Cleartext

Cleartext – July 06, 2026


Listen Later

Cleartext – July 06, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 8 stories across 4 topic areas, including: Risky Bulletin: EU official’s phone infected with Pegasus; Canadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last year; Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT.

Stories Covered
🌍 Geopolitical
Risky Bulletin: EU official’s phone infected with Pegasus

Risky Business News Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

Why it matters to CISOs: Pegasus infections of elected officials signal continued aggressive use of commercial spyware against high-value targets, raising direct concerns for CISOs protecting executives, board members, and government-facing personnel who may be similarly targeted.

  • A European Member of Parliament's phone was confirmed infected with Pegasus spyware
  • Android is reducing its PIN guessing limit from 1,800 attempts to 20, a significant brute-force mitigation
  • Alibaba has banned employees from using Claude at work, reflecting growing enterprise AI governance tensions
  • πŸ“– Read full article

    Canadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last year

    TechCrunch Security Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

    Why it matters to CISOs: Government offensive cyber operations against ransomware gangs provide strategic context for CISOs on how allied intelligence services are disrupting threat actors, which may temporarily affect the operational tempo of specific ransomware groups.

    • Canada's signals intelligence agency (CSE) publicly disclosed offensive cyber operations in its annual report
    • Targets included a ransomware gang, drug traffickers, and extremist groups
    • The disclosure underscores growing Five Eyes willingness to use offensive cyber tools against criminal infrastructure
    • πŸ“– Read full article

      Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

      The Hacker News Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

      Why it matters to CISOs: China-nexus espionage campaigns targeting corporate finance teams via tax authority impersonation are directly relevant to CISOs at multinationals with India operations, highlighting the need for spear-phishing controls around regulatory compliance workflows.

      • Operation DragonReturn targets Indian taxpayers, tax professionals, and corporate finance teams with spear-phishing emails
      • Attackers impersonate India's Income Tax Department to deliver DcRAT remote access trojan
      • Attribution points to a suspected China-nexus threat actor, suggesting state-aligned economic espionage motivation
      • πŸ“– Read full article

        Ukrainian media outlets now among 'priority targets' for Russian hackers

        The Record (Recorded Future) Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘ 6/10

        Why it matters to CISOs: Russia's escalating targeting of media organizations extends the information warfare threat surface and is relevant to CISOs at media, publishing, and broadcast companies, as well as organizations in industries frequently covered by adversarial state media narratives.

        • A top Ukrainian security official disclosed two previously unreported attacks on TV media organizations
        • Russian hackers have designated Ukrainian media outlets as priority targets, indicating a strategic shift
        • The escalation reflects broader Russian information warfare objectives tied to the ongoing conflict
        • πŸ“– Read full article

          πŸ“‘ Macro Trends
          Researchers Claim First Fully Agentic Ransomware: JadePuffer

          Infosecurity Magazine Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

          Why it matters to CISOs: The emergence of agentic AI-powered ransomware represents a qualitative escalation in attacker capability that CISOs must factor into incident response planning and AI governance frameworks, as autonomous agents could dramatically compress attack timelines.

          • JadePuffer is described as the first fully agentic AI-powered ransomware campaign by researchers
          • Autonomous agents can automate reconnaissance, lateral movement, and encryption stages without human attacker involvement
          • The development signals that AI-accelerated attack chains will require equally accelerated detection and response capabilities
          • πŸ“– Read full article

            SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

            The Hacker News Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

            Why it matters to CISOs: As enterprises rapidly adopt AI coding agents, SkillCloak demonstrates that existing static analysis controls are insufficient to detect malicious agent plugins, forcing CISOs to rethink supply chain security for the AI agent ecosystem.

            • SkillCloak technique evades static scanners for malicious AI agent skills more than 90% of the time in testing
            • The technique uses self-extracting packing to hide malicious payloads within agent skill packages
            • Researchers also developed a runtime checker that catches most evasion attempts, suggesting a path toward mitigation
            • πŸ“– Read full article

              βš–οΈ Governance & Policy
              OAuth, guest accounts, and weak MFA drive SaaS risk

              Help Net Security Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

              Why it matters to CISOs: With guest accounts comprising 69% of monitored SaaS accounts and persistent OAuth grants creating orphaned access paths, CISOs face a measurable and growing SaaS identity hygiene problem that requires updated third-party access governance policies.

              • Guest accounts accounted for 69% of monitored SaaS accounts in 2025, up by more than 1.9 million year-over-year
              • Guest accounts outnumber licensed users and frequently remain active after contractors or partners disengage
              • OAuth grants and weak MFA identified as primary drivers of unmanaged SaaS trust exposure per Kaseya's 2026 report
              • πŸ“– Read full article

                🚨 Critical Vulnerability
                Max severity Adobe ColdFusion flaw now exploited in attacks

                BleepingComputer Β· Jul 06 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                Why it matters to CISOs: A maximum-severity ColdFusion vulnerability under active exploitation requires immediate attention from CISOs whose organizations run ColdFusion-based web applications or legacy enterprise portals, as unpatched instances face direct compromise risk.

                • CVE-2026-48282 is rated maximum severity and is actively being exploited in the wild
                • Exploitation confirmed by vulnerability intelligence firm KEVIntel
                • Adobe ColdFusion remains in use across many enterprise and government web application environments
                • πŸ“– Read full article

                  Further Reading
                  • 🌍 Risky Bulletin: EU official’s phone infected with Pegasus β€” Risky Business News
                  • 🌍 Canadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last year β€” TechCrunch Security
                  • 🌍 Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT β€” The Hacker News
                  • 🌍 Ukrainian media outlets now among 'priority targets' for Russian hackers β€” The Record (Recorded Future)
                  • πŸ“‘ Researchers Claim First Fully Agentic Ransomware: JadePuffer β€” Infosecurity Magazine
                  • πŸ“‘ SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing β€” The Hacker News
                  • βš–οΈ OAuth, guest accounts, and weak MFA drive SaaS risk β€” Help Net Security
                  • 🚨 Max severity Adobe ColdFusion flaw now exploited in attacks β€” BleepingComputer
                  • Full Transcript
                    Click to expand full episode transcript

                    Alex: Welcome to Cleartext for Monday, July 6th, 2026. I'm Alex Chen.

                    Jordan: And I'm Jordan Reeves. So, researchers just published what they're calling the first fully agentic ransomware. JadePuffer. Autonomous AI agents handling recon, lateral movement, encryption, the whole chain, no human in the loop. If that doesn't rearrange your Monday priorities, I don't know what will. We'll get to that.

                    Alex: We've got a packed show today. Pegasus is back in the headlines, this time infecting a European parliamentarian's phone. Canada's signals intelligence agency just went public about hacking a ransomware gang. There's a China-nexus campaign targeting corporate finance teams in India. We've got a max-severity ColdFusion zero-day under active exploitation. And we'll talk about why your SaaS guest accounts might be your biggest blind spot. Let's get into it.

                    Jordan: Let's start with the spyware story because it connects to something every CISO should be thinking about right now. A European Member of Parliament's phone was confirmed infected with Pegasus. NSO Group's flagship product, still in active use, still landing on high-value targets.

                    Alex: And this is the part that should make CISOs uncomfortable. If you're protecting executives who interact with government officials, board members with political exposure, anyone in a regulated industry that intersects with geopolitics, you are in the blast radius of commercial spyware. This isn't hypothetical.

                    Jordan: The targeting logic has broadened. It used to be dissidents and journalists. Now it's elected officials in EU member states. The implication for the private sector is straightforward. If your CEO is meeting with a defense ministry official, or your general counsel is advising on sanctions compliance, their devices are plausible targets for state-aligned commercial spyware.

                    Alex: And this is where I'd push CISOs to have a real conversation with their boards about mobile threat defense. Not the checkbox version. Actual device attestation, behavioral anomaly detection on mobile endpoints, and honest policies about what devices executives carry into sensitive meetings. Most organizations still treat mobile as a second-class citizen in their security architecture.

                    Jordan: One related data point from the same bulletin. Android is dropping its PIN brute-force limit from 1,800 attempts to 20. That's a massive reduction. It signals that even the platform vendors are acknowledging that physical device compromise is a real and present threat.

                    Alex: Good. That's overdue. Let's shift to offensive cyber, because Canada just made some noise.

                    Jordan: CSE, Canada's signals intelligence agency, publicly disclosed in its annual report that it conducted offensive cyber operations against a ransomware gang, drug traffickers, and extremist groups last year. This is notable not because Five Eyes countries haven't been doing this, but because they said it out loud.

                    Alex: And the strategic read for CISOs is important. Allied governments are actively disrupting ransomware infrastructure. That's a tailwind for defenders, but it's an unpredictable one. You might see a ransomware group go dark for a few weeks, and the reason might be a government operation you'll never hear the full details of.

                    Jordan: Right. Don't build your risk model around it, but understand that the threat landscape isn't purely organic. There are state hands on the scale. And the more that Five Eyes normalizes public disclosure of these operations, the more deterrent value they carry. It also raises the bar for ransomware operators who now have to worry about offensive capabilities from multiple allied intelligence services, not just the FBI.

                    Alex: Which brings us to China-nexus activity. Operation DragonReturn, attributed to a suspected Chinese threat actor, is targeting Indian taxpayers, tax professionals, and corporate finance teams with spear-phishing emails that impersonate India's Income Tax Department. They're delivering DcRAT, a remote access trojan designed to exfiltrate sensitive financial data.

                    Jordan: The tradecraft here is bread and butter, but the targeting is strategic. Tax season lures impersonating a legitimate regulatory body, aimed at people whose jobs require them to open exactly these kinds of documents. If you're a multinational with India operations, your finance and compliance teams are the attack surface here.

                    Alex: And the lesson is broader than India. Every jurisdiction has regulatory compliance workflows that create predictable, exploitable moments. Tax filings, audit cycles, regulatory submissions. Attackers know when your people are most likely to click on something that looks official. CISOs should be mapping those calendars and layering additional controls during peak periods. Extra scrutiny on inbound attachments, tighter sandboxing, targeted user awareness campaigns timed to those windows.

                    Jordan: Now let's talk about Russia and Ukraine. A top Ukrainian security official disclosed two previously unreported attacks on TV media organizations and said Russian hackers have designated Ukrainian media outlets as priority targets. This is a strategic shift. Media has moved up the Russian targeting hierarchy alongside energy and government.

                    Alex: For CISOs at media companies, broadcast organizations, or even PR and communications firms with clients in contested geopolitical spaces, this is a direct signal. You're not collateral damage. You're the objective. Information warfare is a core component of modern conflict, and the infrastructure that produces and distributes information is a legitimate target in the adversary's calculus.

                    Jordan: And it extends beyond Ukraine. If you're a Western media organization covering the conflict, covering sanctions, covering anything that intersects with Russian strategic narratives, your risk profile just went up.

                    Alex: All right, Jordan. Let's talk about the story you opened with. JadePuffer.

                    Jordan: So researchers have published what they describe as the first fully agentic AI-powered ransomware campaign. JadePuffer uses autonomous AI agents to handle the entire attack chain. Reconnaissance, initial access exploitation, lateral movement, privilege escalation, and encryption. No human operator making real-time decisions.

                    Alex: Let me be direct about what this means operationally. The thing that has historically given defenders a fighting chance against ransomware is dwell time. The gap between initial compromise and encryption where you can detect anomalous behavior and intervene. Agentic ransomware compresses that window potentially to minutes.

                    Jordan: And it's adaptive. These agents can make decisions based on what they find in the environment. They're not following a static playbook. They're adjusting. That means your detection logic built around known attack patterns may not trigger until it's too late.

                    Alex: So the defensive implications are clear. You need to be investing in detection capabilities that operate at machine speed. Behavioral analytics that don't depend on signatures. Automated containment that can isolate compromised segments without waiting for a human to approve the action. And your incident response playbooks need a scenario where encryption starts 20 minutes after initial access, not 20 days.

                    Jordan: Paired with JadePuffer, there's a related story about SkillCloak, a technique that lets malicious AI agent plugins evade static scanners more than 90 percent of the time using self-extracting packing. As enterprises rush to adopt AI coding agents and their plugin ecosystems, the supply chain for agent skills is effectively unvetted.

                    Alex: This is the AI supply chain problem we've been warning about. You're adopting tools that accept third-party plugins, and the scanning tools you rely on to catch malicious code are failing against basic evasion. The researchers did build a runtime checker that catches most of these attempts, which is encouraging. But the message for CISOs is clear. Static analysis alone is not sufficient for the AI agent ecosystem. You need runtime behavioral monitoring of what these agent skills actually do when they execute.

                    Jordan: Let's pivot to something more immediately actionable. Adobe ColdFusion.

                    Alex: CVE-2026-48282. Maximum severity. Actively exploited in the wild, confirmed by KEVIntel. If you run ColdFusion, and a surprising number of enterprises and government agencies still do, this needs to be patched today. Not this sprint. Today.

                    Jordan: ColdFusion is one of those platforms that lives in the forgotten corners of enterprise environments. Legacy web apps, internal portals nobody remembers building. If your asset inventory isn't comprehensive, you might not even know you're exposed.

                    Alex: Which is why this is also an asset management story. If you can't confidently say you've accounted for every ColdFusion instance in your environment, that's a problem that existed before this CVE and will exist after you patch it. Get the inventory right.

                    Jordan: Last item. A new report from Kaseya shows that guest accounts made up 69 percent of monitored SaaS accounts in 2025, an increase of 1.9 million year over year. These are contractor accounts, partner accounts, vendor accounts that were created for temporary access and never deprovisioned.

                    Alex: Sixty-nine percent. That number should be shocking, but honestly, it tracks with what I've seen. Every SaaS platform makes it trivially easy to invite a guest and almost none of them make it easy to audit or expire that access. Add in persistent OAuth grants that outlive the business relationship, and you've got orphaned access paths everywhere.

                    Jordan: And weak MFA on those guest accounts. Many organizations enforce strong MFA for employees but treat guest accounts as low-risk. They're not low-risk. They're high-risk with low visibility.

                    Alex: The fix here is governance, not technology. You need policies that tie guest account lifecycles to business relationships with automatic expiration. You need regular access reviews that specifically include OAuth grants. And you need to treat guest accounts as the threat surface they actually are.

                    Jordan: Looking ahead this week, the thread connecting these stories is acceleration. Adversaries are moving faster, whether it's agentic ransomware compressing attack timelines, commercial spyware hitting new categories of targets, or the AI agent supply chain outpacing our ability to secure it. The question for CISOs isn't whether they need to move faster. It's where to invest in automation and where human judgment still matters.

                    Alex: I'd add that the governance stories are just as urgent as the technical ones. SaaS sprawl, guest account hygiene, AI tool policies. Alibaba banning Claude internally, that's a governance decision that a lot of organizations haven't made yet. The organizations that get ahead of this week are the ones matching their detection speed to the threat's operational speed while also cleaning up the identity sprawl that gives attackers room to maneuver.

                    Jordan: Prioritize the ColdFusion patch. Audit your SaaS guest accounts. And start war-gaming a ransomware scenario where dwell time is measured in minutes, not weeks.

                    Alex: That's Cleartext for Monday, July 6th, 2026. Show notes and links to every story we covered are at cleartext.fm. We're back tomorrow. Stay sharp.

                    Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-06.

                    Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                    ...more
                    View all episodesView all episodes
                    Download on the App Store

                    CleartextBy Cleartext