Bharat Threat FeedGlobal threats, decoded for Indian defenders
Government & Defence Sector Edition · September 2026

Government & Defence Sector Edition — September 2026

This month's government and defence exposure did not come from new malware. It came from the administrative machinery departments rarely count as security assets: the print server in the records room, the VPN appliance at the gateway, the virtualisation console in the data centre, the build repository the software vendor runs, and the remote-management platform the outsourced IT provider uses. Four of those were confirmed under exploitation in August, and a case in the Philippines showed what happens when a strategic research body leaves internet-facing software unpatched for two years.

1. Sector snapshot

The pattern across August 2026 is administrative planes reachable from places they should not be. Print and output management, edge VPN gateways, virtualisation management, MSP remote-management platforms and artefact repositories all saw confirmed exploitation, and in three cases exploitation preceded or outpaced the vendor fix. Against that, CERT-In spent June and July running ten customised exercises themed "Building Resilience against Frontier AI-driven Cyber Threats", drawing 1,470 participants from 345 government and private-sector organisations across power, telecom, BFSI, transport, education, healthcare and space. The gap this edition is concerned with sits between that exercise capability and the ordinary patch record on assets nobody in the security team owns.

Source (with date): MeitY and CERT-In, as reported by ANI (30 Jul 2026).

2. Threats targeting government & defence

PaperCut NG/MF: two flaws chained into unauthenticated code execution, exploited before the fix. CVE-2026-81578, an improper access control flaw in the web management interface, lets an unauthenticated attacker change configuration values that should require an administrator login. Chained with CVE-2026-82078, an unsafe dynamic class-loading flaw rated CVSS 9.4, it becomes arbitrary Java bytecode execution on the Application Server with no credentials and no user interaction. PaperCut published an urgent advisory on 27 August 2026 and confirmed customer incidents; the work came from Huntress, watchTowr and a university customer's security team. All NG and MF versions are affected. The first emergency patch was bypassed within about 48 hours and superseded by Emergency Patch Release 2, so take the current release from the vendor advisory rather than assuming the first fix held. Interim mitigation is restricting Application Server web access to trusted addresses. In Indian departments and PSUs this software usually sits with facilities or IT operations rather than security, which is why it is off the patch calendar.

Source (with date): PaperCut urgent advisory; Help Net Security (27 Aug 2026); CISA KEV (31 Aug 2026).

A strategic research body and a naval supplier, reached through flaws patched over two years ago. Hunt.io reported finding an exposed staging server holding attack scripts, logs written in Simplified Chinese, and data taken from two Philippine organisations. A nuclear research body was reached through CVE-2023-49105, an ownCloud WebDAV authentication bypass rated CVSS 9.8, disclosed in November 2023 and fixed in 10.13.1; the attacker abused pre-signed URLs with empty signing secrets to retrieve files without credentials. Roughly 176 files relating to nuclear research operations were taken, which we are not itemising. A second victim was a marine engineering firm supporting the Philippine Navy, reached through CVE-2024-28000, a LiteSpeed Cache WordPress plugin flaw allowing unauthenticated creation of an administrator account. Hunt.io stopped short of naming a state group, noting that language artefacts are among the easiest indicators to plant. India is not a victim here. It belongs in an Indian advisory because of the target shape: a defence-adjacent research institute and a naval supply-chain firm, both running internet-facing software years behind its fix, is a profile that exists across Indian strategic research and shipyard supplier estates.

Source (with date): Hunt.io; The Hacker News (28 Aug 2026); Security Affairs (29 Aug 2026).

VMware vCenter turned into root, then ransomware on the ESXi hosts underneath. CVE-2026-59310 is a directory traversal in the vCenter Syslog service rated CVSS 9.8, disclosed by Broadcom on 29 July 2026 with no workaround. QUIRSO assesses with moderate confidence that the campaign is run by a Chinese-speaking actor working in the UTC+08:00 time zone, based on language artefacts, tooling, working hours and a victimology excluding mainland China; no named group is claimed. Exploitation gave immediate root-context code execution. The actor wrote malformed files into /etc/cron.d, staged tooling through scheduled jobs, dropped reverse SSH binaries for persistence, and in at least one case deployed Babuk-derived ransomware on ESXi hosts, renaming partially encrypted files with a .babyk extension — read as partly a smokescreen, since encrypting ESXi logs removes the telemetry a defender needs. QUIRSO mapped 361 affected IP addresses across 47 countries, 343 of them by 5 August 2026, with technology, research, education and telecommunications environments among those exposed. One appliance was also hit through CVE-2026-59309, an authentication bypass. CISA listed the traversal flaw on 18 August 2026. vCenter 6.x and 7.x are past end of general support, and patching is not closure here; an exposed appliance needs a compromise assessment.

Source (with date): QUIRSO; The Hacker News (17 Aug 2026); CISA KEV (18 Aug 2026).

The standing Pakistan-nexus baseline has not moved. APT36 (Transparent Tribe) and the aligned SideCopy cluster remain the continuous espionage pressure on Indian government and defence networks, with cross-platform Windows and Linux RAT activity reported this year, including GETA RAT, ARES RAT and Desk RAT, and earlier CYFIRMA work on weaponised .desktop autostart files aimed at BOSS Linux desktops. Keep those detections live regardless of what else is in this issue.

Source (with date): Aryaka; The Hacker News (Feb 2026); CYFIRMA.

Insider risk, with a device-install element. Delhi Police and Air Force intelligence arrested an Indian Air Force officer on 31 May 2026 over alleged leakage of sensitive material to a suspected Pakistani handler contacted through social media. Reporting states the officer was also asked to install an application on a colleague's phone, treated by investigators as a suspected attempt to plant remote-access spyware. The officer has been booked under the Official Secrets Act and the extent of any compromise was still being assessed at the time of reporting. No individual is named here and nothing beyond the reported allegations should be assumed. The control point is narrow: on a defence estate, sideload blocking, device enrolment and alerting on peer-initiated installs are counter-espionage controls, not only device hygiene.

Source (with date): The Week (08 Aug 2026).

3. Sector tech & exposures

Citrix NetScaler ADC and Gateway, CVE-2026-8452. Citrix described this in June 2026 as a memory overflow capable of denial of service. watchTowr Labs published analysis and proof-of-concept code on 14 August 2026 showing it reaches unauthenticated remote code execution, and CISA listed it on 26 August 2026 with a 29 August federal remediation date. Observed activity includes web shells named x.php and z.php alongside discovery commands. It affects appliances configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA virtual servers; take the fixed builds from the Citrix bulletin rather than secondary reporting. Second NetScaler item in two editions, same pattern: a memory-safety bug scoped down at disclosure, then reopened by outside research.

Source (with date): watchTowr Labs; Help Net Security (27 Aug 2026); CISA KEV (26 Aug 2026).

Cisco Secure Firewall ASA and FTD, CVE-2026-20349. CVSS 8.6. A single crafted HTTP request crashes and reloads the Remote Access SSL VPN service, an unauthenticated denial of service against the remote-access path itself. Cisco confirmed active exploitation on 11 August 2026 and CISA listed it the same day with a 14 August federal deadline. No public actor attribution, and it should not be conflated with the earlier ArcaneDoor espionage activity on the same product line.

Source (with date): Cisco; CISA KEV (11 Aug 2026).

N-able N-central, CVE-2026-18577. Authentication bypass and account takeover rated CVSS 8.2, an incomplete fix for CVE-2026-18556, affecting builds before 2026.3.1.7 across on-premises and cloud-hosted deployments. It surfaced on 31 July 2026 when N-able's own managed detection service found zero-day exploitation in a customer environment. Attackers then used the platform's Take Control feature to reach managed endpoints and installed Cloudflare Tunnel for persistence that survived revocation of N-central access. CISA listed it on 3 August 2026; a second hotfix followed on 6 August. Where a department's endpoint estate is run by an outsourced provider, that provider's management platform is part of the department's attack surface whether or not it appears on the asset register.

Source (with date): N-able; Rapid7; CISA KEV (03 Aug 2026).

JFrog Artifactory, CVE-2026-82329. Authentication bypass rated CVSS 9.8; in the default configuration an unauthenticated attacker with network access can obtain administrative privileges, which watchTowr traces to instances without an additional join key receiving a usable placeholder key. JFrog patched on 28 August 2026 across branches 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38 and 7.161.20. watchTowr reported observed exploitation on 1 September 2026: token minting, enumeration of users, groups and credentials, and in a small number of cases creation of backdoor accounts. Not yet on the KEV list at the time of that reporting. An artefact repository sits in the middle of a delivery pipeline, so for e-governance and defence software this is a supply-chain exposure, not a routine server patch.

Source (with date): JFrog; watchTowr; The Hacker News (01 Sep 2026).

SonicWall Global Management System. CVE-2026-66147, an unauthenticated command injection in the GMS Dispatcher Service rated CVSS 9.4, and CVE-2026-66145, rated 9.1, allowing an unauthenticated attacker to read sensitive data and write arbitrary files via zipslip. Both affect GMS 9.5.1 and earlier on the Virtual Appliance and Windows, fixed in 9.5.2, and the same advisory carries four further flaws. GMS was decommissioned in October 2025, which is precisely why lingering deployments deserve a check: a firewall fleet management server is a policy-rewrite position across every appliance it manages.

Source (with date): SonicWall PSIRT SNWLID-2026-0011; Center for Internet Security advisory 2026-083 (12 Aug 2026).

The identity plane, and a correction worth carrying. Microsoft's 20 August 2026 service update batch included CVE-2026-59115, a path-traversal elevation of privilege in the Entra Provisioning Service, and CVE-2026-50481 in Azure Active Directory, both rated CVSS 9.9. Separately, CVE-2026-69836, a deserialization remote code execution flaw in Entra ID rated CVSS 10.0, was first published with its "Exploited" field set to Yes; Microsoft corrected that to No on 21 August 2026, and as a managed service the fix was applied on Microsoft's own infrastructure with nothing for customers to install. Several outlets still carry the original framing, so a board paper citing an exploited CVSS 10.0 Entra flaw needs correcting.

Source (with date): Microsoft MSRC; Help Net Security (21 Aug 2026); SecurityWeek (24 Aug 2026).

4. Regulatory & compliance watch

CERT-In's patch expectation read against this month's list. The May 2026 AI-exploitation guidance, CISG-2026-02, sets an indicative expectation of 12 hours to contain or remediate known exploited vulnerabilities on internet-facing systems, one day for critical externally exposed flaws and five days for high-severity issues on a risk basis. It is guidance with indicative timelines, not a binding mandate, and it sits alongside the April 2022 directions requiring incident reporting within six hours, 180-day log retention within Indian jurisdiction and clock synchronisation to NPL. Read against sections 2 and 3, an internet-facing PaperCut server or a pre-fix NetScaler carried into September is well outside that window. Where systems are notified as protected systems under section 70A of the IT Act, NCIIPC's directions run in parallel with CERT-In's, and both clocks start together.

Source (with date): CERT-In; The Hacker News (26 May 2026).

MeitY's state cybersecurity framework process. MeitY is running a four-stage departmental summit process to build a national cybersecurity framework architecture covering all 36 states and union territories, following directions from the Prime Minister at the fifth National Conference of Chief Secretaries. The second stage was a national consultative workshop in New Delhi on 11 May 2026, after which states and union territories were asked to hold internal workshops and submit structured recommendations by 30 June 2026, with a National Departmental Summit scheduled for August 2026 to discuss the final framework. State IT and home departments should confirm where their own submission landed, because this process will set their baseline. The institutional split remains MeitY on IT Act matters, the Ministry of Home Affairs on cyber-crime, the National Security Council Secretariat on coordination, CERT-In as the section 70B incident agency and NCIIPC under NTRO for critical information infrastructure.

Source (with date): MeitY, as reported by Indian Television (17 May 2026).

A useful external benchmark: CISA's BOD 26-04. Issued on 10 June 2026, it supersedes and revokes BOD 19-02 and BOD 22-01, drops CVSS as the prioritisation basis, and requires a three-day fix where a flaw is publicly exposed, listed as known exploited, automatable and technically impactful. It also requires forensic triage to establish whether the affected system was already compromised, rather than treating a patch as the end of the matter. It binds United States federal civilian agencies only and has no force in India, but the structure is worth borrowing: exposure and exploitation status driving the clock, with compromise assessment written into the remediation step.

Source (with date): CISA (10 Jun 2026).

5. Actor in focus — UAT-10147

Cisco Talos published its analysis of UAT-10147 on 20 August 2026: a previously undocumented Chinese-speaking intrusion set, assessed as financially motivated rather than state-directed, active since early 2026 against vulnerable Windows and Linux web servers worldwide. Talos names government and education among the affected sectors, and Brazil, Bolivia, China, Canada and Vietnam among victim countries. India is not named in that reporting, and this is not an India-targeting campaign. It appears here for the operating model, not the victim list.

An operational security lapse exposed the actor's staging server, revealing a target list of roughly 170,000 URLs alongside AI-generated operational documentation and automation scripts. Talos assesses with moderate-to-high confidence that the actor uses agentic AI systems to run offensive tradecraft at scale, threading AI-driven tooling through exploitation, reconnaissance, payload generation, validation and persistence alongside conventional open-source frameworks. Initial access is entirely through publicly disclosed vulnerabilities in long-lived software: CVE-2022-27925 in Zimbra, CVE-2019-18935 in Telerik UI for ASP.NET AJAX, CVE-2021-23758 in Ajax.NET Professional, and CVE-2021-29441 and CVE-2021-29442 in Alibaba Nacos, followed by Linux privilege escalation through flaws dating back as far as 2010. On Windows it modifies Defender exclusions and creates scheduled tasks disguised as "Google Chrome Start"; on Linux it plants web shells and then escalates. A follow-on Talos report covers SPECTRE, a cross-platform implant with process injection, credential theft, a Linux rootkit and driver-based EDR bypass. Exfiltration is routed through a legitimate cloud configuration management service so it resembles ordinary administrative traffic. On 26 August 2026 CISA added four of the legacy flaws this actor uses to its exploited list.

The exposure for Indian government and PSU estates is real even without named Indian targeting. Automated, AI-assisted scanning for years-old unpatched internet-facing software is precisely the shape of a departmental web estate still carrying legacy Zimbra, Telerik and .NET components, often on domains inherited from a project that ended years ago. As always in this feed, India-nexus actors are out of scope; the lens is foreign activity that creates exposure for Indian organisations.

Source (with date): Cisco Talos (20 Aug 2026); The Hacker News (Aug 2026); CISA KEV (26 Aug 2026).

6. IOC pack

Every entry below is already public in the named source and is reproduced with attribution. These are not Nirad observations. The table mixes atomic indicators with behavioural detection leads; the Type column says which is which, and the leads need tuning against your own baseline.

IndicatorTypeContextSource
x.php, z.phpWeb shell filenamesNetScaler CVE-2026-8452 exploitationwatchTowr Labs
adminapi.tippusoni[.]inDomainUAT-10147 infrastructureCisco Talos
cloudflared service, unexplainedPersistence artefactN-able N-central post-exploitationN-able
svchost.exe inside a user's Documents folderMasqueraded binaryN-able N-central post-exploitationN-able
.babyk extension on ESXi datastoresRansomware artefactvCenter CVE-2026-59310 campaignQUIRSO
Files written to /etc/cron.d on a vCenter applianceDetection leadvCenter CVE-2026-59310 persistenceQUIRSO
Google Chrome Start scheduled taskDetection leadUAT-10147 persistenceCisco Talos
Anomalous child processes of pc-app.exeDetection leadPaperCut exploitationHuntress
Missing, truncated or deleted server.logDetection lead (anti-forensics)PaperCut exploitationPaperCut
ERROR No suitable driver found for jdbc:no:xLog stringPaperCut exploitationHelp Net Security
Snort SIDs 66696, 66697Detection signatureUAT-10147 activityCisco Talos
SPECTRE, NoodleRAT, QuasarRAT, Gh0stCringeMalware familiesUAT-10147 toolingCisco Talos
CVE-2026-81578, CVE-2026-82078CVE referencePaperCut chain, exploitedCISA KEV
CVE-2026-8452CVE referenceNetScaler, exploitedCISA KEV
CVE-2026-20349CVE referenceCisco ASA/FTD VPN denial of service, exploitedCISA KEV
CVE-2026-18577CVE referenceN-able N-central authentication bypass, exploitedCISA KEV
CVE-2026-59310, CVE-2026-59309CVE referencevCenter traversal and authentication bypassCISA KEV; QUIRSO
CVE-2026-82329CVE referenceJFrog Artifactory authentication bypasswatchTowr Labs
CVE-2023-49105, CVE-2024-28000CVE referenceownCloud and LiteSpeed Cache, Philippine casesHunt.io

7. Tiered actions

Board. Ask for a written position on internet-facing exposure across four asset classes usually missing from the departmental register: print and output management, edge VPN appliances, virtualisation management, and build or artefact repositories. Ask whether the outsourced IT provider's remote-management platform sits inside the department's own risk register, and who patches it. Ask whether the six-hour CERT-In reporting path has been tested end to end, including out of hours, and whether NCIIPC reporting runs in parallel for any notified protected system. Where the department funds a research institute or a defence-adjacent supplier, ask what their patch position is on internet-facing software.

CISO. Patch on an emergency basis across PaperCut, NetScaler, vCenter, Cisco ASA and FTD, N-able N-central and Artifactory; on PaperCut take the current emergency release, not the first one. Treat an exploited vCenter or Artifactory as compromised until an assessment says otherwise: rotate credentials, tokens and keys rather than only applying the fix, and check for administrative accounts and scheduled jobs created before the patch. Restrict PaperCut and vCenter management interfaces to trusted networks. Inventory internet-facing legacy software across the department and its funded institutes, specifically ownCloud, Zimbra, Telerik and WordPress plugin estates, including domains inherited from closed projects. Require managed service providers to report their own patch state. At the device management layer, block sideloaded packages on issued devices and alert on peer-initiated installs.

SOC. Hunt the indicators in section 6. On the perimeter, alert on new .php files in NetScaler web paths and on unexpected reloads of the ASA remote-access VPN service. In the data centre, alert on new or modified files in /etc/cron.d on vCenter appliances and on reverse SSH sessions from appliance addresses, and baseline vCenter and ESXi administrative logins now rather than during an incident. Across the estate, alert on unexplained cloudflared services and outbound tunnels, on Defender exclusion changes, on PaperCut server log gaps, and on Artifactory administrative token creation and user enumeration. Keep the APT36 lure paths and .desktop autostart detections in the active set.

8. Source index

ANI · Aryaka · Center for Internet Security · CERT-In (CISG-2026-02) · CISA · CISA KEV · Cisco · Cisco Talos · Citrix · CYFIRMA · Help Net Security · Hunt.io · Huntress · Indian Television · JFrog · MeitY · Microsoft MSRC · N-able · PaperCut · QUIRSO · Rapid7 · Security Affairs · SecurityWeek · SonicWall PSIRT · The Hacker News · The Week · watchTowr Labs

9. Byline

1

Nirad Threat Research

NBTF — Government & Defence Sector Edition | 2 September 2026