Cleartext

Cleartext โ€“ July 08, 2026


Listen Later

Cleartext โ€“ July 08, 2026

Daily cybersecurity briefing for CISOs and security leaders.

๐ŸŽง Listen to this episode

Episode Summary

Today's episode covers 10 stories across 5 topic areas, including: China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware; What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out; Hacked, leaked, and held for ransom: The worst breaches of 2026 so far.

Stories Covered
๐ŸŒ Geopolitical
China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

The Hacker News ยท Jul 08 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 8/10

Why it matters to CISOs: China's active expansion of its Operational Relay Box infrastructure through compromised networking devices indicates a persistent, growing capability to proxy malicious traffic through enterprise edge devices โ€” organizations must audit internet-facing routers and network appliances for signs of compromise.

  • Chinese APT UAT-7810 is deploying new LONGLEASH malware to expand the LapDogs ORB network, primarily targeting unpatched Ruckus routers
  • ORB networks allow threat actors to route attacks through legitimate-looking infrastructure, defeating IP-based detection and attribution
  • Cisco Talos research indicates the campaign is actively evolving since at least June 2025
  • ๐Ÿ“– Read full article

    What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out

    Wired Security ยท Jul 08 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

    Why it matters to CISOs: A closed-door Volt Typhoon war game involving insurers surfaced critical gaps in cyber incident response for critical infrastructure disruption scenarios โ€” CISOs in sectors with OT/ICS exposure or insurance dependencies should examine the scenario's findings for their own resilience planning.

    • A closed-door simulation modeled China's Volt Typhoon hackers attacking US water systems, resulting in burst mains and evacuated hospitals
    • The exercise involved insurers assessing their exposure to mass critical infrastructure disruption, highlighting systemic financial risk
    • Findings signal that existing response frameworks and insurance models are not calibrated for coordinated, nation-state critical infrastructure attacks
    • ๐Ÿ“– Read full article

      ๐Ÿ“ก Macro Trends
      Hacked, leaked, and held for ransom: The worst breaches of 2026 so far

      TechCrunch Security ยท Jul 07 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

      Why it matters to CISOs: A mid-year retrospective covering the most damaging incidents of 2026 โ€” including DOGE data exposure, critical energy and water system hacks, and an FBI surveillance system breach โ€” provides essential context for board reporting and benchmarking program priorities against actual threat patterns.

      • 2026 H1 incidents include a massive DOGE-related data breach, hacks of critical energy and water infrastructure, and compromise of an FBI surveillance system
      • The recap provides a comprehensive threat landscape baseline for board-level communication and strategic security investment justification
      • Pattern of attacks on government and critical infrastructure signals ongoing nation-state and ransomware escalation
      • ๐Ÿ“– Read full article

        ๐Ÿ”“ Data Breach
        Accenture confirms breach after hacker offers stolen data for sale

        BleepingComputer ยท Jul 07 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 8/10

        Why it matters to CISOs: Accenture's confirmed breach involving source code, RSA and SSH keys, and Azure access tokens raises third-party supply chain risk concerns for any enterprise with Accenture as a technology services partner, requiring immediate review of shared credential and access arrangements.

        • Threat actor '888' claims to have stolen 35GB of data including source code, RSA keys, SSH keys, Azure personal access tokens, and Azure Storage access keys
        • Accenture has acknowledged the security incident though the full scope remains unknown
        • Stolen credentials and tokens could enable downstream compromise of Accenture's enterprise clients
        • ๐Ÿ“– Read full article

          Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target

          Infosecurity Magazine ยท Jul 08 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘ 8/10

          Why it matters to CISOs: Documented adversarial use of agentic AI compressing a cloud attack lifecycle from weeks to 72 hours fundamentally changes incident response planning assumptions โ€” detection and containment SLAs built around human-speed attacks are now dangerously outdated.

          • Sygnia report documents a real-world case where agentic AI accelerated a cloud compromise from a weeks-long attack to just 72 hours
          • AI-assisted attackers can now automate reconnaissance, lateral movement, and exploitation at machine speed
          • The case signals a new threat tempo that outpaces traditional SOC detection and response timelines
          • ๐Ÿ“– Read full article

            DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

            The Hacker News ยท Jul 07 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

            Why it matters to CISOs: Active M365 device-code phishing campaigns bypassing traditional credential-page detection represent a direct threat to enterprise identity infrastructure โ€” CISOs should validate that conditional access policies and user awareness programs account for legitimate-flow abuse tactics.

            • DEBULL tooling exploits Microsoft's legitimate device-code authentication flow to hijack M365 accounts without using a fake login page, evading many detection controls
            • The active campaign ran from late June into early July 2026 using collaboration-themed lures
            • The technique abuses trusted Microsoft authentication infrastructure, making it difficult to block without disrupting legitimate device-code workflows
            • ๐Ÿ“– Read full article

              โš–๏ธ Governance & Policy
              EU unveils cyber plan to reduce reliance on foreign AI systems

              The Record (Recorded Future) ยท Jul 08 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

              Why it matters to CISOs: The EU's new cybersecurity communication anchored around AI sovereignty will likely shape procurement requirements, vendor due diligence standards, and regulatory expectations for enterprises operating in European markets โ€” CISOs should assess exposure to forthcoming AI sourcing mandates.

              • The European Commission adopted a formal communication on July 7 aimed at reducing reliance on foreign AI in cybersecurity contexts
              • The plan is built on three pillars: making frontier AI safe and accessible for European cybersecurity, preparing the EU cyber ecosystem, and scaling European AI capabilities
              • The communication signals regulatory direction toward AI provenance requirements that could affect enterprise vendor selection and compliance programs
              • ๐Ÿ“– Read full article

                Risky Bulletin: DHS IG investigates forced CISA reassignments

                Risky Business News ยท Jul 08 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘ 7/10

                Why it matters to CISOs: DHS Inspector General scrutiny of forced CISA staff reassignments adds to concerns about the operational capacity and independence of the US federal cybersecurity authority โ€” CISOs relying on CISA threat intelligence, advisories, and coordination should factor in the agency's diminished capacity when planning.

                • The DHS Inspector General has opened an investigation into forced reassignments of CISA personnel
                • The investigation raises questions about political interference with the nation's primary civilian cybersecurity agency
                • The bulletin also notes Canada hacked a ransomware gang and Taiwan charged two executives with aiding Chinese hackers
                • ๐Ÿ“– Read full article

                  ๐Ÿšจ Critical Vulnerability
                  15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

                  The Hacker News ยท Jul 08 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ 9/10

                  Why it matters to CISOs: A privilege escalation flaw requiring no special permissions affecting virtually every mainstream Linux distribution since 2011 poses existential risk to enterprise server fleets, cloud workloads, and container environments โ€” emergency patching prioritization required across the estate.

                  • CVE-2026-43499 (GhostLock) allows any logged-in user to gain full root control with no special permissions or unusual configuration required
                  • The vulnerable code has shipped by default in essentially every mainstream Linux distribution since 2011, making the blast radius near-universal
                  • Enables container escape, threatening multi-tenant cloud and Kubernetes environments beyond single-host compromise
                  • ๐Ÿ“– Read full article

                    New Januscape Linux flaw allows VM escape on Intel, AMD devices

                    BleepingComputer ยท Jul 07 ยท Relevance: โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘ 9/10

                    Why it matters to CISOs: A 16-year-old Linux kernel vulnerability enabling full VM escape on Intel and AMD hardware threatens the hypervisor isolation that enterprise cloud and on-premises virtualization security models depend on โ€” this demands immediate assessment of patching status across all virtualized infrastructure.

                    • Januscape is a 16-year-old Linux kernel flaw allowing attackers to escape a virtual machine and execute arbitrary code on the host
                    • Affects both Intel and AMD hardware, covering the vast majority of enterprise x86 server infrastructure
                    • VM escape capability breaks the core hypervisor isolation boundary that underpins multi-tenant and segmented cloud environments
                    • ๐Ÿ“– Read full article

                      Further Reading
                      • ๐ŸŒ China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware โ€” The Hacker News
                      • ๐ŸŒ What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out โ€” Wired Security
                      • ๐Ÿ“ก Hacked, leaked, and held for ransom: The worst breaches of 2026 so far โ€” TechCrunch Security
                      • ๐Ÿ”“ Accenture confirms breach after hacker offers stolen data for sale โ€” BleepingComputer
                      • ๐Ÿ”“ Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target โ€” Infosecurity Magazine
                      • ๐Ÿ”“ DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts โ€” The Hacker News
                      • โš–๏ธ EU unveils cyber plan to reduce reliance on foreign AI systems โ€” The Record (Recorded Future)
                      • โš–๏ธ Risky Bulletin: DHS IG investigates forced CISA reassignments โ€” Risky Business News
                      • ๐Ÿšจ 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros โ€” The Hacker News
                      • ๐Ÿšจ New Januscape Linux flaw allows VM escape on Intel, AMD devices โ€” BleepingComputer
                      • Full Transcript
                        Click to expand full episode transcript

                        Jordan: A fifteen-year-old Linux kernel flaw lets any logged-in user take root with zero special permissions. Every mainstream distro since 2011. And that's not even the only ancient Linux kernel bug dropping today โ€” there's a separate sixteen-year-old flaw enabling full VM escape on Intel and AMD. If you run Linux anywhere โ€” and you do โ€” today's episode is not optional.

                        Alex: Welcome to Cleartext for Wednesday, July 8th, 2026. I'm Alex Chen, alongside Jordan Reeves. We've got a packed show. Two critical Linux kernel vulnerabilities that together threaten basically everything from your container fleet to your hypervisor boundaries. China's APT infrastructure is growing in ways that should change how you think about IP-based detection. Accenture confirmed a breach that puts its entire client base on notice. And we have documented evidence of agentic AI compressing attack timelines from weeks to three days. Plus, the EU is making moves on AI sovereignty that will reshape procurement for anyone doing business in Europe. Let's get into it.

                        Jordan: Let's start with the two Linux vulnerabilities because they're both genuinely critical and they compound each other. GhostLock, CVE-2026-43499 โ€” disclosed by Nebula Security. This is a privilege escalation flaw in the Linux kernel. It requires nothing exotic. Any authenticated user, no special permissions, no unusual configuration, gets full root. It's been sitting in every mainstream distro since 2011. Fifteen years.

                        Alex: And the blast radius here is what makes this a board-level conversation. This isn't a niche component. This is default kernel code shipping in Ubuntu, Red Hat, Debian, SUSE โ€” everything. Your on-prem servers, your cloud workloads, your container hosts. And speaking of containers, GhostLock enables container escape, which means your multi-tenant Kubernetes environments, your shared cloud infrastructure โ€” the isolation boundaries you're depending on are compromised.

                        Jordan: Then layer on Januscape. Separate vulnerability, sixteen years old, also in the Linux kernel. This one enables VM escape on both Intel and AMD hardware. So if GhostLock breaks your container isolation, Januscape breaks your hypervisor isolation. Together, these two vulnerabilities attack the two fundamental containment models that modern infrastructure relies on.

                        Alex: The action here is straightforward but urgent. This is an emergency patching cycle. If you're a CISO listening to this, you need your infrastructure team treating both of these as P-zero today. Not this sprint, not next maintenance window. And if you're in a cloud environment, you need to be pressing your providers โ€” AWS, Azure, GCP โ€” for confirmation that their host kernels are patched. Don't assume it.

                        Jordan: And for the detection side โ€” GhostLock requires only a logged-in user. That means any compromised service account, any low-privilege foothold an attacker already has, instantly becomes root. Your threat models around lateral movement and privilege escalation just changed.

                        Alex: Let's pivot to the geopolitical picture because there's a clear through-line today. Jordan, walk us through UAT-7810 and what the ORB network expansion means.

                        Jordan: So UAT-7810 is a Chinese APT that maintains and grows something called the LapDogs ORB network. ORB stands for Operational Relay Box. Think of it as a distributed proxy network built from compromised legitimate devices โ€” in this case, primarily unpatched Ruckus routers sitting on enterprise network edges. They've developed new malware called LONGLEASH specifically to expand this network. Cisco Talos has been tracking this campaign since at least June 2025, and it's actively evolving.

                        Alex: And for CISOs, the strategic implication is significant. ORB networks defeat IP-based detection and attribution. When the attack traffic hitting your environment originates from what looks like a legitimate enterprise router in a normal geography, your threat intel feeds, your geo-blocking, your IP reputation systems โ€” they all fail. This is China building persistent, distributed infrastructure that makes their operations harder to detect and nearly impossible to attribute through traditional means.

                        Jordan: Exactly. And this connects directly to the second China story. Wired reported on a closed-door war game simulating Volt Typhoon attacks on US water systems. This wasn't a think tank exercise. Insurers were in the room, stress-testing their exposure models against coordinated critical infrastructure disruption. The scenario produced burst water mains and hospital evacuations. And the finding was stark โ€” existing response frameworks and insurance models are simply not calibrated for nation-state coordinated attacks on critical infrastructure.

                        Alex: This matters to CISOs in two dimensions. First, if you have OT or ICS exposure, the scenario modeling coming out of these exercises should feed directly into your resilience planning. Second โ€” and this is the one people miss โ€” the insurance implications. If your cyber insurance policy has exclusions or sub-limits around acts of war or nation-state attacks, and insurers are actively war-gaming their exposure to exactly these scenarios, expect coverage terms to tighten. You need to be having that conversation with your broker now, not after an incident.

                        Jordan: The TechCrunch mid-year retrospective reinforces all of this. The worst breaches of 2026's first half include DOGE-related data exposure, energy and water infrastructure compromises, and the breach of an FBI surveillance system. The pattern is unmistakable โ€” government and critical infrastructure are under sustained, escalating pressure from both nation-states and ransomware operators. If you're preparing a board update for Q3, this retrospective is useful source material for contextualizing your own risk posture against the broader landscape.

                        Alex: Now let's talk about Accenture, because this has immediate third-party risk implications for a very large number of enterprises. The threat actor known as 888 claims to have stolen thirty-five gigabytes of data including source code, RSA keys, SSH keys, Azure personal access tokens, and Azure Storage access keys. Accenture has confirmed the breach, though the full scope remains unclear.

                        Jordan: This is a supply chain risk story. Accenture is embedded in the technology infrastructure of a significant portion of the Fortune 500. If stolen credentials include access tokens and keys tied to client environments โ€” and the claimed data types strongly suggest they could โ€” then downstream compromise is a real possibility. This isn't theoretical. Those Azure personal access tokens and storage keys could provide direct access to client cloud resources.

                        Alex: If Accenture is a services partner for your organization, the action is immediate. Review every shared credential arrangement, every service account, every access token that connects your environment to theirs. Rotate anything that could be compromised. And have a direct conversation with your Accenture account team about whether your environment is in scope. Don't wait for their notification.

                        Jordan: Let's talk about the Sygnia report on agentic AI in attacks, because this one fundamentally changes operational assumptions. They documented a real-world case โ€” not a lab exercise, not a proof of concept โ€” where an attacker used agentic AI to compress what would normally be a weeks-long cloud compromise into seventy-two hours. Automated reconnaissance, lateral movement, exploitation โ€” all at machine speed.

                        Alex: This is the story I'd flag for every CISO thinking about their SOC's detection and response SLAs. If your mean time to detect is measured in days and your mean time to contain is measured in additional days, you are now operating slower than your adversaries' automated tooling. The assumption that you have a window โ€” that human attackers take time to orient, to make mistakes, to move cautiously โ€” that assumption is eroding fast.

                        Jordan: And to be clear, this isn't some hypothetical future concern. This is happening now. The Sygnia case is documented. The tooling exists. The question isn't whether agentic AI will be used offensively โ€” it's whether your defensive automation can match the tempo. For most organizations, honestly, the answer today is no.

                        Alex: Staying on the identity and access front โ€” the DEBULL tooling campaign is worth sixty seconds because it's clever and it's actively running. This exploits Microsoft's legitimate device-code authentication flow. No fake login page. The attacker sends a collaboration-themed lure โ€” looks like a Teams invite, a SharePoint share โ€” and it pushes the user into the real Microsoft device login experience. The user authenticates against Microsoft's actual infrastructure, and the attacker captures the token.

                        Jordan: This is hard to detect because there's no malicious infrastructure to block. It's Microsoft's own authentication flow. Your phishing detection that keys on fake login pages misses this entirely. CISOs need to validate that conditional access policies restrict device-code flow to managed devices only, and that user awareness training covers this specific scenario. It's an active campaign running since late June.

                        Alex: Two governance items to close the segments. The European Commission adopted a formal communication on July 7th aimed at reducing reliance on foreign AI in cybersecurity contexts. Three pillars โ€” making frontier AI safe and accessible for European cybersecurity, preparing the EU's cyber ecosystem, and scaling European AI capabilities. This is regulatory direction, not regulation yet, but it signals where procurement requirements and vendor due diligence standards are heading for anyone operating in European markets.

                        Jordan: And the DHS Inspector General has opened an investigation into forced reassignments of CISA personnel. I'll be direct โ€” if you rely on CISA for threat intelligence, advisories, or coordination during incidents, you should be factoring in diminished operational capacity. The agency's independence and staffing are under pressure, and that has practical implications for the quality and timeliness of the support you can expect.

                        Alex: Alright, Jordan, looking at today's stories together โ€” what's the emerging theme?

                        Jordan: The theme is that the assumptions underlying most security architectures are being invalidated simultaneously. Kernel isolation โ€” broken by GhostLock and Januscape. IP-based detection โ€” defeated by ORB networks. Human-speed attack timelines โ€” obsoleted by agentic AI. Credential-page phishing detection โ€” bypassed by device-code flow abuse. Hypervisor boundaries โ€” compromised by VM escape. Every one of these is a foundational assumption that security programs are built on, and every one of them took a hit today.

                        Alex: And the meta-point for CISOs is that this isn't about any single vulnerability or technique. It's about the rate at which your defensive model's core assumptions are being challenged. The question for every security leader this week is โ€” when was the last time you stress-tested your architecture against the failure of its own foundational assumptions? Not individual controls, but the assumptions those controls are built on. Container isolation works. VMs are isolated from hosts. Attackers move at human speed. IP reputation is meaningful. If those assumptions fail, does your program still hold?

                        Jordan: That's the conversation to have with your team this week. Not just patch GhostLock โ€” though do that immediately โ€” but what else are we assuming that might not be true anymore?

                        Alex: That's our show for Wednesday, July 8th. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.

                        Jordan: I'm Jordan Reeves. Patch your kernels. We'll see you tomorrow.

                        Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-08.

                        Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                        ...more
                        View all episodesView all episodes
                        Download on the App Store

                        CleartextBy Cleartext