Cleartext

Cleartext โ€“ August 03, 2026


Listen Later

Cleartext โ€“ August 03, 2026

Daily cybersecurity briefing for CISOs and security leaders.

๐ŸŽง Listen to this episode

Episode Summary

Today's episode covers 9 stories across 6 topic areas, including: Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers; Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says; Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS.

Stories Covered
๐ŸŒ Geopolitical
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

Help Net Security ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ 9/10

Why it matters to CISOs: This is a documented, real-world case of a state-linked Chinese threat actor deploying AI-orchestrated autonomous attacks at scale against internet-facing systems โ€” a threat model CISOs must now operationalize defenses against, not just theorize about.

  • Threat actor 'knaithe'/'KnYuan' used multiple LLMs including DeepSeek to automate attacks with minimal human intervention
  • Unit 42 gained full visibility into the operation after the attacker's own AI agent misconfigured a file server, exposing their entire infrastructure
  • The operation represents a documented shift from AI-assisted to AI-autonomous offensive operations by a nation-state-linked actor
  • ๐Ÿ“– Read full article

    Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says

    The Record (Recorded Future) ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 8/10

    Why it matters to CISOs: Executives and security staff traveling internationally are directly at risk; CISOs should immediately reinforce travel security policies, mandate VPN usage, and brief board members and leadership on credential harvesting risks tied to hotel networks.

    • Russian state-sponsored actors are compromising hotel Wi-Fi infrastructure globally to steal credentials and deploy espionage malware
    • Microsoft attributed the campaign in a formal disclosure
    • Attack vector targets travelers' devices at the network layer, bypassing endpoint controls
    • ๐Ÿ“– Read full article

      Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

      The Hacker News ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

      Why it matters to CISOs: A Chinese threat actor operating over 100 fake AWS sign-in pages while deploying iOS exploit kits represents a direct threat to enterprise mobile device users and cloud credential security โ€” CISOs should assess iOS MDM posture and evaluate phishing simulation coverage for cloud login spoofing.

      • An unidentified Chinese threat actor is running 100+ fake AWS sign-in pages alongside the DarkSword exploit toolkit
      • The campaign targets Apple iOS devices using a publicly leaked exploit kit to deploy GHOSTBLADE malware
      • Censys' attack surface management platform identified the infrastructure, suggesting broad internet-facing exposure
      • ๐Ÿ“– Read full article

        ๐Ÿ“ก Macro Trends
        CrowdStrike: AI is now both the weapon and the target in cyberattacks

        CyberScoop ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 8/10

        Why it matters to CISOs: CrowdStrike's annual threat hunting report provides board-ready data on AI's dual role in the threat landscape, with concrete signal-to-noise metrics that CISOs can use to justify AI-augmented SOC investments and reframe defender strategy.

        • AI now generates 2.5 signals for every human-triggered signal that CrowdStrike analysts must assess
        • Attackers are leveraging AI to weaponize vulnerabilities faster than enterprise patch cycles can respond
        • The report frames AI as simultaneously a force multiplier for defenders and the primary new attack surface requiring protection
        • ๐Ÿ“– Read full article

          ๐Ÿ”“ Data Breach
          Biotech giant Amgen says patient data stolen from third-party cloud systems

          The Record (Recorded Future) ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 8/10

          Why it matters to CISOs: Amgen's SEC disclosure of a third-party cloud breach exposing patient and proprietary data reinforces the critical need for robust vendor risk programs and cloud access governance, particularly for regulated healthcare and life sciences environments.

          • Amgen filed an SEC disclosure confirming patient information and proprietary company data were accessed
          • The breach originated through a compromise of third-party cloud systems, not Amgen's own infrastructure
          • The incident highlights supply chain and third-party cloud risk as a leading breach vector for large enterprises
          • ๐Ÿ“– Read full article

            PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

            The Hacker News ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

            Why it matters to CISOs: The exposure of law enforcement and government contact data on the dark web has direct implications for enterprise CISOs working with government partners or managing criminal justice supply chains, and underscores third-party data handling risks for sensitive professional directories.

            • The Police National Legal Database confirmed names, organizations, and work email addresses of police, government staff, and criminal justice professionals were compromised
            • Data appeared on the dark web; incident was identified July 26
            • The breach affects a cross-sector database touching law enforcement, government, and private sector criminal justice partners
            • ๐Ÿ“– Read full article

              โš–๏ธ Governance & Policy
              CISA lays out new guidance for using open-source software

              Help Net Security ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

              Why it matters to CISOs: CISA's OSS security guidance sets a new federal baseline for managing open-source risk โ€” enterprise CISOs, especially those with federal contracts or operating in regulated sectors, should assess alignment of their OSS governance programs with these principles before they become contractual requirements.

              • CISA published 'Open Source Software: Security Principles and Practices' targeting federal agencies
              • Guidance covers OSS security management, contributing to OSS projects, and evaluating open-source AI systems
              • The document emphasizes independent code review and reducing single-vendor dependency as core security benefits of OSS adoption
              • ๐Ÿ“– Read full article

                ๐Ÿš€ Startup Ecosystem
                Horizon3.ai hits $2 billion valuation in $250 million funding round

                Help Net Security ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

                Why it matters to CISOs: Horizon3.ai's tripling valuation in just over a year signals strong enterprise demand for autonomous, continuous security validation as a replacement for periodic pentesting โ€” CISOs should assess whether their current validation programs match the cadence of AI-accelerated attacker timelines.

                • Horizon3.ai raised $250M Series E at a $2B valuation, up from $650M at Series D roughly a year ago
                • Round was oversubscribed and co-led by NightDragon and NEA with 12 total investor participants
                • Growth is attributed to accelerating demand for autonomous security validation as AI-driven cyberattacks increase velocity
                • ๐Ÿ“– Read full article

                  ๐Ÿšจ Critical Vulnerability
                  N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

                  The Hacker News ยท Aug 03 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ 9/10

                  Why it matters to CISOs: N-central is an RMM platform with privileged access to thousands of downstream customer environments โ€” active exploitation of this authentication bypass means any MSP or enterprise using N-central prior to build 2026.3.1.7 should treat this as an emergency patching event and audit for indicators of compromise immediately.

                  • CVE-2026-18577 is an authentication bypass in N-able N-central enabling remote administrative takeover of managed customer systems
                  • The initial patch was confirmed incomplete; the first unaffected build (2026.3.1.7) shipped August 2
                  • Active exploitation is confirmed, with attackers leveraging compromised N-central servers to pivot into downstream managed environments
                  • ๐Ÿ“– Read full article

                    Further Reading
                    • ๐ŸŒ Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers โ€” Help Net Security
                    • ๐ŸŒ Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says โ€” The Record (Recorded Future)
                    • ๐ŸŒ Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS โ€” The Hacker News
                    • ๐Ÿ“ก CrowdStrike: AI is now both the weapon and the target in cyberattacks โ€” CyberScoop
                    • ๐Ÿ”“ Biotech giant Amgen says patient data stolen from third-party cloud systems โ€” The Record (Recorded Future)
                    • ๐Ÿ”“ PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web โ€” The Hacker News
                    • โš–๏ธ CISA lays out new guidance for using open-source software โ€” Help Net Security
                    • ๐Ÿš€ Horizon3.ai hits $2 billion valuation in $250 million funding round โ€” Help Net Security
                    • ๐Ÿšจ N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete โ€” The Hacker News
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext. It's Monday, August 3rd, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves. Let's get into it.

                      Alex: So Jordan, you walked into the studio this morning and said, and I quote, "the machines are writing their own exploits now." Let's start there.

                      Jordan: Yeah. Unit 42 dropped a report over the weekend that I think every CISO needs to read before their Monday standup. A Chinese threat actor operating under the handles "knaithe" and "KnYuan" deployed DeepSeek and multiple other large language models to run autonomous cyberattacks against internet-facing infrastructure. Not AI-assisted. Autonomous. Minimal human intervention. The AI agent was selecting targets, crafting exploits, executing the attack chain.

                      Alex: And the kicker is how we even know about this.

                      Jordan: Right. The attacker's own AI agent misconfigured a file server and exposed the entire operation. The AI made an OPSEC mistake. Which is almost poetic. Unit 42 got full visibility into the infrastructure, the tooling, the operational tempo. This is the most documented case we've seen of a nation-state-linked actor crossing the line from using AI as a copilot to deploying AI as the pilot.

                      Alex: So let's talk about what this actually means for defenders. If you're a CISO and your threat model still treats AI as an accelerant for human operators, you're behind. This is a fundamentally different attack cadence. An AI agent doesn't take breaks, doesn't make judgment calls the way a human does, and can scale horizontally across targets in a way that a human team simply cannot.

                      Jordan: And it changes your detection math. Your SOC is built to detect patterns of human behavior. Dwell time, lateral movement cadence, the rhythm of a keyboard. An AI agent operating autonomously produces different telemetry. You need to be asking your detection engineering team whether their models account for machine-speed, machine-pattern attack sequences.

                      Alex: This dovetails perfectly with the CrowdStrike annual threat hunting report that also dropped today. The headline number: AI now generates two and a half signals for every human-triggered signal that CrowdStrike analysts have to assess. So the signal-to-noise problem is not hypothetical. It's quantified.

                      Jordan: And the other side of that CrowdStrike data is just as important. Attackers are weaponizing vulnerabilities faster than enterprise patch cycles can respond. We've been saying this for years, but now we have the data. The window between disclosure and exploitation has compressed to the point where traditional vulnerability management programs are structurally inadequate.

                      Alex: Which brings me to the N-able story, because this is a perfect case study of that compression. CVE-2026-18577, an authentication bypass in N-central. This is an RMM platform. If you're an MSP or you use one, N-central has privileged access to potentially thousands of downstream customer environments. Active exploitation is confirmed. And here's the part that should make you uncomfortable: N-able's first patch was incomplete. The actually fixed build, 2026.3.1.7, shipped Saturday. August 2nd.

                      Jordan: So if you patched when the first advisory came out and moved on, you're still exposed. This is a "go verify right now" situation. Don't assume your MSP has handled it. Call them. Confirm the build number. And audit for indicators of compromise, because attackers were already leveraging compromised N-central servers to pivot into downstream managed environments before the real fix shipped.

                      Alex: The MSP supply chain remains one of the highest-leverage attack surfaces in enterprise security, and incidents like this are why. You inherit their risk posture whether you like it or not.

                      Jordan: Let's stay on the supply chain theme for a second, because the Amgen breach fits here too. Amgen filed an SEC disclosure confirming that patient information and proprietary company data were accessed through a compromise of third-party cloud systems. Not Amgen's infrastructure. Their vendor's infrastructure.

                      Alex: And this is a pattern that boards are increasingly uncomfortable with. You can have a world-class internal security program, and your risk exposure is still dictated by the weakest link in your vendor ecosystem. For CISOs in healthcare, life sciences, any regulated environment, this is a board conversation about contractual controls, right to audit clauses, and whether your vendor risk management program has actual teeth or is just a questionnaire factory.

                      Jordan: The PNLD breach in the UK is a similar flavor. The Police National Legal Database confirmed that names, organizations, and work email addresses of police officers, government staff, and criminal justice professionals were compromised and published on the dark web. If your organization intersects with law enforcement or government criminal justice partnerships, this data is now circulating. Social engineering risk against those contacts just went up meaningfully.

                      Alex: Alright, let's pivot to the geopolitical bloc, because we have three China-linked stories today and that's not a coincidence. Beyond the DeepSeek autonomous attack story, there's a campaign tracked by The Hacker News where a Chinese threat actor is running over a hundred fake AWS sign-in pages alongside the DarkSword exploit kit, which is a leaked iOS exploit toolkit being used to deploy GHOSTBLADE malware on Apple devices.

                      Jordan: So let's unpack why this matters operationally. You've got credential harvesting at scale against AWS, which means cloud identity is the target. And simultaneously, iOS devices being hit with a publicly available exploit kit. The combination is nasty. Your executives log into AWS from their iPhones. If the device is compromised and the credential is harvested, you've lost both layers.

                      Alex: CISOs should be looking at two things immediately. One, your iOS MDM posture. Are you enforcing the latest iOS versions? Are you detecting jailbreak indicators? And two, your phishing simulation program. Does it cover cloud login spoofing? Most programs are still focused on email credential harvesting. Fake AWS sign-in pages are a different beast.

                      Jordan: And then on the Russian side, Microsoft formally attributed a campaign where Russian state-sponsored actors are compromising hotel Wi-Fi infrastructure globally to steal credentials and deploy espionage malware against travelers.

                      Alex: This one is personal for a lot of our listeners. Your executives travel. Your security staff travels. Your board members travel. The attack vector here operates at the network layer, which means it can bypass endpoint controls if your VPN discipline isn't airtight.

                      Jordan: And let's be honest, VPN discipline on the road is terrible at most organizations. People connect to hotel Wi-Fi, dismiss the certificate warning, check their email. This is a policy enforcement problem as much as a technical one. If you don't have a mandatory always-on VPN policy for travel, today's the day to write one. And if you do have one, verify that it's actually enforced, not just recommended.

                      Alex: Brief your board members specifically. They are high-value targets. They travel frequently. And they are the least likely people in your organization to follow your security policies voluntarily.

                      Jordan: Diplomatic way of putting it.

                      Alex: I'm a diplomat. Alright, let's hit a couple more items quickly. CISA published new guidance on open-source software security, targeting federal agencies but with implications well beyond government. The document covers OSS security management, contributing to open-source projects, and evaluating open-source AI systems. It emphasizes independent code review and reducing single-vendor dependency.

                      Jordan: If you have federal contracts or operate in a regulated sector, treat this as a preview of future contractual requirements, not just guidance. CISA doesn't publish frameworks for fun. This is the groundwork for compliance expectations that will show up in procurement language within twelve to eighteen months.

                      Alex: Agreed. And on the funding side, Horizon3.ai hit a two billion dollar valuation on a two hundred fifty million Series E. That's triple their valuation from roughly a year ago. The round was oversubscribed, co-led by NightDragon and NEA.

                      Jordan: The signal here isn't about Horizon3 specifically. It's about market validation for autonomous continuous security validation as a category. Periodic pentesting on an annual or quarterly cadence was already struggling to keep up. When your adversaries are running AI-autonomous attack chains, testing your defenses once a quarter is like checking your smoke detectors once a year and hoping for the best.

                      Alex: CISOs should be evaluating whether their current validation cadence matches the tempo of the threat environment they actually face, not the one they faced two years ago.

                      Jordan: Alright, looking ahead. The theme for this week and honestly for the rest of this year is the operational reality of AI-autonomous offense. We've crossed a threshold. The Unit 42 report isn't a proof of concept or a research paper. It's a documented nation-state operation. The CrowdStrike data quantifies the signal overload that defenders are already drowning in. And the market is voting with capital that autonomous validation is the response.

                      Alex: What I'm watching is how quickly boards internalize this shift. The conversation has been "AI might be used by attackers" for two years. That conversation is over. AI is being used by attackers, autonomously, at scale, right now. The board question is no longer whether to invest in AI-augmented defense. It's whether your current investment is keeping pace with the adversary's investment. And if you can't answer that question with data, you're going to have a difficult Q3 review.

                      Jordan: And on the policy side, watch for acceleration in AI governance frameworks. When autonomous AI agents are conducting offensive operations, the regulatory pressure to govern defensive AI use will intensify. CISOs need to be at that table, not waiting for legal or compliance to hand them a framework to follow.

                      Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow.

                      Jordan: Stay sharp out there.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-03.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext