloneOneDriveUpdater-2626 | Scheduled task | RapidRust persistence | Zscaler ThreatLabz |
| GitHub REST API calls to private repositories from non-developer hosts | Detection lead | RUSTYSHADE command and control | Zscaler ThreatLabz |
| Backblaze downloads followed by PowerShell execution | Detection lead | RapidRust payload staging | Zscaler ThreatLabz |
| Process creation shortly after removable-media insertion | Detection lead | RUSTYMOVE propagation | Zscaler ThreatLabz |
POST requests to /j_security_check, usernames beginning viptela-reserved- | Log pattern | Cisco Catalyst SD-WAN Manager exploitation | CISA KEV; The Hacker News |
| Certificate-based Mobile Access logins with unusual certificate subjects | Detection lead | Check Point CVE-2026-85102 exploitation | Check Point |
CVE-2026-76504 | CVE | Cisco Catalyst SD-WAN Manager bypass, exploited | CISA KEV |
CVE-2026-104286 | CVE | FortiMail unauthenticated file write, exploited | CISA KEV |
CVE-2026-85102, CVE-2026-93616 | CVE | Check Point gateway and management flaws, exploited | CISA KEV |
CVE-2026-93952 | CVE | Arista VeloCloud Orchestrator, exploited | Arista; CISA KEV |
CVE-2026-94127 | CVE | F5 BIG-IP APM, exploited | F5; CISA KEV |
CVE-2026-88779 | CVE | Citrix NetScaler SAML memory overflow, exploited | Citrix; CISA KEV |
CVE-2026-102489, CVE-2026-102490 | CVE | Zammad chain to root, exploited | CISA KEV |
Board. Ask for one page listing which systems administer other systems and who patches each: the SD-WAN manager, the firewall management server, the mail gateway, the remote-access appliance, the helpdesk platform. Ask who owns the department's dependency on the State Data Centre and what the tested restore path is if it is unavailable for a week. Ask which departmental websites run on commercial hosting and who monitors them. Confirm the six-hour CERT-In path has been exercised out of hours and that NCIIPC reporting runs in parallel for any notified protected system. Ask for a DPDP position separating the settled 13 November 2026 Consent Manager date from MeitY's proposed compression.
CISO. Emergency-patch Cisco Catalyst SD-WAN Manager, Check Point gateway and management, Arista VeloCloud Orchestrator, F5 BIG-IP APM, Citrix NetScaler and the helpdesk estate. On FortiMail apply the mitigations now and plan branch migration where no fixed build exists. Make compromise assessment, not patch completion, the closure criterion on every internet-facing system in that list: rotate credentials, tokens and certificates, and look for administrative accounts and scheduled jobs created before the fix. Audit the F5 estate by configuration rather than version. Bring departmental sites on third-party hosting under managed hosting with logging. On defence estates, block sideloaded packages, enforce device enrolment, and monitor removable-media use on isolated networks instead of treating the air gap as sufficient.
SOC. Hunt the section 6 indicators. On the perimeter, alert on POST requests to /j_security_check with reserved-prefix usernames, on certificate-based Mobile Access logins with unexpected subjects, on file writes outside expected paths on FortiMail, and on unexplained NetScaler restarts. Inside the estate, alert on GitHub REST API traffic to private repositories from hosts with no development function, on cloud-storage downloads followed closely by PowerShell, on process creation after USB insertion, and on new administrative accounts or tokens on any management platform. Baseline administrative logins to the SD-WAN manager and orchestrator now rather than during an incident. Keep the APT36 and SideCopy lure and loader detections active.
Arista · BleepingComputer · CERT-In (CISG-2026-02 and directions of 28 Apr 2022) · Check Point · CISA Known Exploited Vulnerabilities catalogue · Cisco · Citrix · Dutch Institute for Vulnerability Disclosure · F5 · Fortinet PSIRT · Help Net Security · Japan Digital Agency · MeitY (DPDP Rules) · NCIIPC · Organiser · SecurityWeek · Seqrite · TechNadu · The Hacker News · The Print · The Statesman · UNI India · Zscaler ThreatLabz
NBTF — Government & Defence Sector Edition | 7 October 2026