Cleartext

Cleartext – July 01, 2026


Listen Later

Cleartext – July 01, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: Risky Bulletin: Researcher drops giant cache of zero-days; U.S. lifting export control restrictions on Anthropic’s Mythos, Fable; Microsoft Accelerates Post-Quantum Cryptography Shift to 2029.

Stories Covered
🌍 Geopolitical
Risky Bulletin: Researcher drops giant cache of zero-days

Risky Business News Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

Why it matters to CISOs: A public dump of a large zero-day cache combined with a confirmed DHS network breach and a Supreme Court ruling restricting geofence warrants in the same news cycle represents compounding risk across technical, legal, and governmental dimensions that senior security leaders must track simultaneously.

  • An anonymous researcher publicly released a large cache of zero-day exploits, potentially enabling widespread opportunistic exploitation before vendors can patch
  • A sensitive DHS network was confirmed hacked, raising concerns about the security of government cybersecurity infrastructure itself
  • The U.S. Supreme Court issued a ruling restricting law enforcement use of geofence warrants, with implications for corporate incident response and legal holds
  • πŸ“– Read full article

    U.S. lifting export control restrictions on Anthropic’s Mythos, Fable

    CyberScoop Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

    Why it matters to CISOs: The government's decision to lift export controls on frontier cybersecurity AI models β€” conditioned on new technical guardrails β€” sets a precedent for how dual-use AI capabilities will be regulated globally, with direct implications for CISOs evaluating AI security tool procurement, vendor risk, and adversarial AI threat modeling.

    • The U.S. Commerce Department reached an agreement with Anthropic to lift export controls on its Mythos and Fable frontier AI models
    • Release is conditioned on new classifiers and guardrails that Anthropic says block the jailbreak technique that triggered original controls in over 99% of cases
    • The decision establishes a conditional release framework that may become the regulatory model for other advanced AI security capabilities
    • πŸ“– Read full article

      πŸ“‘ Macro Trends
      Microsoft Accelerates Post-Quantum Cryptography Shift to 2029

      The Hacker News Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

      Why it matters to CISOs: Microsoft's accelerated 2029 deadline for quantum-safe cryptography across Azure compresses the planning window for enterprise security programs that depend on Microsoft infrastructure, forcing CISOs to accelerate their own PQC transition roadmaps and vendor dependency reviews.

      • Microsoft Azure CTO Mark Russinovich stated quantum computing advances have 'shifted the risk horizon,' requiring faster action than previously planned
      • Microsoft is targeting 2029 for full quantum-safe cryptography deployment across its cloud infrastructure
      • The announcement signals that 'harvest now, decrypt later' threats are being treated as a near-term, not theoretical, risk by major cloud providers
      • πŸ“– Read full article

        πŸ”“ Data Breach
        Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day

        Infosecurity Magazine Β· Jun 30 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

        Why it matters to CISOs: The Oracle PeopleSoft zero-day campaign is now confirmed to have claimed a major global manufacturer's employee data, expanding the known victim list and underscoring urgency for any enterprise running PeopleSoft HR systems to verify patch status and investigate potential prior compromise.

        • Nissan confirmed employee data was stolen via an Oracle PeopleSoft zero-day vulnerability
        • The Oracle PeopleSoft zero-day campaign has now affected multiple major enterprises across different industries
        • HR system compromise puts sensitive employee PII, compensation, and identity data at risk, with downstream fraud and social engineering implications
        • πŸ“– Read full article

          Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches

          The Record (Recorded Future) Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

          Why it matters to CISOs: A simultaneous wave of disclosures across major Japanese enterprises β€” spanning insurance, consumer goods, manufacturing, and telecom β€” signals either a coordinated campaign or a common vulnerability in the supply chain; CISOs with Japanese subsidiaries, partners, or vendors should assess exposure immediately.

          • Aflac Japan, Sapporo Holdings, Nidec, and KDDI have all disclosed data breaches in close proximity
          • Aflac Japan confirmed policy details and personal and banking information were compromised, affecting millions
          • The clustering of breaches across unrelated sectors suggests potential shared infrastructure, third-party, or supply chain vector
          • πŸ“– Read full article

            βš–οΈ Governance & Policy
            DHS to unveil replacement council for critical infrastructure cybersecurity

            CyberScoop Β· Jun 30 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

            Why it matters to CISOs: This directly affects how enterprise security leaders in critical infrastructure sectors receive threat intelligence and coordinate with the federal government β€” a channel that was severed for over a year. CISOs should evaluate whether their organizations qualify for and should engage with the new ANCHOR-CI framework.

            • DHS is launching the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI) program
            • The replacement comes more than a year after the Trump administration shut down the previous public-private information sharing council
            • The new framework is intended to restore government-to-private sector cybersecurity coordination on critical infrastructure
            • πŸ“– Read full article

              Trump budget boss Russell Vought open to re-staffing CISA

              CyberScoop Β· Jun 30 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

              Why it matters to CISOs: CISA's capacity to support enterprise security programs, issue advisories, and respond to national incidents hinges on staffing levels; a potential reversal of deep cuts would meaningfully affect the agency's operational value to CISOs who rely on it as a resource and partner.

              • DHS Secretary Markwayne Mullin has floated adding back approximately 600 CISA personnel after significant Trump administration cuts
              • OMB Director Russell Vought has signaled openness to the re-staffing proposal
              • CISA had experienced deep personnel reductions that reduced its advisory and incident response capacity
              • πŸ“– Read full article

                🚨 Critical Vulnerability
                Over 900 Oracle E-Business instances exposed to ongoing attacks

                BleepingComputer Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                Why it matters to CISOs: Oracle E-Business Suite is mission-critical ERP for many large enterprises; active at-scale exploitation of a critical flaw with 900+ exposed instances means CISOs must treat this as an emergency patching and exposure-verification priority, not a routine patch cycle item.

                • Over 900 Oracle E-Business Suite instances are publicly exposed and under active attack exploiting a critical vulnerability
                • Oracle EBS is widely used across enterprise finance, supply chain, and HR operations, making compromise a potential existential business risk
                • The campaign is ongoing, meaning unpatched organizations face imminent risk of data exfiltration or operational disruption
                • πŸ“– Read full article

                  Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts

                  The Hacker News Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                  Why it matters to CISOs: A massive automated password spray campaign specifically targeting Azure CLI β€” a privileged management interface β€” represents a direct threat to enterprise cloud control planes; CISOs should verify MFA enforcement on all Azure CLI and DevOps pipeline service accounts and review anomalous IPv6 authentication attempts.

                  • Over 81 million password spray attempts targeted Microsoft Azure CLI accounts between June 12–26, 2026, compromising at least 78 accounts
                  • The attack originates from IPv6 range 2a0a:d683::/32 controlled by infrastructure provider LSHIY LLC (AS32167)
                  • Huntress researchers identified the campaign and note it is ongoing and fully automated, suggesting many enterprises may have undetected compromises
                  • πŸ“– Read full article

                    Further Reading
                    • 🌍 Risky Bulletin: Researcher drops giant cache of zero-days β€” Risky Business News
                    • 🌍 U.S. lifting export control restrictions on Anthropic’s Mythos, Fable β€” CyberScoop
                    • πŸ“‘ Microsoft Accelerates Post-Quantum Cryptography Shift to 2029 β€” The Hacker News
                    • πŸ”“ Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day β€” Infosecurity Magazine
                    • πŸ”“ Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches β€” The Record (Recorded Future)
                    • βš–οΈ DHS to unveil replacement council for critical infrastructure cybersecurity β€” CyberScoop
                    • βš–οΈ Trump budget boss Russell Vought open to re-staffing CISA β€” CyberScoop
                    • 🚨 Over 900 Oracle E-Business instances exposed to ongoing attacks β€” BleepingComputer
                    • 🚨 Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts β€” The Hacker News
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext. It's Wednesday, July 1st, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves. Let's get into it.

                      Alex: We have a packed show today. An anonymous researcher just dumped a massive cache of zero-days into the wild, and that's landing in the same week as a confirmed DHS network breach and Oracle systems getting hammered across the globe. We'll cover Microsoft compressing the post-quantum timeline to 2029, the U.S. lifting export controls on Anthropic's frontier AI models, a wave of breaches hitting Japanese enterprises, and DHS trying to rebuild the public-private information sharing apparatus it tore down a year ago. Plus, CISA might actually get some of its people back. There's a lot to unpack, so let's move.

                      Jordan: So let's start with the zero-day dump, because this is the story that should have every SOC on high alert this morning. An anonymous researcher β€” and I'm using that term loosely β€” publicly released a large cache of zero-day exploits. We don't have a full accounting yet of what's in there, but the early analysis suggests this covers multiple major platforms. The window between public release and vendor patches is where the damage happens, and that window is now open.

                      Alex: And the timing here is terrible, or maybe deliberate, depending on how conspiratorial you want to get. This drops in the same cycle as confirmation that a DHS network was breached. Not a contractor. Not a peripheral system. A sensitive DHS network. When the agency responsible for coordinating national cybersecurity defense gets compromised, that's not just an incident β€” it's a credibility event.

                      Jordan: Right. And look, DHS has had security issues before, but the optics of this landing alongside a zero-day dump β€” it raises a question that boards are going to ask: if the government can't secure itself, what does that mean for the threat intelligence and guidance we're receiving from them? And that connects directly to the ANCHOR-CI story we'll get to in a minute.

                      Alex: There's a third piece in this Risky Business bulletin that CISOs need to track. The Supreme Court issued a ruling restricting geofence warrants. Now, on the surface that's a privacy win, but it has real implications for corporate incident response. If you're dealing with a breach that involves law enforcement, the tools available to investigators just changed. Your legal team needs to understand what this means for evidence collection, legal holds, and how you cooperate with federal investigations going forward.

                      Jordan: Three simultaneous shifts β€” technical, institutional, and legal. That's the kind of compounding risk that doesn't show up in any single dashboard.

                      Alex: Let's stay on the Oracle thread, because this is becoming a campaign, not an isolated incident. Nissan confirmed that employee data was stolen through an Oracle PeopleSoft zero-day. This is the same vulnerability chain that's been hitting enterprises across multiple industries. And separately, BleepingComputer is reporting over 900 Oracle E-Business Suite instances are publicly exposed and under active exploitation right now.

                      Jordan: Two different Oracle product lines, both under active attack. PeopleSoft is your HR backbone β€” employee PII, compensation data, banking details. E-Business Suite is your ERP β€” finance, supply chain, procurement. If you're running either of these, this is not a patch-cycle conversation. This is a drop-everything conversation. Nine hundred exposed EBS instances means there are organizations that don't even know they're internet-facing with critical Oracle infrastructure.

                      Alex: And the Nissan disclosure is instructive here. This is a global manufacturer with a mature security program, and they still got hit. The PeopleSoft zero-day campaign has now claimed victims across multiple industries. If you're a CISO running PeopleSoft for HR, you need to assume you were targeted and investigate accordingly. Don't wait for the vendor advisory to tell you what you should already be looking for.

                      Jordan: The downstream risk from HR system compromise is significant. You're not just talking about notification obligations. You're talking about identity fraud, targeted social engineering against your own employees using real compensation and organizational data. That's a gift to any threat actor running a business email compromise operation.

                      Alex: Let's pivot to the Azure CLI password spray campaign, because this connects to the broader theme of cloud control plane security. Huntress identified over 81 million password spray attempts targeting Azure CLI accounts over a two-week window in June. At least 78 accounts were compromised.

                      Jordan: Eighty-one million attempts. And the interesting technical detail here is this is coming from an IPv6 range, which a lot of detection stacks still don't monitor with the same rigor as IPv4. The source is an infrastructure provider called LSHIY LLC. This is fully automated, it's ongoing, and it's targeting a privileged management interface. Azure CLI is how your DevOps teams manage cloud infrastructure. A compromised CLI account is essentially root access to your cloud environment.

                      Alex: The action item is straightforward but urgent. Verify MFA enforcement on every Azure CLI account and every service account in your DevOps pipelines. Review authentication logs specifically for IPv6 anomalies. And if you're using Huntress, they've published indicators. If you're not, go find them anyway.

                      Jordan: And honestly, if you haven't audited your service account authentication policies in the last 90 days, this is your reason.

                      Alex: Let's talk about the wave of breaches coming out of Japan. Aflac Japan, Sapporo Holdings, Nidec, and KDDI have all disclosed data breaches in close proximity. These are companies spanning insurance, consumer goods, manufacturing, and telecom. Aflac alone confirmed that policy details, personal information, and banking data were compromised, affecting millions of customers.

                      Jordan: The clustering is what makes this interesting. Four major companies, four completely different sectors, all disclosing within essentially the same window. That pattern usually points to one of two things: either a coordinated campaign by a single actor, or a shared third-party or supply chain vector that connected them. Japan's regulatory disclosure requirements have tightened, so we might be seeing faster reporting, but the volume is unusual.

                      Alex: If you have Japanese subsidiaries, joint ventures, or tier-one suppliers in Japan, this is your signal to assess exposure. Don't wait for attribution. Check your data flows, check your shared service providers, and verify your incident notification agreements with Japanese partners are current.

                      Jordan: Now let's shift to a story that's going to reshape how we think about AI security tools. The Commerce Department reached an agreement with Anthropic to lift export controls on its Mythos and Fable frontier AI models. These were restricted because of dual-use concerns β€” specifically, jailbreak vulnerabilities that could enable adversarial applications.

                      Alex: The lift is conditional. Anthropic says they've implemented new classifiers and guardrails that block the original jailbreak technique in over 99 percent of cases. And Commerce apparently accepted that as sufficient. What's significant here isn't just this specific decision β€” it's that this creates a precedent. A conditional release framework for frontier AI capabilities. Other AI companies are watching this very closely.

                      Jordan: From a CISO perspective, there are two angles. First, if you're evaluating AI-powered security tools, the vendor landscape just changed. Models that were previously restricted are now available, which means your procurement evaluation criteria need to account for what guardrails are actually in place and how they're validated. Second, if you're doing adversarial AI threat modeling, the capabilities available to both defenders and attackers just expanded. The 99 percent block rate sounds impressive until you think about what the remaining one percent enables at scale.

                      Alex: And for CISOs sitting on AI governance committees β€” which should be all of you at this point β€” this regulatory model matters. Conditional release with technical guardrails is going to be the template. Your AI risk frameworks need to accommodate it.

                      Jordan: Let's talk about Microsoft's post-quantum announcement, because this one changes planning timelines. Mark Russinovich, Azure's CTO, announced they're targeting 2029 for full quantum-safe cryptography deployment across Azure. That's an acceleration from their previous roadmap.

                      Alex: This is a big deal for any enterprise that runs on Azure, which is a significant portion of the Fortune 500. When your primary cloud provider says the risk horizon has shifted and they're moving faster, you need to move faster too. If your PQC transition plan was built around a 2032 or 2035 timeline, you're now potentially out of sync with your infrastructure provider.

                      Jordan: The subtext here is that Microsoft is treating harvest-now-decrypt-later as a near-term operational risk, not a theoretical academic exercise. They have visibility into threat intelligence that most enterprises don't. When they accelerate, it's worth asking what they're seeing that's driving the urgency.

                      Alex: The practical implication: CISOs need to inventory every cryptographic dependency in their environment, identify what's quantum-vulnerable, and build a migration roadmap that aligns with β€” or ideally leads β€” their cloud provider's timeline. If you haven't started that work, 2029 is going to arrive faster than you think.

                      Jordan: Three years is not a lot of time for a cryptographic migration across enterprise infrastructure. This is a program that needs executive sponsorship and budget now.

                      Alex: Last two stories, and they're connected. DHS is launching ANCHOR-CI β€” the Alliance of National Councils for Homeland Operational Resilience for Critical Infrastructure. This is the replacement for the public-private information sharing council that was shut down over a year ago. And separately, OMB Director Russell Vought has signaled openness to re-staffing CISA with roughly 600 personnel after deep cuts.

                      Jordan: So the government broke the information sharing mechanism, let CISA atrophy, and is now trying to rebuild both. I'll skip the editorial on the wisdom of that sequence. What matters for CISOs is whether the replacement is actually functional or just a rebrand.

                      Alex: If you're in a critical infrastructure sector β€” energy, financial services, healthcare, water, transportation β€” you need to evaluate whether your organization should engage with ANCHOR-CI. The original council, for all its imperfections, was a real channel for actionable threat intelligence. Its absence has been felt. If this replacement can deliver even partial capability, it's worth participating.

                      Jordan: On the CISA re-staffing, 600 people is meaningful. CISA's advisory and incident response capacity was genuinely degraded by the cuts. If those positions come back, the agency's value as a resource to enterprise security programs improves. But staffing decisions are slow, and the threat environment isn't waiting.

                      Alex: Alright, let's talk about what we're watching. Jordan, when you look at this week's landscape, what's the thread?

                      Jordan: It's convergence under pressure. You've got active exploitation campaigns on Oracle, a zero-day dump accelerating the attacker's advantage, a massive automated campaign against cloud control planes, and a wave of breaches in Japan suggesting supply chain compromise. At the same time, the institutional infrastructure that's supposed to help β€” DHS, CISA, public-private coordination β€” is being rebuilt mid-crisis. And the technology landscape is shifting under everyone's feet with quantum timelines compressing and AI capabilities expanding. CISOs are being asked to manage compounding, simultaneous risk with structures that are still under construction.

                      Alex: I'd add that the Oracle situation specifically is something to watch over the next two weeks. Two product lines under active exploitation, confirmed victims at the scale of Nissan β€” this campaign isn't done. If you're an Oracle shop, treat this as your top priority this week.

                      Jordan: And keep an eye on what comes out of that zero-day cache. The exploit brokers and opportunistic actors are going to move fast. Your threat intel feeds should be on fire right now. If they're not, ask why.

                      Alex: That's our show for today. Show notes, links to every story we covered, and our source list are all at cleartext.fm. We'll be back tomorrow. Stay sharp.

                      Jordan: See you then.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-01.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext