
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 10 stories across 4 topic areas, including: US lifts export controls on Anthropicβs frontier cybersecurity AI models; Srsly Risky Biz: America won't beat the distillation ecosystem; AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack.
The Record (Recorded Future) Β· Jul 01 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: The US government's decision to lift export controls on Anthropic's frontier cybersecurity AI modelsβwith new guardrailsβreshapes the global AI security landscape and raises questions about adversary access to powerful offensive and defensive AI capabilities.
π Read full article
Risky Business News Β· Jul 02 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Chinese AI labs exploiting a grey market for US model access logs to conduct distillation attacks represents a structural intelligence threat that could erode the US's AI security edgeβdirectly relevant to CISOs evaluating AI supply chain risk and model provenance.
π Read full article
The Hacker News Β· Jul 02 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: This marks a strategic inflection point: an LLM-driven agent autonomously executed a full ransomware attack chain from initial access through encryption, signaling that AI-accelerated attacks will compress defender response windows and stress-test current detection and response architectures.
π Read full article
BleepingComputer Β· Jul 01 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: An 81-million-attempt password-spraying campaign against Microsoft 365 over just two weeks underscores the industrial scale of credential attacks on enterprise identity infrastructure, making this an urgent prompt to review MFA enforcement, conditional access policies, and legacy authentication blocking.
π Read full article
BleepingComputer Β· Jul 01 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The Homeland Security Information Network is a sensitive government-private sector intelligence-sharing platform; its compromise potentially exposes threat intelligence shared by enterprise partners and signals attackers may have visibility into federal-private security coordination.
π Read full article
The Hacker News Β· Jul 02 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: Mass FortiGate credential theft is now directly tied to active ransomware deployment pipelines, meaning organizations with exposed Fortinet infrastructure face imminent ransomware risk and should treat stolen credentials as already weaponized.
π Read full article
The Record (Recorded Future) Β· Jul 01 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A cluster of simultaneous breach disclosures across major Japanese multinationalsβspanning insurance, consumer goods, manufacturing, and telecomβsuggests coordinated or opportunistic targeting of Japanese enterprise infrastructure with potential supply chain and partner notification implications for global organizations.
π Read full article
BleepingComputer Β· Jul 02 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: ShinyHunters' breach of a major medical device manufacturer highlights persistent third-party and cloud storage risk in healthcare; CISOs in regulated industries should review vendor access controls and assess exposure through shared cloud environments this threat actor has repeatedly targeted.
π Read full article
The Hacker News Β· Jul 02 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A high-severity RCE vulnerability in Microsoft SharePoint Server is now confirmed actively exploited and added to CISA's KEV catalog, requiring immediate remediation given SharePoint's near-universal deployment in enterprise environments as a document collaboration and intranet platform.
π Read full article
BleepingComputer Β· Jul 01 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: With over 900 Oracle EBS instances exposed and under active attack, enterprises running Oracle Payments and related EBS modules face immediate financial system compromise risk, warranting emergency inventory and remediation checks.
π Read full article
Alex: Welcome to Cleartext. It's Thursday, July 2nd, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. So, Sysdig just published research on what they're calling the first documented ransomware attack run end-to-end by an AI agent. No human operator in the loop. The LLM handled initial access, credential theft, lateral movement, encryption, and data wiping. All of it. Autonomously. We've been warning about this inflection point for two years, and now we're here.
Alex: Yeah, we're going to dig into that. We've also got the US lifting export controls on Anthropic's frontier cybersecurity AI models, a confirmed breach of DHS's intelligence-sharing platform, a SharePoint RCE that just hit CISA's KEV catalog, and FortiBleed credentials now directly linked to active ransomware pipelines. Plus a massive password-spraying campaign hitting Microsoft 365 at industrial scale. Lot to cover. Let's get into it.
Jordan: Let's start with the AI stories because they're all connected. The Commerce Department reached an agreement with Anthropic to lift export controls on their Mythos and Fable models, the frontier cybersecurity AI systems. There are new guardrails and classifiers as part of the deal, but the fundamental shift here is that these models are now going to be available to allied nations and potentially beyond.
Alex: And this is the core tension that US policymakers have been wrestling with for over a year. You maintain AI dominance by getting your models deployed everywhere, adopted everywhere, embedded in allied security architectures. But the moment you loosen the reins, you lose some control over who ultimately gets access to the capabilities. It's a classic dual-use problem, except the speed of proliferation with software is fundamentally different from hardware export controls.
Jordan: Which connects directly to the Risky Business reporting on Chinese AI labs running distillation attacks against US models. The mechanism is clever and frankly hard to counter. Chinese consumers buy legitimate access to US models through resellers. The logs of those interactions, the request-response pairs, become training data for distillation. Chinese labs may actually be subsidizing this grey market specifically to harvest those logs at scale.
Alex: So for CISOs, there are two things to think about here. First, model provenance. If you're deploying AI security tools, you need to understand where the underlying model came from and whether it's been influenced by distilled capabilities from frontier models that were supposed to be controlled. Second, if your organization is using any of these models in sensitive contexts, the logs of your interactions could be feeding adversary training pipelines through channels you have zero visibility into.
Jordan: Right. The supply chain risk here isn't the traditional one. It's not a compromised library or a backdoored update. It's the intellectual output of your interactions with AI models becoming a training input for adversary systems. That's a novel category of data leakage that most security programs aren't structured to detect or prevent.
Alex: Let's pivot to the JADEPUFFER story because this is genuinely significant. Sysdig's threat research team documented a threat actor using an LLM-driven agent to execute a full ransomware kill chain against a production database. The initial access was through the Langflow RCE vulnerability, and from there the agent handled everything autonomously.
Jordan: What makes this different from the AI-assisted attacks we've seen before is the absence of human decision-making in the loop. Previous cases involved operators using AI to write better phishing emails or generate exploit code, essentially AI as a productivity tool for attackers. This is AI as the operator. The implications for defenders are significant because the attack tempo changes fundamentally.
Alex: That's the board-level conversation. When your adversary's attack chain is fully automated and can execute in minutes rather than hours or days, your detection and response windows compress dramatically. The mean time to respond that you've been reporting to your board may no longer be fast enough. And the economics shift too. The marginal cost of launching an additional attack drops toward zero.
Jordan: CISOs should be asking their SOC leaders a very specific question right now: if an attack progresses from initial access to data encryption in under fifteen minutes with no human pauses for reconnaissance or decision-making, does our detection and response architecture actually catch it in time? For most organizations, the honest answer is no.
Alex: Let's move to the DHS breach. The Homeland Security Information Network, HSIN, has been confirmed compromised. This is the platform that federal, state, local, and private-sector partners use to share sensitive security information.
Jordan: This is the kind of breach that has second-order effects that are hard to scope. HSIN is where threat intelligence gets shared between government and critical infrastructure operators. If an adversary has visibility into what defenders know, what indicators they're tracking, what coordination is happening, that's an intelligence advantage that undermines the entire collective defense model. It's not just about data exposure. It's about the attacker understanding the defender's playbook.
Alex: If your organization participates in any government information-sharing program, and many critical infrastructure companies do, you should be reviewing what you've shared through those channels and assessing whether that information could be weaponized against your own defenses. Also worth considering whether intelligence you received through HSIN may have been manipulated or whether the breach timeline overlaps with any anomalies in your own environment.
Jordan: Now let's talk about the two vulnerability stories because they both demand immediate action. CVE-2026-45659, the SharePoint Server RCE, just hit CISA's KEV catalog. CVSS 8.8, deserialization of untrusted data, confirmed active exploitation. The patch has been available since May.
Alex: If you haven't patched SharePoint since May, you are actively being targeted. There's no ambiguity here. SharePoint is in virtually every enterprise environment. It holds sensitive documents, it's integrated with Active Directory, it's often internet-facing or accessible through VPN. This is a priority-one remediation item for today, not next week's change window.
Jordan: And separately, over 900 Oracle E-Business Suite instances are exposed to the internet and under active attack. The critical flaw could let attackers compromise Oracle Payments. If you're running EBS, particularly the Payments module, you need an emergency inventory of what's exposed and whether patches have been applied. Financial system compromise is the kind of thing that gets people fired and companies sued.
Alex: Let's connect FortiBleed into this conversation because it illustrates how vulnerability exploitation feeds directly into the ransomware economy. The FortiBleed credential theft campaign is now directly attributed to operators running both INC and Lynx ransomware operations. An operator tied to FortiBleed infrastructure was found actively working negotiation panels for both groups.
Jordan: So the pipeline is: mass exploit FortiGate devices, harvest credentials, stage them for follow-on intrusions, deploy ransomware. If your organization has any Fortinet infrastructure that was exposed during the FortiBleed campaign window, you should treat those credentials as compromised and already in the hands of ransomware operators. Not potentially compromised. Compromised. Rotate everything. Hunt for persistence.
Alex: And speaking of credential attacks at scale, the Microsoft 365 password-spraying campaign is worth flagging. Eighty-one million login attempts over two weeks against enterprise M365 environments. The volume and distribution suggest botnet-driven infrastructure specifically designed to stay under per-IP rate-limiting thresholds.
Jordan: This is a good reminder that MFA is necessary but not sufficient. Legacy authentication protocols that don't support MFA are the soft underbelly here. Conditional access policies need to block legacy auth completely. And if you're not monitoring for distributed, low-and-slow credential attacks across your identity infrastructure, you're likely not seeing this kind of campaign until after they've found a valid credential pair.
Alex: Two more items to cover quickly. Four major Japanese companies, Aflac's Tokyo unit, Sapporo, Nidec, and KDDI, all disclosed breaches simultaneously. Spanning insurance, consumer goods, manufacturing, and telecom. Whether this is coordinated targeting or coincidental timing, if you have Japanese subsidiaries or supply chain relationships with these companies, review your exposure and your notification obligations under both Japanese and your home jurisdiction's regulations.
Jordan: And Medtronic is notifying customers of a ShinyHunters breach. ShinyHunters continues to be prolific in targeting cloud storage environments. For CISOs in healthcare and regulated industries, this is another data point reinforcing that your third-party risk management program needs specific focus on cloud storage configurations and vendor access controls. ShinyHunters has a playbook, and it keeps working.
Alex: So Jordan, stepping back from today's stories, what's the emerging theme you're watching?
Jordan: The theme is compression. Attack timelines are compressing because of AI automation. The window between vulnerability disclosure and active exploitation is compressing. The pipeline from credential theft to ransomware deployment is compressing. And the geopolitical competition around AI capabilities is compressing the timeline for adversaries to match our frontier model capabilities. Every one of these trends pressures the same thing: the defender's decision cycle.
Alex: And that has direct implications for how we structure our security programs. The traditional model of weekly patch cycles, quarterly risk reviews, annual tabletop exercises, those cadences were designed for a threat landscape that moved slower than this one. I'm not saying abandon structure, but CISOs need to be honest with their boards about whether their operational tempo matches the threat tempo. Because right now, for a lot of organizations, it doesn't.
Jordan: The AI agent ransomware story is a signal, not an anomaly. The next twelve months are going to produce more of these. And the organizations that survive them will be the ones that invested in detection and response architectures that don't depend on the attacker being slow.
Alex: That's a good place to leave it. That's Cleartext for Thursday, July 2nd, 2026. Show notes and links to every story we covered are at cleartext.fm. We're back tomorrow.
Jordan: See you then.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-02.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 10 stories across 4 topic areas, including: US lifts export controls on Anthropicβs frontier cybersecurity AI models; Srsly Risky Biz: America won't beat the distillation ecosystem; AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack.
The Record (Recorded Future) Β· Jul 01 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: The US government's decision to lift export controls on Anthropic's frontier cybersecurity AI modelsβwith new guardrailsβreshapes the global AI security landscape and raises questions about adversary access to powerful offensive and defensive AI capabilities.
π Read full article
Risky Business News Β· Jul 02 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Chinese AI labs exploiting a grey market for US model access logs to conduct distillation attacks represents a structural intelligence threat that could erode the US's AI security edgeβdirectly relevant to CISOs evaluating AI supply chain risk and model provenance.
π Read full article
The Hacker News Β· Jul 02 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: This marks a strategic inflection point: an LLM-driven agent autonomously executed a full ransomware attack chain from initial access through encryption, signaling that AI-accelerated attacks will compress defender response windows and stress-test current detection and response architectures.
π Read full article
BleepingComputer Β· Jul 01 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: An 81-million-attempt password-spraying campaign against Microsoft 365 over just two weeks underscores the industrial scale of credential attacks on enterprise identity infrastructure, making this an urgent prompt to review MFA enforcement, conditional access policies, and legacy authentication blocking.
π Read full article
BleepingComputer Β· Jul 01 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The Homeland Security Information Network is a sensitive government-private sector intelligence-sharing platform; its compromise potentially exposes threat intelligence shared by enterprise partners and signals attackers may have visibility into federal-private security coordination.
π Read full article
The Hacker News Β· Jul 02 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: Mass FortiGate credential theft is now directly tied to active ransomware deployment pipelines, meaning organizations with exposed Fortinet infrastructure face imminent ransomware risk and should treat stolen credentials as already weaponized.
π Read full article
The Record (Recorded Future) Β· Jul 01 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A cluster of simultaneous breach disclosures across major Japanese multinationalsβspanning insurance, consumer goods, manufacturing, and telecomβsuggests coordinated or opportunistic targeting of Japanese enterprise infrastructure with potential supply chain and partner notification implications for global organizations.
π Read full article
BleepingComputer Β· Jul 02 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: ShinyHunters' breach of a major medical device manufacturer highlights persistent third-party and cloud storage risk in healthcare; CISOs in regulated industries should review vendor access controls and assess exposure through shared cloud environments this threat actor has repeatedly targeted.
π Read full article
The Hacker News Β· Jul 02 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A high-severity RCE vulnerability in Microsoft SharePoint Server is now confirmed actively exploited and added to CISA's KEV catalog, requiring immediate remediation given SharePoint's near-universal deployment in enterprise environments as a document collaboration and intranet platform.
π Read full article
BleepingComputer Β· Jul 01 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: With over 900 Oracle EBS instances exposed and under active attack, enterprises running Oracle Payments and related EBS modules face immediate financial system compromise risk, warranting emergency inventory and remediation checks.
π Read full article
Alex: Welcome to Cleartext. It's Thursday, July 2nd, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. So, Sysdig just published research on what they're calling the first documented ransomware attack run end-to-end by an AI agent. No human operator in the loop. The LLM handled initial access, credential theft, lateral movement, encryption, and data wiping. All of it. Autonomously. We've been warning about this inflection point for two years, and now we're here.
Alex: Yeah, we're going to dig into that. We've also got the US lifting export controls on Anthropic's frontier cybersecurity AI models, a confirmed breach of DHS's intelligence-sharing platform, a SharePoint RCE that just hit CISA's KEV catalog, and FortiBleed credentials now directly linked to active ransomware pipelines. Plus a massive password-spraying campaign hitting Microsoft 365 at industrial scale. Lot to cover. Let's get into it.
Jordan: Let's start with the AI stories because they're all connected. The Commerce Department reached an agreement with Anthropic to lift export controls on their Mythos and Fable models, the frontier cybersecurity AI systems. There are new guardrails and classifiers as part of the deal, but the fundamental shift here is that these models are now going to be available to allied nations and potentially beyond.
Alex: And this is the core tension that US policymakers have been wrestling with for over a year. You maintain AI dominance by getting your models deployed everywhere, adopted everywhere, embedded in allied security architectures. But the moment you loosen the reins, you lose some control over who ultimately gets access to the capabilities. It's a classic dual-use problem, except the speed of proliferation with software is fundamentally different from hardware export controls.
Jordan: Which connects directly to the Risky Business reporting on Chinese AI labs running distillation attacks against US models. The mechanism is clever and frankly hard to counter. Chinese consumers buy legitimate access to US models through resellers. The logs of those interactions, the request-response pairs, become training data for distillation. Chinese labs may actually be subsidizing this grey market specifically to harvest those logs at scale.
Alex: So for CISOs, there are two things to think about here. First, model provenance. If you're deploying AI security tools, you need to understand where the underlying model came from and whether it's been influenced by distilled capabilities from frontier models that were supposed to be controlled. Second, if your organization is using any of these models in sensitive contexts, the logs of your interactions could be feeding adversary training pipelines through channels you have zero visibility into.
Jordan: Right. The supply chain risk here isn't the traditional one. It's not a compromised library or a backdoored update. It's the intellectual output of your interactions with AI models becoming a training input for adversary systems. That's a novel category of data leakage that most security programs aren't structured to detect or prevent.
Alex: Let's pivot to the JADEPUFFER story because this is genuinely significant. Sysdig's threat research team documented a threat actor using an LLM-driven agent to execute a full ransomware kill chain against a production database. The initial access was through the Langflow RCE vulnerability, and from there the agent handled everything autonomously.
Jordan: What makes this different from the AI-assisted attacks we've seen before is the absence of human decision-making in the loop. Previous cases involved operators using AI to write better phishing emails or generate exploit code, essentially AI as a productivity tool for attackers. This is AI as the operator. The implications for defenders are significant because the attack tempo changes fundamentally.
Alex: That's the board-level conversation. When your adversary's attack chain is fully automated and can execute in minutes rather than hours or days, your detection and response windows compress dramatically. The mean time to respond that you've been reporting to your board may no longer be fast enough. And the economics shift too. The marginal cost of launching an additional attack drops toward zero.
Jordan: CISOs should be asking their SOC leaders a very specific question right now: if an attack progresses from initial access to data encryption in under fifteen minutes with no human pauses for reconnaissance or decision-making, does our detection and response architecture actually catch it in time? For most organizations, the honest answer is no.
Alex: Let's move to the DHS breach. The Homeland Security Information Network, HSIN, has been confirmed compromised. This is the platform that federal, state, local, and private-sector partners use to share sensitive security information.
Jordan: This is the kind of breach that has second-order effects that are hard to scope. HSIN is where threat intelligence gets shared between government and critical infrastructure operators. If an adversary has visibility into what defenders know, what indicators they're tracking, what coordination is happening, that's an intelligence advantage that undermines the entire collective defense model. It's not just about data exposure. It's about the attacker understanding the defender's playbook.
Alex: If your organization participates in any government information-sharing program, and many critical infrastructure companies do, you should be reviewing what you've shared through those channels and assessing whether that information could be weaponized against your own defenses. Also worth considering whether intelligence you received through HSIN may have been manipulated or whether the breach timeline overlaps with any anomalies in your own environment.
Jordan: Now let's talk about the two vulnerability stories because they both demand immediate action. CVE-2026-45659, the SharePoint Server RCE, just hit CISA's KEV catalog. CVSS 8.8, deserialization of untrusted data, confirmed active exploitation. The patch has been available since May.
Alex: If you haven't patched SharePoint since May, you are actively being targeted. There's no ambiguity here. SharePoint is in virtually every enterprise environment. It holds sensitive documents, it's integrated with Active Directory, it's often internet-facing or accessible through VPN. This is a priority-one remediation item for today, not next week's change window.
Jordan: And separately, over 900 Oracle E-Business Suite instances are exposed to the internet and under active attack. The critical flaw could let attackers compromise Oracle Payments. If you're running EBS, particularly the Payments module, you need an emergency inventory of what's exposed and whether patches have been applied. Financial system compromise is the kind of thing that gets people fired and companies sued.
Alex: Let's connect FortiBleed into this conversation because it illustrates how vulnerability exploitation feeds directly into the ransomware economy. The FortiBleed credential theft campaign is now directly attributed to operators running both INC and Lynx ransomware operations. An operator tied to FortiBleed infrastructure was found actively working negotiation panels for both groups.
Jordan: So the pipeline is: mass exploit FortiGate devices, harvest credentials, stage them for follow-on intrusions, deploy ransomware. If your organization has any Fortinet infrastructure that was exposed during the FortiBleed campaign window, you should treat those credentials as compromised and already in the hands of ransomware operators. Not potentially compromised. Compromised. Rotate everything. Hunt for persistence.
Alex: And speaking of credential attacks at scale, the Microsoft 365 password-spraying campaign is worth flagging. Eighty-one million login attempts over two weeks against enterprise M365 environments. The volume and distribution suggest botnet-driven infrastructure specifically designed to stay under per-IP rate-limiting thresholds.
Jordan: This is a good reminder that MFA is necessary but not sufficient. Legacy authentication protocols that don't support MFA are the soft underbelly here. Conditional access policies need to block legacy auth completely. And if you're not monitoring for distributed, low-and-slow credential attacks across your identity infrastructure, you're likely not seeing this kind of campaign until after they've found a valid credential pair.
Alex: Two more items to cover quickly. Four major Japanese companies, Aflac's Tokyo unit, Sapporo, Nidec, and KDDI, all disclosed breaches simultaneously. Spanning insurance, consumer goods, manufacturing, and telecom. Whether this is coordinated targeting or coincidental timing, if you have Japanese subsidiaries or supply chain relationships with these companies, review your exposure and your notification obligations under both Japanese and your home jurisdiction's regulations.
Jordan: And Medtronic is notifying customers of a ShinyHunters breach. ShinyHunters continues to be prolific in targeting cloud storage environments. For CISOs in healthcare and regulated industries, this is another data point reinforcing that your third-party risk management program needs specific focus on cloud storage configurations and vendor access controls. ShinyHunters has a playbook, and it keeps working.
Alex: So Jordan, stepping back from today's stories, what's the emerging theme you're watching?
Jordan: The theme is compression. Attack timelines are compressing because of AI automation. The window between vulnerability disclosure and active exploitation is compressing. The pipeline from credential theft to ransomware deployment is compressing. And the geopolitical competition around AI capabilities is compressing the timeline for adversaries to match our frontier model capabilities. Every one of these trends pressures the same thing: the defender's decision cycle.
Alex: And that has direct implications for how we structure our security programs. The traditional model of weekly patch cycles, quarterly risk reviews, annual tabletop exercises, those cadences were designed for a threat landscape that moved slower than this one. I'm not saying abandon structure, but CISOs need to be honest with their boards about whether their operational tempo matches the threat tempo. Because right now, for a lot of organizations, it doesn't.
Jordan: The AI agent ransomware story is a signal, not an anomaly. The next twelve months are going to produce more of these. And the organizations that survive them will be the ones that invested in detection and response architectures that don't depend on the attacker being slow.
Alex: That's a good place to leave it. That's Cleartext for Thursday, July 2nd, 2026. Show notes and links to every story we covered are at cleartext.fm. We're back tomorrow.
Jordan: See you then.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-02.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.