Cleartext

Cleartext – July 03, 2026


Listen Later

Cleartext – July 03, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: Someone infected a spyware probe overseer with spyware; FBI Seizes NetNut Proxy Platform, Popa Botnet; Alleged longstanding member of Scattered Spider extradited to US.

Stories Covered
🌍 Geopolitical
Someone infected a spyware probe overseer with spyware

CyberScoop Β· Jul 03 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

Why it matters to CISOs: Citizen Lab's confirmation that a sitting EU lawmaker investigating commercial spyware was repeatedly targeted with Pegasus underscores the political weaponization of enterprise-grade surveillance tools and should inform executive and board mobile device security policies.

  • Citizen Lab forensically confirmed that MEP Stelios Kouloglou's device was infected twice with NSO Group's Pegasus spyware
  • The targeted politician was serving on the EU's PEGA Committee, which was established specifically to investigate abuses of commercial spyware
  • The incident demonstrates that state-level adversaries will target individuals in oversight roles, with implications for executive and legal counsel device security
  • πŸ“– Read full article

    FBI Seizes NetNut Proxy Platform, Popa Botnet

    Krebs on Security Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

    Why it matters to CISOs: The FBI's seizure of a two-million-device botnet operated through a publicly traded Israeli company illustrates how commercial proxy services can serve as threat actor infrastructure, with implications for enterprise threat intelligence and vendor due diligence.

    • The FBI seized hundreds of domains tied to NetNut, a residential proxy service run by Nasdaq-listed Alarum Technologies
    • The Popa botnet connected to NetNut had compromised at least two million devices, often without meaningful user consent
    • The takedown followed investigative reporting linking NetNut to botnet infrastructure used by cyber threat actors
    • πŸ“– Read full article

      πŸ“‘ Macro Trends
      Alleged longstanding member of Scattered Spider extradited to US

      CyberScoop Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

      Why it matters to CISOs: The extradition of a key Scattered Spider member signals continued law enforcement pressure on the group responsible for high-profile enterprise breaches, and reinforces the need for CISOs to maintain social engineering and SIM-swapping defenses even as the group's operational tempo may be disrupted.

      • Peter Stokes, alleged to be a longstanding Scattered Spider member, has been extradited to the United States to face federal charges
      • The group was connected to an $8 million ransom demand against a luxury jewelry retailer, which incurred at least $2 million in losses despite not paying
      • Scattered Spider is known for sophisticated social engineering, SIM swapping, and targeting enterprise help desks to gain initial access
      • πŸ“– Read full article

        πŸ”“ Data Breach
        US government says it got hacked β€” again

        TechCrunch Security Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

        Why it matters to CISOs: A breach of a DHS intelligence-sharing network with potential national security implications signals ongoing vulnerability in federal cyber infrastructure, raising questions about third-party data sharing risks and supply chain exposure for enterprise partners.

        • A top Senate Intelligence Committee Democrat confirmed a hack of a Homeland Security intelligence-sharing network
        • The information accessed may risk national security, according to the senator's warning
        • This follows a pattern of repeated US government network compromises
        • πŸ“– Read full article

          βš–οΈ Governance & Policy
          Supreme Court decision threatens EU-US data transfer agreement

          The Record (Recorded Future) Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

          Why it matters to CISOs: A legal challenge to the EU-US Data Privacy Framework could invalidate the primary mechanism enterprises rely on to transfer personal data across the Atlantic, forcing CISOs to urgently revisit data residency architectures and Standard Contractual Clauses as fallback.

          • Max Schrems and noyb have formally notified European officials of plans to sue to invalidate the EU-US Data Privacy Framework
          • A successful challenge would disrupt data transfers for thousands of US companies processing EU personal data
          • This follows the prior invalidation of Privacy Shield, suggesting a familiar legal trajectory with significant compliance consequences
          • πŸ“– Read full article

            Most cybersecurity workers have been told to conceal a breach, report finds

            Cybersecurity Dive Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

            Why it matters to CISOs: Evidence that security professionals are routinely pressured to conceal breaches creates direct personal legal liability for CISOs under SEC and other disclosure frameworks, and signals a governance gap that boards need to address urgently.

            • Bitdefender's annual survey found that a majority of cybersecurity workers have been instructed to conceal a breach from regulators or the public
            • US companies were simultaneously more confident in their defenses yet reported higher operational strain than international peers
            • The findings are particularly significant given SEC breach disclosure requirements and CISO personal liability exposure under current regulatory regimes
            • πŸ“– Read full article

              Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis

              The Record (Recorded Future) Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

              Why it matters to CISOs: The delay of the UK's National Cyber Action Plan creates near-term regulatory uncertainty for enterprises operating in the UK market and signals that strategic cyber policy commitments may slip further as political instability continues.

              • The UK National Cyber Action Plan, scheduled for Monday publication, has been postponed due to the Labour Party leadership crisis
              • The Labour leadership contest opens July 9, creating an indeterminate timeline for the plan's release
              • The delay affects enterprise planning around UK-specific cyber compliance obligations and government partnership frameworks
              • πŸ“– Read full article

                🚨 Critical Vulnerability
                FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs

                Dark Reading Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                Why it matters to CISOs: Threat actors who compromised thousands of Fortinet firewalls via FortiBleed are now monetizing that access through ransomware partnerships, and are also exploiting a Nextcloud zero-dayβ€”making this an active, escalating threat to enterprise perimeter infrastructure.

                • FortiBleed actors have established footholds in thousands of Fortinet firewalls and are now collaborating with INC and Lynx ransomware operations
                • Attackers are additionally leveraging a suspected Nextcloud zero-day vulnerability to expand access
                • The pivot from persistent access to active ransomware deployment significantly raises the risk level for any organization running affected Fortinet products
                • πŸ“– Read full article

                  Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

                  The Hacker News Β· Jul 02 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                  Why it matters to CISOs: Active exploitation of Citrix Bleed 2 (CVE-2025-5777) by the Anubis ransomware group for initial access, combined with BYOVD and supply chain credential abuse, represents an immediate threat to enterprises running Citrix NetScaler environments.

                  • Anubis ransomware affiliates are actively exploiting CVE-2025-5777 (Citrix Bleed 2) to gain initial access to enterprise environments
                  • Attack chains include BYOVD techniques and abuse of legitimate RMM tooling for lateral movement and persistence
                  • Supply chain credential theft is being used to broaden the attack surface beyond the initial Citrix entry point
                  • πŸ“– Read full article

                    Further Reading
                    • 🌍 Someone infected a spyware probe overseer with spyware β€” CyberScoop
                    • 🌍 FBI Seizes NetNut Proxy Platform, Popa Botnet β€” Krebs on Security
                    • πŸ“‘ Alleged longstanding member of Scattered Spider extradited to US β€” CyberScoop
                    • πŸ”“ US government says it got hacked β€” again β€” TechCrunch Security
                    • βš–οΈ Supreme Court decision threatens EU-US data transfer agreement β€” The Record (Recorded Future)
                    • βš–οΈ Most cybersecurity workers have been told to conceal a breach, report finds β€” Cybersecurity Dive
                    • βš–οΈ Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis β€” The Record (Recorded Future)
                    • 🚨 FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs β€” Dark Reading
                    • 🚨 Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials β€” The Hacker News
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext. It's Friday, July 3rd, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves. Let's get into it.

                      Alex: We have a packed show today. The EU-US data transfer framework is under threat again, courtesy of Max Schrems. We've got a major DHS intelligence network breach, active ransomware campaigns exploiting Fortinet and Citrix infrastructure, the FBI taking down a two-million-device botnet run through a Nasdaq-listed company, a Scattered Spider extradition, a damning survey on breach concealment, and a story that honestly reads like satire but isn't β€” a European lawmaker investigating spyware got hit with spyware. Jordan, take us there.

                      Jordan: Yeah, let's start with the Pegasus story because it's one of those things that sounds like a movie pitch but is very real. Citizen Lab has forensically confirmed that Stelios Kouloglou, who is a sitting member of the European Parliament and specifically a member of the PEGA Committee β€” the committee created to investigate commercial spyware abuses β€” had his device infected with NSO Group's Pegasus. Not once. Twice. The audacity is almost artistic.

                      Alex: It would be funny if it weren't so alarming. And for our audience, the reason this matters beyond the geopolitical theater is what it tells you about the threat model for anyone in an oversight or governance role. If a sitting EU lawmaker investigating spyware isn't safe, your general counsel, your board members, your executives traveling internationally β€” they're absolutely viable targets for commercial surveillance tools.

                      Jordan: Exactly. And this isn't some hypothetical. NSO Group markets Pegasus as a law enforcement tool, but the client list has always been the problem. We're talking about nation-state customers who will deploy this against political targets, journalists, activists, and yes, corporate executives. If your C-suite is operating on the assumption that their iPhone is secure because they have MDM enrolled, that assumption needs to be revisited. Pegasus exploits are zero-click. They don't require the target to do anything.

                      Alex: So the action item here is straightforward. If you haven't already deployed Lockdown Mode on executive devices, that conversation needs to happen Monday. And beyond that, this should inform your executive device refresh cadence, your travel security protocols, and honestly, your board reporting on surveillance risk. This isn't a fringe concern anymore.

                      Jordan: Let's pivot to the DHS breach, because this one has real gravity. A senior Democrat on the Senate Intelligence Committee confirmed that a Homeland Security intelligence-sharing network was compromised, and explicitly warned that the accessed information may risk national security.

                      Alex: The details are still emerging, but the pattern is what matters. This is another in a long sequence of US government network compromises. And for CISOs in the private sector, the question you need to be asking is: what data did we share through federal information-sharing programs, and does this breach create exposure for us? If your organization participates in any DHS CISA information-sharing frameworks, you need to be talking to your government affairs team and your legal counsel about what was in that pipeline.

                      Jordan: And I'll add that this also affects trust in the broader information-sharing ecosystem. Every time a government network gets popped, it makes the next CISO more reluctant to share threat intelligence through official channels. That's a compounding problem for the entire community.

                      Alex: Now let's connect two stories that are really one story. FortiBleed and Citrix Bleed 2. Jordan, walk us through the threat landscape here.

                      Jordan: So these are two separate vulnerability exploitation campaigns, but they share a common operational model that's worth understanding together. FortiBleed β€” the actors who compromised thousands of Fortinet firewalls β€” they've now moved from persistent access to monetization. They're partnering with INC and Lynx ransomware operations to convert those footholds into extortion revenue. And they're stacking on a suspected Nextcloud zero-day to expand their access within compromised environments.

                      Alex: So if you're running Fortinet perimeter infrastructure, this is no longer a "patch and monitor" situation. This is an "assume compromise and hunt" situation.

                      Jordan: Correct. And simultaneously, the Anubis ransomware group is actively exploiting CVE-2025-5777, which is Citrix Bleed 2, to get initial access into enterprise environments running NetScaler. The attack chains are sophisticated β€” BYOVD techniques, legitimate RMM tooling for lateral movement, and supply chain credential theft to broaden the blast radius. This is not smash-and-grab. These are methodical, multi-stage intrusions.

                      Alex: The action items are clear. For Fortinet shops, assume compromise on unpatched devices and run threat hunts now. For Citrix NetScaler environments, patch CVE-2025-5777 immediately if you haven't, audit your RMM tooling for unauthorized instances, and review your supply chain credential hygiene. Both of these represent active, escalating threats, not theoretical risk.

                      Jordan: Let's shift to the FBI's takedown of NetNut and the Popa botnet. This one is fascinating because of who was behind it. NetNut is a residential proxy service operated by Alarum Technologies, which is a publicly traded company on the Nasdaq. The FBI seized hundreds of domains after investigations connected NetNut to a botnet of at least two million compromised devices.

                      Alex: This is a vendor due diligence story. A Nasdaq-listed company was operating infrastructure that served as a platform for threat actors. The residential proxy market has always been murky, but this is a clear example of how commercial services that look legitimate on paper can be deeply intertwined with criminal infrastructure.

                      Jordan: And for CISOs, the question is twofold. First, is any of your traffic routing through residential proxy networks that you don't fully understand? And second, are your threat intelligence feeds and your fraud detection systems calibrated to detect traffic originating from residential proxy infrastructure? Because that's how attackers look like legitimate users.

                      Alex: Good. Let's talk about Scattered Spider. Peter Stokes, alleged to be a longstanding member, has been extradited to the US to face federal charges. Jordan, is this meaningful or is this another arrest that doesn't change the operational picture?

                      Jordan: It's meaningful in the aggregate but not decisive. Scattered Spider is a loosely organized group. Taking one member off the board disrupts but doesn't dismantle. That said, the law enforcement pressure is cumulative. Multiple arrests, multiple countries cooperating β€” it raises the cost and the risk for these operators. The eight-million-dollar ransom demand against the luxury retailer and the two million in losses even without payment β€” that's the kind of case that makes prosecutors enthusiastic.

                      Alex: And for CISOs, the reminder is that Scattered Spider's playbook hasn't changed. They target help desks with social engineering. They use SIM swapping. These are people problems, not technology problems. If your help desk verification procedures haven't been hardened against these specific techniques, the arrest of one member doesn't reduce your risk.

                      Jordan: Now, the governance stories. Alex, the Data Privacy Framework challenge is potentially enormous.

                      Alex: It really is. Max Schrems and noyb have formally notified European officials that they plan to sue to invalidate the EU-US Data Privacy Framework. If you've been in this space for more than five minutes, you've seen this movie before. Safe Harbor was invalidated. Privacy Shield was invalidated. DPF was supposed to be the durable replacement, and now it's under legal challenge following the Supreme Court decision that changed the underlying US legal landscape.

                      Jordan: And the trajectory is predictable. Even if the challenge takes a year or two to wind through the courts, the uncertainty itself is a problem. If you're a CISO at a company that transfers EU personal data to the US, and your legal basis is DPF, you need a fallback architecture. Standard Contractual Clauses, data residency, whatever your legal team recommends β€” but you can't be caught flat-footed.

                      Alex: Exactly. Start the conversation with your DPO and your privacy counsel now. Map your transatlantic data flows. Understand where your SCCs are current and where they're not. This isn't a fire drill yet, but it's a fire watch.

                      Jordan: And then there's the Bitdefender survey. A majority of cybersecurity professionals say they've been instructed to conceal a breach from regulators or the public.

                      Alex: This is a governance crisis, full stop. Under SEC rules, under GDPR, under virtually every modern regulatory framework, concealing a material breach creates personal criminal and civil liability. For CISOs specifically, we've seen the SolarWinds case, we've seen the Uber case. The message from regulators is unambiguous: if you know about a material breach and you help conceal it, you are personally at risk.

                      Jordan: And the survey finding that US companies are simultaneously more confident in their defenses and more strained operationally β€” that's cognitive dissonance that boards need to understand. Confidence without capacity is how you get pressure to hide bad news.

                      Alex: If you're a CISO and you're being pressured to conceal, document everything, engage outside counsel, and understand your whistleblower protections. And if you're a board member listening to this, create the reporting structures that make concealment unnecessary. This is a culture problem, not a security problem.

                      Jordan: Last note β€” the UK's National Cyber Action Plan has been delayed due to the Labour leadership crisis. It was supposed to publish Monday.

                      Alex: For anyone operating in the UK market, this creates near-term regulatory uncertainty. We don't know how long the delay will be. The leadership contest opens July 9th, and depending on how that plays out, strategic cyber policy could slip significantly. Monitor it, but don't pause your compliance planning.

                      Jordan: So stepping back, Alex β€” what's the thread this week?

                      Alex: The thread is that the structures we rely on are fragile. The EU-US data transfer framework, government intelligence-sharing networks, the assumption that oversight bodies are safe from surveillance, the expectation that breaches will be honestly reported. All of those are under stress simultaneously. The CISO's job right now is to build resilience that doesn't depend on any single structure holding.

                      Jordan: And on the technical side, the perimeter is on fire. Fortinet, Citrix, residential proxies as threat infrastructure β€” the attackers are monetizing access faster than most organizations are patching. If you take one action this weekend, run a threat hunt against your edge infrastructure. Don't wait for Monday.

                      Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. Have a safe Fourth of July weekend. We'll be back Monday.

                      Jordan: Stay sharp.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-03.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext