
Who this is for
The Exchange is for public-sector technology leaders, acquisition teams, CISOs, and enterprise operators who sell to or deliver for city, state, and federal buyers. This week: an active VPN credential campaign that can lock administrators out, a GSA LLM acquisition clause contracting officers can use now, a FedRAMP High Claude path for agencies, California's human-in-the-loop rule for automated discipline and termination, and a White House-framed $2.4 billion tools-and-compute-credits push for the Genesis Mission.
Top 5 things this week
- Cyber: FortiBleed - FBI and U.S. Secret Service joint advisory JCSA-20261006-01 (October 6). Active credential campaign against internet-facing FortiGate SSL VPN; SOCRadar (as cited by FBI) reports more than 86,644 devices across 194 countries; lockouts when attackers change or delete accounts; initial-access brokers feeding ransomware affiliates including INC/Lynx and Payload. Not a CVE/KEV listing.
- Federal acquisition: GSA clause 552.239-7001 (LLM data safeguarding) as a GSAR class deviation. Effective October 19; contracting officers may use it now. Applies when LLM is a material feature and Government Data moves to or from the model.
- AI buy path: Anthropic Claude for Government generally available October 2 for federal and state agencies. FedRAMP High; no seat fees; prepaid not-to-exceed usage; SSO/SCIM; audit logs; direct contract with Anthropic. Claude Code CLI and Claude for Microsoft 365 in early access.
- State / SLTT: California SB 947 (Chapter 859), signed September 30, operative July 1, 2027. Employers cannot rely solely on an automated decision system for discipline or termination; human corroboration and written notice required; $500 civil penalty per violation.
- Federal SI compute: Genesis Mission Consortium receives $2.4 billion in tools and compute credits from eleven industry partners (White House fact sheet, October 8). NVIDIA $1B, AMD $500M, OpenAI $200M, Anthropic and Google $150M each, and others. Separately, universities, industry, and the State of Georgia are framed at $1 billion for scientific computing and workforce (credits/tools and institutional totals are not cash grants).
1. FortiBleed turns stolen FortiGate credentials into lockouts and ransomware access

On October 6, 2026, the FBI and U.S. Secret Service published joint advisory JCSA-20261006-01, "FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts," as TLP:CLEAR via the Internet Crime Complaint Center. It describes FortiBleed as an active, global credential-compromise campaign aimed at internet-facing Fortinet FortiGate firewalls and SSL VPN gateways.
Per the advisory, the campaign exploits reused or leaked credentials and legacy SHA-256 password storage, letting operators harvest and crack authentication data at scale. The authoring agencies cite SOCRadar's figure of more than 86,644 compromised devices across 194 countries; we have not independently census-counted exposed appliances.
The advisory details an initial-access-broker workflow: scan for exposed SSL VPN portals; stuff and spray credentials from prior Fortinet leak dumps and infostealer logs; dump hashes; crack them offline with GPU rigs (Hashcat/Hashtopolis); validate the cracked credentials; create new admin accounts for persistence; enumerate Active Directory and spray further; then package working VPN access for sale. Per the advisory, brokers using this chain have sold access to ransomware affiliates including INC/Lynx and Payload.
The operational sting is lockout. Intruders create new accounts, and in some cases delete existing ones or change passwords so legitimate administrators cannot log in during lateral movement. Remediation is more than "patch and move on": organizations may need account recovery, out-of-band management access, and a full configuration review before eviction can even begin.
This is not a CVE assignment and not a CISA KEV catalog entry. It is a credential-and-operations campaign warning with indicators of compromise, MITRE ATT&CK mapping, and concrete mitigations. Treat it as an exposure and identity problem on a high-volume remote-access surface, not a single-patch KEV clock.
A stolen VPN password that lets an attacker delete your admin account is an availability incident before it becomes a ransomware ticket."
Why it matters
Public-sector and enterprise networks still expose FortiGate SSL VPN for telework, partner access, and emergency operations. When attackers can authenticate, plant persistence accounts, and lock operators out, the incident jumps from credential hygiene to business continuity and, via initial-access brokers, to ransomware affiliates. The advisory names all 16 critical infrastructure sectors explicitly, with CISOs, vulnerability analysts, and defensive operators as the intended audience.
What to do
1. Reduce attack surface. Restrict external management via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best), matching the CSA's language.
2. Terminate sessions and reset credentials. End all admin and VPN sessions. Reset Fortinet VPN and administrative passwords on internet-facing systems; enforce strong password policy.
3. Require phishing-resistant MFA on all remote access and administrative accounts, enforced on every external gateway and admin interface.
4. Validate configuration. Compare running config to a known-good baseline. Hunt for unrecognized accounts (the CSA lists commonly observed names such as fortiAdmin, forticloud-sync, adminsslvpn, and others). Review and rotate REST API keys.
5. Move admin hashes to PBKDF2. Confirm PBKDF2 for administrator credentials and remove weaker legacy hashes per Fortinet guidance for FortiOS 7.2.11 and later.
6. Review logs against the CSA's observed IPs and lateral-movement patterns; preserve evidence; report compromises to IC3, local FBI, and/or USSS field offices as appropriate.
7. Do not treat this as a KEV due-date exercise. Inventory exposure, assume credential reuse, and exercise lockout recovery procedures before you need them.
Sources: FBI/USSS JCSA-20261006-01 (https://www.ic3.gov/CSA/2026/261006.pdf); SOCRadar and Fortinet materials as cited in the CSA notes.
2. GSA's LLM safeguarding clause is usable now and effective October 19

GSA has issued clause 552.239-7001, Basic Safeguarding of Data within Large Language Model Artificial Intelligence Systems, as a GSAR class deviation. Trade coverage (FedScoop, Crowell, Nextgov/FCW) ties the action to a Senior Procurement Executive regulation-overhaul/RGO memo package around September 28, 2026. We did not open the September 28 RGO memo PDF on gsa.gov; what follows attributes the clause through trade reporting and published memo descriptions.
Timing: The deviation is described as effective October 19, 2026. Contracting officers may use it immediately, and existing contracts may be modified at the contracting officer's discretion (FedScoop, October 1, updated October 2).
Scope test: The clause applies when the Government is buying a system where LLM functionality is a material feature and Government Data is submitted directly to or produced by the LLM. It does not apply (and is described as self-deleting) for contractor internal/back-office LLM use that is not delivered to or accessed by the Government, and for products where LLM functionality is incidental to the primary purpose, unless the contracting officer says otherwise.
What buyers and sellers should expect (trade consensus):
- No training on Government Data, and no use of that data for advertising or sale to third parties (Nextgov, Crowell, GovConFeed summaries).
- Contractors must use reasonable efforts so the LLM prioritizes accuracy, scientific inquiry, and objectivity on factual prompts, and acknowledges uncertainty when information is incomplete or contradictory (FedScoop quoting the clause).
- The Government may conduct automated assessments of the LLM for bias, truthfulness, safety, unsolicited ideological content, and other factors it determines (FedScoop).
- The Government retains the right to suspend use of the LLM at any time (FedScoop).
- Contractors must notify the Government within seven calendar days of a material change that materially increases output bias, decreases safety guardrails or behavioral constraints, or degrades performance or truthfulness (FedScoop).
- After for-cause termination, contractor liability for decommissioning costs is capped at 25% of the affected task or delivery order (FedScoop).
- Flowdown follows the data: obligations reach subcontractors who handle Government Data, rather than tying solely to model authorship (FedScoop; industry comment framing such as "obligations should follow the data, not the model's authorship").
- Additional clocks appear in trade digests (for example 72-hour material-violation or FISMA incident notice, and model disclosure within 120 days). Treat those as trade-attributed until we or counsel open the primary memo PDF.
Earlier draft language on "unbiased AI principles" and bans on embedding "partisan or ideological judgments" largely gave way, after public comment, to the "reasonable efforts" factuality standard, while preserving Government assessment and suspension rights.
If LLM is a material feature and Government Data touches the model, the buy clause is no longer theoretical."
Why it matters
This is the practical acquisition signal for Q4. Program offices buying chat, document, coding, or agentic tools through GSA schedules need a clear applicability test. Integrators need data-flow maps, subcontract flowdown language, change-notice procedures, and a decommissioning cost model. Contracting officers can insert the clause now; waiting until October 19 is optional.
What to do
1. Map every proposed or live offering: is LLM a material feature, and does Government Data enter or leave the model?
2. Separate internal contractor tooling from Government-delivered LLM features so the self-delete path is honest, not hand-wavy.
3. Update proposal templates for no-training-on-Gov-data, seven-day material-change notice, assessment cooperation, suspension, and 25% decommissioning cap.
4. Rewrite subcontract flowdown to follow who touches Government Data.
5. Have counsel open the RGO/class-deviation text before arguing clause subsection numbers in a protest or negotiation. Our citations are trade-corroborated, not a substitute for the PDF.
Sources: FedScoop (https://fedscoop.com/gsa-issued-an-ai-acquisition-policy-for-new-contracts-heres-what-it-says/); Crowell client alert on 552.239-7001; Nextgov/FCW reporting on the GSA memo. Primary memo PDF on gsa.gov not opened by us.
3. Claude for Government goes GA for federal and state agencies

On October 2, 2026, Anthropic announced Claude for Government is generally available for federal and state agencies, after a public beta since July. Anthropic describes a FedRAMP High authorized environment delivering coding and agentic capabilities on a commercial release cadence, with governance controls built for public-sector administrators and authorizing officials.
Buying and control model (vendor primary):
- No seat fees. Agencies pay for usage in fixed increments with a hard not-to-exceed prepaid cap so spend cannot exceed what has been obligated.
- Administrators set user tiers with spend and model limits, track usage by user and model, and receive burndown alerts.
- Department-level admins can allocate prepaid usage to sub-agencies.
- Agencies connect their own identity provider for single sign-on, with self-serve setup; SCIM group mappings set rate limits, dollar caps, and allowed models per seat tier.
- Administrative actions are recorded in an audit log; Anthropic states sensitive operations on its side require two-person approval.
- Usage exports are metering data only; conversation history stays local on the agency-managed device.
- Agencies can contract with Anthropic directly and award on general-availability terms. Anthropic states agencies do not need a separate cloud-provider relationship to get started.
- Existing beta customers can move to the desktop application and import conversation history in-app.
Early access (not GA): The Claude Code command-line interface and Claude for Microsoft 365 are rolling out in early access through the same environment and administrative controls. Agencies interested in those paths are directed to Anthropic's public-sector team. FedRAMP Secure Configuration Guide materials are described as available through Anthropic's trust center; deployment is framed through standard agency MDM platforms.
Prepaid NTE plus FedRAMP High is the sentence acquisition and security can both underline."
Why it matters
Federal and state buyers now have another governed path alongside OneGov and commercial offers: direct Anthropic contracting, prepaid hard caps, SSO/SCIM, and audit artifacts aimed at ATO and IG questions. That matters for memo drafting, RFP review, casework, and modernization where agencies want Claude-class capabilities without inventing a new compliance stack. Early-access Code CLI and M365 connectors are optional accelerators, not the GA baseline.
What to do
1. Request access via Anthropic's government solutions path and confirm FedRAMP High boundary and current authorization package with your AO.
2. Design a prepaid NTE envelope and department allocation model before inviting users.
3. Wire SSO and SCIM first; treat seat tiers as control surfaces, not convenience settings.
4. Keep early-access Code CLI and M365 in a separate pilot lane until GA and agency configuration baselines catch up.
5. Align use cases with data-handling rules that will also have to satisfy GSA 552.239-7001 when the clause is on the vehicle.
Source: https://claude.com/blog/claude-for-government-is-now-generally-available
4. California SB 947: no sole reliance on automated systems for firing or discipline

On September 30, 2026, Governor Gavin Newsom signed Senate Bill 947 (McNerney), chaptered as Chapter 859, Statutes of 2026. The Governor's office framed the bill among a package of first-in-the-nation worker protections around AI and automated technology. The Exchange focus here is the employment ADS rule that public and private employers in California must implement before mid-2027.
Core rule (enrolled bill, corroborated via LegiScan and CapitolTrack): beginning July 1, 2027, an employer shall not rely solely on an automated decision system (ADS) for a disciplinary or termination decision. If an employer primarily relies on ADS output, a human must corroborate the decision using the data behind the ADS output or other supporting information. If the output cannot be corroborated, or the reviewer finds it inaccurate, incomplete, or misleading, the employer shall not use it.
Notice and access: Employers that primarily relied on an ADS for discipline or termination must provide a written postuse notice. Employees may request a description of their own data primarily used by the ADS. Retaliation for asserting rights under the bill is prohibited. Enforcement sits with the Labor Commissioner, with public-prosecutor civil enforcement authorized. Civil penalty: $500 per violation.
The Governor's September 30 release also lists companion measures (among them SB 951 on technological-displacement notice, AB 1331 and AB 1883 on workplace surveillance, and others). Those are context for California's broader AI labor package; SB 947 is the Top 5 story for HRIS, workforce analytics, and vendor ADS stacks used by state and local employers.
If the model is the only witness, California says that is not enough to fire someone."
Why it matters
State agencies, cities, counties, school districts, and every covered private employer have a hard operative date: July 1, 2027. Vendor roadmaps for performance management, scheduling, fraud detection, and "AI HR" copilots need human-corroboration workflows, evidence retention, and notice templates, not a slide that says "human in the loop" without a procedure. Multi-state employers will feel California's rule as a de facto design constraint even where other states have not matched it.
What to do
1. Inventory every ADS that can influence discipline, performance scoring, or termination recommendations for California employees (including public employers).
2. Design a documented human corroboration step with access to underlying data, not a rubber stamp.
3. Draft written postuse notice language and a data-description response process before July 1, 2027.
4. Update vendor contracts and acceptance tests so ADS outputs used for employment actions cannot be sole-source decisions.
5. Treat this as compliance program work, not a press release. The Exchange is not providing legal advice; counsel should read the enrolled chapter text.
Sources: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB947 ; Governor release https://www.gov.ca.gov/2026/09/30/californias-nation-leading-ai-framework-just-got-stronger-governor-newsom-signs-more-first-in-the-nation-worker-protections-and-more/ ; LegiScan/CapitolTrack enrolled corroboration for Chapter 859, operative date, corroboration duty, and $500 penalty.
5. Genesis Mission: $2.4B in SI tools and compute credits, plus a Georgia scientific-computing push

On October 8, 2026, the White House released a fact sheet from the Science: A New Golden Age Summit describing what it called the most ambitious set of science initiatives in decades. For Exchange readers, the SI compute signal is the headline.
The Administration announced $2.4 billion in SI for science tools and compute credits for the Genesis Mission Consortium from eleven industry partners, intended to support over 15 Federal agencies working toward National Science & Technology Challenges. Named partner commitments in the fact sheet:
- NVIDIA - $1 billion
- AMD - $500 million
- OpenAI - $200 million
- Anthropic - $150 million
- Google - $150 million
- AMP - $100 million
- Emerald AI - $100 million
- AWS, Armada, Crusoe, and Micron - $50 million each
Hedge: These are tools and compute credits, not cash grants to agencies. Dollar figures are as announced in the White House fact sheet and should be treated as institutional/partner self-reported commitments.
The same fact sheet states that universities, industry, and the State of Georgia announced a $1 billion investment in scientific computing and workforce training, alongside Southeast regional SI computing consortia. Separately, same-day Georgia Tech and Emory coverage describes combined institutional AI investments exceeding $1 billion (Emory approximately $600 million; Georgia Tech more than $575 million), including advanced computing in Tech Square, a campuswide platform, and a new AI supercomputer (Nexus). We treat the White House Georgia $1B line and the Georgia Tech/Emory institutional packaging as related but not identical totals; do not collapse them into one unverified cash pile.
Broader summit items (X-Labs, quantum prizes, space nuclear MOUs, metascience units) are out of scope for this Top 5 section except as context that SI compute is being framed as national-mission infrastructure.
Credits and clusters are how SI research capacity shows up in agency roadmaps, not as a single appropriation line."
Why it matters
Federal research, energy, health, and space programs that need SI-scale compute will chase consortium credits, regional hubs, and university partnerships as much as classic contract vehicles. Georgia and Southeast economic-development and university CIOs should expect more pressure to show workforce pipelines and shared infrastructure. GPU, cloud, and scientific-software vendors should read the partner list as a map of who is underwriting capacity, then ask which agency challenges those credits actually unlock.
What to do
1. Track Genesis Mission Consortium credit eligibility and agency challenge areas rather than treating $2.4B as free money.
2. For Georgia and Southeast buyers, separate White House $1B scientific-computing framing from individual university press totals when briefing leadership.
3. Align research computing roadmaps with FedRAMP, agency ATO, and data-governance constraints before moving sensitive workloads onto partner credits.
4. Watch follow-on NSF/DOE instrumentation and autonomous-lab announcements for operational buy signals beyond the headline credits.
Sources: https://www.whitehouse.gov/fact-sheets/2026/10/fact-sheet-trump-administration-announces-the-most-ambitious-set-of-science-initiatives-this-century/ ; https://news.gatech.edu/news/2026/10/08/georgia-tech-and-emory-invest-more-1b-ai-drive-states-jobs-economic-growth
Also this week
- Citrix NetScaler CVE-2026-88779 added to CISA KEV with an October 7 due date for covered federal civilian executive branch agencies (one-line cyber note; FortiBleed remains the featured cyber story).
- CISA catalogued additional legacy KEVs with remediation due October 11.
- FAR CUI proposed-rule discussion continues around a 72-hour breach-notification clock; confirm Federal Register text before deep operational reliance.
- TSA OIG-26-40 access-control findings for transportation security stakeholders.
- Technology Modernization Fund approximately $83.4 million across four investments (confirm amounts on agency release).
- DISA Enclave notice JA26-059 for teams tracking DISA hosting and enclave paths.
- North Carolina PC quarterly price-lock activity for state buyers.
- Houston roughly $79.1 million PC procurement signal.
- Utah AI executive order dated October 6.
- SSA Carahsoft identity BPA on the order of ~$29.6 million (trade figure; confirm).
- San Diego SHI Microsoft agenda item around ~$24.9 million (confirm council action).
- Anduril NGC2 ceiling framing up to $1.8 billion (confirm vehicle and terms).
- OPM FWD Chat as a federal workforce SI tooling signal.
- Los Angeles Axon LPR pilot delay.
- Raleigh data-center moratorium discussion alongside ServiceNow Alli activity.
- San Francisco / Oakland 45-day data-center moratoria.
- Cal OES ICEYE earth-observation / SAR partnership signal.
- DHS NCCS 2.0 timeline slipped relative to the prior early-October sprint framing.
- California Little Hoover Commission IT recommendations for state oversight watchers.
The Exchange takeaway
Five signals, one operating picture. FortiBleed is a live credential campaign that can lock operators out of their own FortiGate VPN estates and feed ransomware affiliates. GSA's LLM safeguarding clause turns data handling, change notice, assessment, suspension, and decommissioning cost into enforceable buy language usable now. Claude for Government gives agencies a FedRAMP High, prepaid-NTE path with direct Anthropic contracting. California SB 947 starts a July 1, 2027 clock on human corroboration for automated discipline and termination. And the Genesis Mission's $2.4 billion in tools and compute credits reframes how agencies and university partners chase SI research capacity.
If your team is translating these signals into a security backlog, an acquisition plan, an HRIS compliance roadmap, or a research-compute partnership, that is the work we help make practical. Reach out at info@MetoraSolutions.com for a focused conversation.
Discussion
Which signal changes your next 90 days most: FortiBleed exposure and lockout recovery, inserting 552.239-7001 into LLM buys, standing up Claude for Government with prepaid NTE controls, building SB 947 human-corroboration workflows before mid-2027, or chasing Genesis Mission compute credits? What are you seeing?
Share this briefing with a colleague who owns cyber, acquisition, or workforce systems. Follow Metora Solutions on LinkedIn, and subscribe so you do not miss the next weekly package.
Daily notice
For a shorter daily cut of public-sector cyber, acquisition, and SI signals, watch The Exchange Daily on YouTube: https://www.youtube.com/@Metora_The_Exchange
This weekly edition is a practical information briefing, not legal, procurement, cybersecurity, employment, or investment advice. Dates, schedules, clause text, and program terms can change. Confirm current requirements and primary-source materials before acting. Device counts, partner credit totals, and institutional investment figures are attributed to the cited sources and are not independent audits by The Exchange.
About
The Exchange is Dee Anthony's weekly briefing on public-sector technology, federal acquisition, cybersecurity, digital government, and practical SI strategy. It is written for leaders who need the signal, the source, and the next decision.
Metora Solutions supports public-sector and enterprise teams with federal SI governance, program advisory, and practical technology strategy. Metora Solutions is a HUBZone and SDVOSB.
Because guesswork isn't a strategy.
Sources (selected)
- FBI/USSS JCSA-20261006-01: https://www.ic3.gov/CSA/2026/261006.pdf
- FedScoop on GSA AI acquisition class deviation: https://fedscoop.com/gsa-issued-an-ai-acquisition-policy-for-new-contracts-heres-what-it-says/
- Crowell on GSAR 552.239-7001; Nextgov/FCW on GSA memo
- Anthropic: https://claude.com/blog/claude-for-government-is-now-generally-available
- CA SB 947: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB947
- CA Governor release Sep 30, 2026
- White House fact sheet Oct 8, 2026 (Genesis Mission / science initiatives)
- Georgia Tech Oct 8, 2026 (Georgia Tech and Emory AI investments)