Cleartext

Cleartext – July 02, 2026


Listen Later

Cleartext – July 02, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 4 topic areas, including: US lifts export controls on Anthropic’s frontier cybersecurity AI models; Srsly Risky Biz: America won't beat the distillation ecosystem; AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack.

Stories Covered
🌍 Geopolitical
US lifts export controls on Anthropic’s frontier cybersecurity AI models

The Record (Recorded Future) Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

Why it matters to CISOs: The US government's decision to lift export controls on Anthropic's frontier cybersecurity AI modelsβ€”with new guardrailsβ€”reshapes the global AI security landscape and raises questions about adversary access to powerful offensive and defensive AI capabilities.

  • The US Commerce Department reached an agreement with Anthropic to lift export controls on its Mythos and Fable AI models
  • Release will be conditional on new guardrails and classifiers negotiated between Anthropic and the government
  • The decision reflects broader US policy tension between maintaining AI dominance and restricting adversary access to frontier models
  • πŸ“– Read full article

    Srsly Risky Biz: America won't beat the distillation ecosystem

    Risky Business News Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

    Why it matters to CISOs: Chinese AI labs exploiting a grey market for US model access logs to conduct distillation attacks represents a structural intelligence threat that could erode the US's AI security edgeβ€”directly relevant to CISOs evaluating AI supply chain risk and model provenance.

    • Chinese AI labs are allegedly conducting 'distillation attacks' using logs from grey-market access to US AI models including via consumer resellers
    • The grey market may be subsidized by Chinese AI labs purchasing user request-response logs as training data inputs
    • The episode also covers the possibility that the Jaguar Land Rover hack was conducted by Russian state-adjacent actors, illustrating ongoing nation-state IP theft targeting manufacturers
    • πŸ“– Read full article

      πŸ“‘ Macro Trends
      AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

      The Hacker News Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

      Why it matters to CISOs: This marks a strategic inflection point: an LLM-driven agent autonomously executed a full ransomware attack chain from initial access through encryption, signaling that AI-accelerated attacks will compress defender response windows and stress-test current detection and response architectures.

      • Sysdig's Threat Research Team identified threat actor JADEPUFFER using an AI agent to conduct an end-to-end ransomware attack on a production database
      • The LLM handled breach entry, credential theft, lateral movement, and data encryption/wiping without human operator intervention
      • Sysdig describes this as the first documented case of ransomware run start-to-finish by an AI agent, exploiting the Langflow RCE vulnerability as the initial access vector
      • πŸ“– Read full article

        Hackers target Microsoft 365 accounts with 81 million login attempts

        BleepingComputer Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

        Why it matters to CISOs: An 81-million-attempt password-spraying campaign against Microsoft 365 over just two weeks underscores the industrial scale of credential attacks on enterprise identity infrastructure, making this an urgent prompt to review MFA enforcement, conditional access policies, and legacy authentication blocking.

        • A single password-spraying campaign generated over 81 million Microsoft 365 login attempts in a two-week period
        • The campaign targets enterprise M365 environments, which are ubiquitous across large organizations
        • The scale indicates automated, likely botnet-driven infrastructure designed to evade per-IP rate limiting and detection thresholds
        • πŸ“– Read full article

          πŸ”“ Data Breach
          DHS confirms hackers breached HSIN info-sharing platform

          BleepingComputer Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

          Why it matters to CISOs: The Homeland Security Information Network is a sensitive government-private sector intelligence-sharing platform; its compromise potentially exposes threat intelligence shared by enterprise partners and signals attackers may have visibility into federal-private security coordination.

          • DHS confirmed a cyberattack compromised HSIN, a platform used by federal, state, local, and private-sector partners
          • HSIN is used for sharing sensitive security information across government and critical industry sectors
          • An active investigation is underway into the scope and attribution of the breach
          • πŸ“– Read full article

            FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

            The Hacker News Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

            Why it matters to CISOs: Mass FortiGate credential theft is now directly tied to active ransomware deployment pipelines, meaning organizations with exposed Fortinet infrastructure face imminent ransomware risk and should treat stolen credentials as already weaponized.

            • FortiBleed campaign attributed to operators running both INC and Lynx ransomware operations
            • An operator tied to FortiBleed infrastructure was found actively working negotiation panels for both ransomware groups
            • Mass FortiGate credential theft is being used as a staging ground for follow-on network intrusions and ransomware deployment
            • πŸ“– Read full article

              Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches

              The Record (Recorded Future) Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

              Why it matters to CISOs: A cluster of simultaneous breach disclosures across major Japanese multinationalsβ€”spanning insurance, consumer goods, manufacturing, and telecomβ€”suggests coordinated or opportunistic targeting of Japanese enterprise infrastructure with potential supply chain and partner notification implications for global organizations.

              • Aflac's Tokyo arm, brewer Sapporo, manufacturer Nidec, and telecom KDDI all disclosed recent data breaches
              • The concurrent disclosures across diverse sectors suggest broad targeting of Japanese enterprise organizations
              • Global enterprises with Japanese subsidiaries or supply chain relationships may face secondary exposure or regulatory notification obligations
              • πŸ“– Read full article

                Medtronic notifies customers impacted by ShinyHunters data breach

                BleepingComputer Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                Why it matters to CISOs: ShinyHunters' breach of a major medical device manufacturer highlights persistent third-party and cloud storage risk in healthcare; CISOs in regulated industries should review vendor access controls and assess exposure through shared cloud environments this threat actor has repeatedly targeted.

                • Medtronic is notifying affected customers following unauthorized access to personal data attributed to the ShinyHunters threat group
                • ShinyHunters has a track record of large-scale data theft from cloud storage environments across multiple industries
                • The breach affects a critical healthcare device company whose customer data may include sensitive health and identity information
                • πŸ“– Read full article

                  🚨 Critical Vulnerability
                  SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

                  The Hacker News Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                  Why it matters to CISOs: A high-severity RCE vulnerability in Microsoft SharePoint Server is now confirmed actively exploited and added to CISA's KEV catalog, requiring immediate remediation given SharePoint's near-universal deployment in enterprise environments as a document collaboration and intranet platform.

                  • CVE-2026-45659 carries a CVSS score of 8.8 and enables remote code execution via deserialization of untrusted data
                  • CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 2, 2026, citing confirmed active exploitation
                  • The vulnerability was patched in May 2026, meaning organizations that have not applied the patch are exposed
                  • πŸ“– Read full article

                    Over 900 Oracle E-Business instances exposed to ongoing attacks

                    BleepingComputer Β· Jul 01 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                    Why it matters to CISOs: With over 900 Oracle EBS instances exposed and under active attack, enterprises running Oracle Payments and related EBS modules face immediate financial system compromise risk, warranting emergency inventory and remediation checks.

                    • Over 900 Oracle E-Business Suite instances have been identified as exposed to the internet amid ongoing attacks
                    • Successful exploitation of the critical flaw could allow attackers to compromise Oracle Payments
                    • Researchers have flagged the vulnerability as under immediate threat with active exploitation attempts observed
                    • πŸ“– Read full article

                      Further Reading
                      • 🌍 US lifts export controls on Anthropic’s frontier cybersecurity AI models β€” The Record (Recorded Future)
                      • 🌍 Srsly Risky Biz: America won't beat the distillation ecosystem β€” Risky Business News
                      • πŸ“‘ AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack β€” The Hacker News
                      • πŸ“‘ Hackers target Microsoft 365 accounts with 81 million login attempts β€” BleepingComputer
                      • πŸ”“ DHS confirms hackers breached HSIN info-sharing platform β€” BleepingComputer
                      • πŸ”“ FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations β€” The Hacker News
                      • πŸ”“ Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches β€” The Record (Recorded Future)
                      • πŸ”“ Medtronic notifies customers impacted by ShinyHunters data breach β€” BleepingComputer
                      • 🚨 SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation β€” The Hacker News
                      • 🚨 Over 900 Oracle E-Business instances exposed to ongoing attacks β€” BleepingComputer
                      • Full Transcript
                        Click to expand full episode transcript

                        Alex: Welcome to Cleartext. It's Thursday, July 2nd, 2026. I'm Alex Chen.

                        Jordan: And I'm Jordan Reeves. So, Sysdig just published research on what they're calling the first documented ransomware attack run end-to-end by an AI agent. No human operator in the loop. The LLM handled initial access, credential theft, lateral movement, encryption, and data wiping. All of it. Autonomously. We've been warning about this inflection point for two years, and now we're here.

                        Alex: Yeah, we're going to dig into that. We've also got the US lifting export controls on Anthropic's frontier cybersecurity AI models, a confirmed breach of DHS's intelligence-sharing platform, a SharePoint RCE that just hit CISA's KEV catalog, and FortiBleed credentials now directly linked to active ransomware pipelines. Plus a massive password-spraying campaign hitting Microsoft 365 at industrial scale. Lot to cover. Let's get into it.

                        Jordan: Let's start with the AI stories because they're all connected. The Commerce Department reached an agreement with Anthropic to lift export controls on their Mythos and Fable models, the frontier cybersecurity AI systems. There are new guardrails and classifiers as part of the deal, but the fundamental shift here is that these models are now going to be available to allied nations and potentially beyond.

                        Alex: And this is the core tension that US policymakers have been wrestling with for over a year. You maintain AI dominance by getting your models deployed everywhere, adopted everywhere, embedded in allied security architectures. But the moment you loosen the reins, you lose some control over who ultimately gets access to the capabilities. It's a classic dual-use problem, except the speed of proliferation with software is fundamentally different from hardware export controls.

                        Jordan: Which connects directly to the Risky Business reporting on Chinese AI labs running distillation attacks against US models. The mechanism is clever and frankly hard to counter. Chinese consumers buy legitimate access to US models through resellers. The logs of those interactions, the request-response pairs, become training data for distillation. Chinese labs may actually be subsidizing this grey market specifically to harvest those logs at scale.

                        Alex: So for CISOs, there are two things to think about here. First, model provenance. If you're deploying AI security tools, you need to understand where the underlying model came from and whether it's been influenced by distilled capabilities from frontier models that were supposed to be controlled. Second, if your organization is using any of these models in sensitive contexts, the logs of your interactions could be feeding adversary training pipelines through channels you have zero visibility into.

                        Jordan: Right. The supply chain risk here isn't the traditional one. It's not a compromised library or a backdoored update. It's the intellectual output of your interactions with AI models becoming a training input for adversary systems. That's a novel category of data leakage that most security programs aren't structured to detect or prevent.

                        Alex: Let's pivot to the JADEPUFFER story because this is genuinely significant. Sysdig's threat research team documented a threat actor using an LLM-driven agent to execute a full ransomware kill chain against a production database. The initial access was through the Langflow RCE vulnerability, and from there the agent handled everything autonomously.

                        Jordan: What makes this different from the AI-assisted attacks we've seen before is the absence of human decision-making in the loop. Previous cases involved operators using AI to write better phishing emails or generate exploit code, essentially AI as a productivity tool for attackers. This is AI as the operator. The implications for defenders are significant because the attack tempo changes fundamentally.

                        Alex: That's the board-level conversation. When your adversary's attack chain is fully automated and can execute in minutes rather than hours or days, your detection and response windows compress dramatically. The mean time to respond that you've been reporting to your board may no longer be fast enough. And the economics shift too. The marginal cost of launching an additional attack drops toward zero.

                        Jordan: CISOs should be asking their SOC leaders a very specific question right now: if an attack progresses from initial access to data encryption in under fifteen minutes with no human pauses for reconnaissance or decision-making, does our detection and response architecture actually catch it in time? For most organizations, the honest answer is no.

                        Alex: Let's move to the DHS breach. The Homeland Security Information Network, HSIN, has been confirmed compromised. This is the platform that federal, state, local, and private-sector partners use to share sensitive security information.

                        Jordan: This is the kind of breach that has second-order effects that are hard to scope. HSIN is where threat intelligence gets shared between government and critical infrastructure operators. If an adversary has visibility into what defenders know, what indicators they're tracking, what coordination is happening, that's an intelligence advantage that undermines the entire collective defense model. It's not just about data exposure. It's about the attacker understanding the defender's playbook.

                        Alex: If your organization participates in any government information-sharing program, and many critical infrastructure companies do, you should be reviewing what you've shared through those channels and assessing whether that information could be weaponized against your own defenses. Also worth considering whether intelligence you received through HSIN may have been manipulated or whether the breach timeline overlaps with any anomalies in your own environment.

                        Jordan: Now let's talk about the two vulnerability stories because they both demand immediate action. CVE-2026-45659, the SharePoint Server RCE, just hit CISA's KEV catalog. CVSS 8.8, deserialization of untrusted data, confirmed active exploitation. The patch has been available since May.

                        Alex: If you haven't patched SharePoint since May, you are actively being targeted. There's no ambiguity here. SharePoint is in virtually every enterprise environment. It holds sensitive documents, it's integrated with Active Directory, it's often internet-facing or accessible through VPN. This is a priority-one remediation item for today, not next week's change window.

                        Jordan: And separately, over 900 Oracle E-Business Suite instances are exposed to the internet and under active attack. The critical flaw could let attackers compromise Oracle Payments. If you're running EBS, particularly the Payments module, you need an emergency inventory of what's exposed and whether patches have been applied. Financial system compromise is the kind of thing that gets people fired and companies sued.

                        Alex: Let's connect FortiBleed into this conversation because it illustrates how vulnerability exploitation feeds directly into the ransomware economy. The FortiBleed credential theft campaign is now directly attributed to operators running both INC and Lynx ransomware operations. An operator tied to FortiBleed infrastructure was found actively working negotiation panels for both groups.

                        Jordan: So the pipeline is: mass exploit FortiGate devices, harvest credentials, stage them for follow-on intrusions, deploy ransomware. If your organization has any Fortinet infrastructure that was exposed during the FortiBleed campaign window, you should treat those credentials as compromised and already in the hands of ransomware operators. Not potentially compromised. Compromised. Rotate everything. Hunt for persistence.

                        Alex: And speaking of credential attacks at scale, the Microsoft 365 password-spraying campaign is worth flagging. Eighty-one million login attempts over two weeks against enterprise M365 environments. The volume and distribution suggest botnet-driven infrastructure specifically designed to stay under per-IP rate-limiting thresholds.

                        Jordan: This is a good reminder that MFA is necessary but not sufficient. Legacy authentication protocols that don't support MFA are the soft underbelly here. Conditional access policies need to block legacy auth completely. And if you're not monitoring for distributed, low-and-slow credential attacks across your identity infrastructure, you're likely not seeing this kind of campaign until after they've found a valid credential pair.

                        Alex: Two more items to cover quickly. Four major Japanese companies, Aflac's Tokyo unit, Sapporo, Nidec, and KDDI, all disclosed breaches simultaneously. Spanning insurance, consumer goods, manufacturing, and telecom. Whether this is coordinated targeting or coincidental timing, if you have Japanese subsidiaries or supply chain relationships with these companies, review your exposure and your notification obligations under both Japanese and your home jurisdiction's regulations.

                        Jordan: And Medtronic is notifying customers of a ShinyHunters breach. ShinyHunters continues to be prolific in targeting cloud storage environments. For CISOs in healthcare and regulated industries, this is another data point reinforcing that your third-party risk management program needs specific focus on cloud storage configurations and vendor access controls. ShinyHunters has a playbook, and it keeps working.

                        Alex: So Jordan, stepping back from today's stories, what's the emerging theme you're watching?

                        Jordan: The theme is compression. Attack timelines are compressing because of AI automation. The window between vulnerability disclosure and active exploitation is compressing. The pipeline from credential theft to ransomware deployment is compressing. And the geopolitical competition around AI capabilities is compressing the timeline for adversaries to match our frontier model capabilities. Every one of these trends pressures the same thing: the defender's decision cycle.

                        Alex: And that has direct implications for how we structure our security programs. The traditional model of weekly patch cycles, quarterly risk reviews, annual tabletop exercises, those cadences were designed for a threat landscape that moved slower than this one. I'm not saying abandon structure, but CISOs need to be honest with their boards about whether their operational tempo matches the threat tempo. Because right now, for a lot of organizations, it doesn't.

                        Jordan: The AI agent ransomware story is a signal, not an anomaly. The next twelve months are going to produce more of these. And the organizations that survive them will be the ones that invested in detection and response architectures that don't depend on the attacker being slow.

                        Alex: That's a good place to leave it. That's Cleartext for Thursday, July 2nd, 2026. Show notes and links to every story we covered are at cleartext.fm. We're back tomorrow.

                        Jordan: See you then.

                        Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-02.

                        Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                        ...more
                        View all episodesView all episodes
                        Download on the App Store

                        CleartextBy Cleartext