
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
๐ง Listen to this episode
Today's episode covers 10 stories across 5 topic areas, including: China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware; What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out; Hacked, leaked, and held for ransom: The worst breaches of 2026 so far.
The Hacker News ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: China's active expansion of its Operational Relay Box infrastructure through compromised networking devices indicates a persistent, growing capability to proxy malicious traffic through enterprise edge devices โ organizations must audit internet-facing routers and network appliances for signs of compromise.
๐ Read full article
Wired Security ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: A closed-door Volt Typhoon war game involving insurers surfaced critical gaps in cyber incident response for critical infrastructure disruption scenarios โ CISOs in sectors with OT/ICS exposure or insurance dependencies should examine the scenario's findings for their own resilience planning.
๐ Read full article
TechCrunch Security ยท Jul 07 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: A mid-year retrospective covering the most damaging incidents of 2026 โ including DOGE data exposure, critical energy and water system hacks, and an FBI surveillance system breach โ provides essential context for board reporting and benchmarking program priorities against actual threat patterns.
๐ Read full article
BleepingComputer ยท Jul 07 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: Accenture's confirmed breach involving source code, RSA and SSH keys, and Azure access tokens raises third-party supply chain risk concerns for any enterprise with Accenture as a technology services partner, requiring immediate review of shared credential and access arrangements.
๐ Read full article
Infosecurity Magazine ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: Documented adversarial use of agentic AI compressing a cloud attack lifecycle from weeks to 72 hours fundamentally changes incident response planning assumptions โ detection and containment SLAs built around human-speed attacks are now dangerously outdated.
๐ Read full article
The Hacker News ยท Jul 07 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: Active M365 device-code phishing campaigns bypassing traditional credential-page detection represent a direct threat to enterprise identity infrastructure โ CISOs should validate that conditional access policies and user awareness programs account for legitimate-flow abuse tactics.
๐ Read full article
The Record (Recorded Future) ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: The EU's new cybersecurity communication anchored around AI sovereignty will likely shape procurement requirements, vendor due diligence standards, and regulatory expectations for enterprises operating in European markets โ CISOs should assess exposure to forthcoming AI sourcing mandates.
๐ Read full article
Risky Business News ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: DHS Inspector General scrutiny of forced CISA staff reassignments adds to concerns about the operational capacity and independence of the US federal cybersecurity authority โ CISOs relying on CISA threat intelligence, advisories, and coordination should factor in the agency's diminished capacity when planning.
๐ Read full article
The Hacker News ยท Jul 08 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: A privilege escalation flaw requiring no special permissions affecting virtually every mainstream Linux distribution since 2011 poses existential risk to enterprise server fleets, cloud workloads, and container environments โ emergency patching prioritization required across the estate.
๐ Read full article
BleepingComputer ยท Jul 07 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: A 16-year-old Linux kernel vulnerability enabling full VM escape on Intel and AMD hardware threatens the hypervisor isolation that enterprise cloud and on-premises virtualization security models depend on โ this demands immediate assessment of patching status across all virtualized infrastructure.
๐ Read full article
Jordan: A fifteen-year-old Linux kernel flaw lets any logged-in user take root with zero special permissions. Every mainstream distro since 2011. And that's not even the only ancient Linux kernel bug dropping today โ there's a separate sixteen-year-old flaw enabling full VM escape on Intel and AMD. If you run Linux anywhere โ and you do โ today's episode is not optional.
Alex: Welcome to Cleartext for Wednesday, July 8th, 2026. I'm Alex Chen, alongside Jordan Reeves. We've got a packed show. Two critical Linux kernel vulnerabilities that together threaten basically everything from your container fleet to your hypervisor boundaries. China's APT infrastructure is growing in ways that should change how you think about IP-based detection. Accenture confirmed a breach that puts its entire client base on notice. And we have documented evidence of agentic AI compressing attack timelines from weeks to three days. Plus, the EU is making moves on AI sovereignty that will reshape procurement for anyone doing business in Europe. Let's get into it.
Jordan: Let's start with the two Linux vulnerabilities because they're both genuinely critical and they compound each other. GhostLock, CVE-2026-43499 โ disclosed by Nebula Security. This is a privilege escalation flaw in the Linux kernel. It requires nothing exotic. Any authenticated user, no special permissions, no unusual configuration, gets full root. It's been sitting in every mainstream distro since 2011. Fifteen years.
Alex: And the blast radius here is what makes this a board-level conversation. This isn't a niche component. This is default kernel code shipping in Ubuntu, Red Hat, Debian, SUSE โ everything. Your on-prem servers, your cloud workloads, your container hosts. And speaking of containers, GhostLock enables container escape, which means your multi-tenant Kubernetes environments, your shared cloud infrastructure โ the isolation boundaries you're depending on are compromised.
Jordan: Then layer on Januscape. Separate vulnerability, sixteen years old, also in the Linux kernel. This one enables VM escape on both Intel and AMD hardware. So if GhostLock breaks your container isolation, Januscape breaks your hypervisor isolation. Together, these two vulnerabilities attack the two fundamental containment models that modern infrastructure relies on.
Alex: The action here is straightforward but urgent. This is an emergency patching cycle. If you're a CISO listening to this, you need your infrastructure team treating both of these as P-zero today. Not this sprint, not next maintenance window. And if you're in a cloud environment, you need to be pressing your providers โ AWS, Azure, GCP โ for confirmation that their host kernels are patched. Don't assume it.
Jordan: And for the detection side โ GhostLock requires only a logged-in user. That means any compromised service account, any low-privilege foothold an attacker already has, instantly becomes root. Your threat models around lateral movement and privilege escalation just changed.
Alex: Let's pivot to the geopolitical picture because there's a clear through-line today. Jordan, walk us through UAT-7810 and what the ORB network expansion means.
Jordan: So UAT-7810 is a Chinese APT that maintains and grows something called the LapDogs ORB network. ORB stands for Operational Relay Box. Think of it as a distributed proxy network built from compromised legitimate devices โ in this case, primarily unpatched Ruckus routers sitting on enterprise network edges. They've developed new malware called LONGLEASH specifically to expand this network. Cisco Talos has been tracking this campaign since at least June 2025, and it's actively evolving.
Alex: And for CISOs, the strategic implication is significant. ORB networks defeat IP-based detection and attribution. When the attack traffic hitting your environment originates from what looks like a legitimate enterprise router in a normal geography, your threat intel feeds, your geo-blocking, your IP reputation systems โ they all fail. This is China building persistent, distributed infrastructure that makes their operations harder to detect and nearly impossible to attribute through traditional means.
Jordan: Exactly. And this connects directly to the second China story. Wired reported on a closed-door war game simulating Volt Typhoon attacks on US water systems. This wasn't a think tank exercise. Insurers were in the room, stress-testing their exposure models against coordinated critical infrastructure disruption. The scenario produced burst water mains and hospital evacuations. And the finding was stark โ existing response frameworks and insurance models are simply not calibrated for nation-state coordinated attacks on critical infrastructure.
Alex: This matters to CISOs in two dimensions. First, if you have OT or ICS exposure, the scenario modeling coming out of these exercises should feed directly into your resilience planning. Second โ and this is the one people miss โ the insurance implications. If your cyber insurance policy has exclusions or sub-limits around acts of war or nation-state attacks, and insurers are actively war-gaming their exposure to exactly these scenarios, expect coverage terms to tighten. You need to be having that conversation with your broker now, not after an incident.
Jordan: The TechCrunch mid-year retrospective reinforces all of this. The worst breaches of 2026's first half include DOGE-related data exposure, energy and water infrastructure compromises, and the breach of an FBI surveillance system. The pattern is unmistakable โ government and critical infrastructure are under sustained, escalating pressure from both nation-states and ransomware operators. If you're preparing a board update for Q3, this retrospective is useful source material for contextualizing your own risk posture against the broader landscape.
Alex: Now let's talk about Accenture, because this has immediate third-party risk implications for a very large number of enterprises. The threat actor known as 888 claims to have stolen thirty-five gigabytes of data including source code, RSA keys, SSH keys, Azure personal access tokens, and Azure Storage access keys. Accenture has confirmed the breach, though the full scope remains unclear.
Jordan: This is a supply chain risk story. Accenture is embedded in the technology infrastructure of a significant portion of the Fortune 500. If stolen credentials include access tokens and keys tied to client environments โ and the claimed data types strongly suggest they could โ then downstream compromise is a real possibility. This isn't theoretical. Those Azure personal access tokens and storage keys could provide direct access to client cloud resources.
Alex: If Accenture is a services partner for your organization, the action is immediate. Review every shared credential arrangement, every service account, every access token that connects your environment to theirs. Rotate anything that could be compromised. And have a direct conversation with your Accenture account team about whether your environment is in scope. Don't wait for their notification.
Jordan: Let's talk about the Sygnia report on agentic AI in attacks, because this one fundamentally changes operational assumptions. They documented a real-world case โ not a lab exercise, not a proof of concept โ where an attacker used agentic AI to compress what would normally be a weeks-long cloud compromise into seventy-two hours. Automated reconnaissance, lateral movement, exploitation โ all at machine speed.
Alex: This is the story I'd flag for every CISO thinking about their SOC's detection and response SLAs. If your mean time to detect is measured in days and your mean time to contain is measured in additional days, you are now operating slower than your adversaries' automated tooling. The assumption that you have a window โ that human attackers take time to orient, to make mistakes, to move cautiously โ that assumption is eroding fast.
Jordan: And to be clear, this isn't some hypothetical future concern. This is happening now. The Sygnia case is documented. The tooling exists. The question isn't whether agentic AI will be used offensively โ it's whether your defensive automation can match the tempo. For most organizations, honestly, the answer today is no.
Alex: Staying on the identity and access front โ the DEBULL tooling campaign is worth sixty seconds because it's clever and it's actively running. This exploits Microsoft's legitimate device-code authentication flow. No fake login page. The attacker sends a collaboration-themed lure โ looks like a Teams invite, a SharePoint share โ and it pushes the user into the real Microsoft device login experience. The user authenticates against Microsoft's actual infrastructure, and the attacker captures the token.
Jordan: This is hard to detect because there's no malicious infrastructure to block. It's Microsoft's own authentication flow. Your phishing detection that keys on fake login pages misses this entirely. CISOs need to validate that conditional access policies restrict device-code flow to managed devices only, and that user awareness training covers this specific scenario. It's an active campaign running since late June.
Alex: Two governance items to close the segments. The European Commission adopted a formal communication on July 7th aimed at reducing reliance on foreign AI in cybersecurity contexts. Three pillars โ making frontier AI safe and accessible for European cybersecurity, preparing the EU's cyber ecosystem, and scaling European AI capabilities. This is regulatory direction, not regulation yet, but it signals where procurement requirements and vendor due diligence standards are heading for anyone operating in European markets.
Jordan: And the DHS Inspector General has opened an investigation into forced reassignments of CISA personnel. I'll be direct โ if you rely on CISA for threat intelligence, advisories, or coordination during incidents, you should be factoring in diminished operational capacity. The agency's independence and staffing are under pressure, and that has practical implications for the quality and timeliness of the support you can expect.
Alex: Alright, Jordan, looking at today's stories together โ what's the emerging theme?
Jordan: The theme is that the assumptions underlying most security architectures are being invalidated simultaneously. Kernel isolation โ broken by GhostLock and Januscape. IP-based detection โ defeated by ORB networks. Human-speed attack timelines โ obsoleted by agentic AI. Credential-page phishing detection โ bypassed by device-code flow abuse. Hypervisor boundaries โ compromised by VM escape. Every one of these is a foundational assumption that security programs are built on, and every one of them took a hit today.
Alex: And the meta-point for CISOs is that this isn't about any single vulnerability or technique. It's about the rate at which your defensive model's core assumptions are being challenged. The question for every security leader this week is โ when was the last time you stress-tested your architecture against the failure of its own foundational assumptions? Not individual controls, but the assumptions those controls are built on. Container isolation works. VMs are isolated from hosts. Attackers move at human speed. IP reputation is meaningful. If those assumptions fail, does your program still hold?
Jordan: That's the conversation to have with your team this week. Not just patch GhostLock โ though do that immediately โ but what else are we assuming that might not be true anymore?
Alex: That's our show for Wednesday, July 8th. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. Patch your kernels. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-08.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
๐ง Listen to this episode
Today's episode covers 10 stories across 5 topic areas, including: China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware; What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out; Hacked, leaked, and held for ransom: The worst breaches of 2026 so far.
The Hacker News ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: China's active expansion of its Operational Relay Box infrastructure through compromised networking devices indicates a persistent, growing capability to proxy malicious traffic through enterprise edge devices โ organizations must audit internet-facing routers and network appliances for signs of compromise.
๐ Read full article
Wired Security ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: A closed-door Volt Typhoon war game involving insurers surfaced critical gaps in cyber incident response for critical infrastructure disruption scenarios โ CISOs in sectors with OT/ICS exposure or insurance dependencies should examine the scenario's findings for their own resilience planning.
๐ Read full article
TechCrunch Security ยท Jul 07 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: A mid-year retrospective covering the most damaging incidents of 2026 โ including DOGE data exposure, critical energy and water system hacks, and an FBI surveillance system breach โ provides essential context for board reporting and benchmarking program priorities against actual threat patterns.
๐ Read full article
BleepingComputer ยท Jul 07 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: Accenture's confirmed breach involving source code, RSA and SSH keys, and Azure access tokens raises third-party supply chain risk concerns for any enterprise with Accenture as a technology services partner, requiring immediate review of shared credential and access arrangements.
๐ Read full article
Infosecurity Magazine ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: Documented adversarial use of agentic AI compressing a cloud attack lifecycle from weeks to 72 hours fundamentally changes incident response planning assumptions โ detection and containment SLAs built around human-speed attacks are now dangerously outdated.
๐ Read full article
The Hacker News ยท Jul 07 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: Active M365 device-code phishing campaigns bypassing traditional credential-page detection represent a direct threat to enterprise identity infrastructure โ CISOs should validate that conditional access policies and user awareness programs account for legitimate-flow abuse tactics.
๐ Read full article
The Record (Recorded Future) ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: The EU's new cybersecurity communication anchored around AI sovereignty will likely shape procurement requirements, vendor due diligence standards, and regulatory expectations for enterprises operating in European markets โ CISOs should assess exposure to forthcoming AI sourcing mandates.
๐ Read full article
Risky Business News ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: DHS Inspector General scrutiny of forced CISA staff reassignments adds to concerns about the operational capacity and independence of the US federal cybersecurity authority โ CISOs relying on CISA threat intelligence, advisories, and coordination should factor in the agency's diminished capacity when planning.
๐ Read full article
The Hacker News ยท Jul 08 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: A privilege escalation flaw requiring no special permissions affecting virtually every mainstream Linux distribution since 2011 poses existential risk to enterprise server fleets, cloud workloads, and container environments โ emergency patching prioritization required across the estate.
๐ Read full article
BleepingComputer ยท Jul 07 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: A 16-year-old Linux kernel vulnerability enabling full VM escape on Intel and AMD hardware threatens the hypervisor isolation that enterprise cloud and on-premises virtualization security models depend on โ this demands immediate assessment of patching status across all virtualized infrastructure.
๐ Read full article
Jordan: A fifteen-year-old Linux kernel flaw lets any logged-in user take root with zero special permissions. Every mainstream distro since 2011. And that's not even the only ancient Linux kernel bug dropping today โ there's a separate sixteen-year-old flaw enabling full VM escape on Intel and AMD. If you run Linux anywhere โ and you do โ today's episode is not optional.
Alex: Welcome to Cleartext for Wednesday, July 8th, 2026. I'm Alex Chen, alongside Jordan Reeves. We've got a packed show. Two critical Linux kernel vulnerabilities that together threaten basically everything from your container fleet to your hypervisor boundaries. China's APT infrastructure is growing in ways that should change how you think about IP-based detection. Accenture confirmed a breach that puts its entire client base on notice. And we have documented evidence of agentic AI compressing attack timelines from weeks to three days. Plus, the EU is making moves on AI sovereignty that will reshape procurement for anyone doing business in Europe. Let's get into it.
Jordan: Let's start with the two Linux vulnerabilities because they're both genuinely critical and they compound each other. GhostLock, CVE-2026-43499 โ disclosed by Nebula Security. This is a privilege escalation flaw in the Linux kernel. It requires nothing exotic. Any authenticated user, no special permissions, no unusual configuration, gets full root. It's been sitting in every mainstream distro since 2011. Fifteen years.
Alex: And the blast radius here is what makes this a board-level conversation. This isn't a niche component. This is default kernel code shipping in Ubuntu, Red Hat, Debian, SUSE โ everything. Your on-prem servers, your cloud workloads, your container hosts. And speaking of containers, GhostLock enables container escape, which means your multi-tenant Kubernetes environments, your shared cloud infrastructure โ the isolation boundaries you're depending on are compromised.
Jordan: Then layer on Januscape. Separate vulnerability, sixteen years old, also in the Linux kernel. This one enables VM escape on both Intel and AMD hardware. So if GhostLock breaks your container isolation, Januscape breaks your hypervisor isolation. Together, these two vulnerabilities attack the two fundamental containment models that modern infrastructure relies on.
Alex: The action here is straightforward but urgent. This is an emergency patching cycle. If you're a CISO listening to this, you need your infrastructure team treating both of these as P-zero today. Not this sprint, not next maintenance window. And if you're in a cloud environment, you need to be pressing your providers โ AWS, Azure, GCP โ for confirmation that their host kernels are patched. Don't assume it.
Jordan: And for the detection side โ GhostLock requires only a logged-in user. That means any compromised service account, any low-privilege foothold an attacker already has, instantly becomes root. Your threat models around lateral movement and privilege escalation just changed.
Alex: Let's pivot to the geopolitical picture because there's a clear through-line today. Jordan, walk us through UAT-7810 and what the ORB network expansion means.
Jordan: So UAT-7810 is a Chinese APT that maintains and grows something called the LapDogs ORB network. ORB stands for Operational Relay Box. Think of it as a distributed proxy network built from compromised legitimate devices โ in this case, primarily unpatched Ruckus routers sitting on enterprise network edges. They've developed new malware called LONGLEASH specifically to expand this network. Cisco Talos has been tracking this campaign since at least June 2025, and it's actively evolving.
Alex: And for CISOs, the strategic implication is significant. ORB networks defeat IP-based detection and attribution. When the attack traffic hitting your environment originates from what looks like a legitimate enterprise router in a normal geography, your threat intel feeds, your geo-blocking, your IP reputation systems โ they all fail. This is China building persistent, distributed infrastructure that makes their operations harder to detect and nearly impossible to attribute through traditional means.
Jordan: Exactly. And this connects directly to the second China story. Wired reported on a closed-door war game simulating Volt Typhoon attacks on US water systems. This wasn't a think tank exercise. Insurers were in the room, stress-testing their exposure models against coordinated critical infrastructure disruption. The scenario produced burst water mains and hospital evacuations. And the finding was stark โ existing response frameworks and insurance models are simply not calibrated for nation-state coordinated attacks on critical infrastructure.
Alex: This matters to CISOs in two dimensions. First, if you have OT or ICS exposure, the scenario modeling coming out of these exercises should feed directly into your resilience planning. Second โ and this is the one people miss โ the insurance implications. If your cyber insurance policy has exclusions or sub-limits around acts of war or nation-state attacks, and insurers are actively war-gaming their exposure to exactly these scenarios, expect coverage terms to tighten. You need to be having that conversation with your broker now, not after an incident.
Jordan: The TechCrunch mid-year retrospective reinforces all of this. The worst breaches of 2026's first half include DOGE-related data exposure, energy and water infrastructure compromises, and the breach of an FBI surveillance system. The pattern is unmistakable โ government and critical infrastructure are under sustained, escalating pressure from both nation-states and ransomware operators. If you're preparing a board update for Q3, this retrospective is useful source material for contextualizing your own risk posture against the broader landscape.
Alex: Now let's talk about Accenture, because this has immediate third-party risk implications for a very large number of enterprises. The threat actor known as 888 claims to have stolen thirty-five gigabytes of data including source code, RSA keys, SSH keys, Azure personal access tokens, and Azure Storage access keys. Accenture has confirmed the breach, though the full scope remains unclear.
Jordan: This is a supply chain risk story. Accenture is embedded in the technology infrastructure of a significant portion of the Fortune 500. If stolen credentials include access tokens and keys tied to client environments โ and the claimed data types strongly suggest they could โ then downstream compromise is a real possibility. This isn't theoretical. Those Azure personal access tokens and storage keys could provide direct access to client cloud resources.
Alex: If Accenture is a services partner for your organization, the action is immediate. Review every shared credential arrangement, every service account, every access token that connects your environment to theirs. Rotate anything that could be compromised. And have a direct conversation with your Accenture account team about whether your environment is in scope. Don't wait for their notification.
Jordan: Let's talk about the Sygnia report on agentic AI in attacks, because this one fundamentally changes operational assumptions. They documented a real-world case โ not a lab exercise, not a proof of concept โ where an attacker used agentic AI to compress what would normally be a weeks-long cloud compromise into seventy-two hours. Automated reconnaissance, lateral movement, exploitation โ all at machine speed.
Alex: This is the story I'd flag for every CISO thinking about their SOC's detection and response SLAs. If your mean time to detect is measured in days and your mean time to contain is measured in additional days, you are now operating slower than your adversaries' automated tooling. The assumption that you have a window โ that human attackers take time to orient, to make mistakes, to move cautiously โ that assumption is eroding fast.
Jordan: And to be clear, this isn't some hypothetical future concern. This is happening now. The Sygnia case is documented. The tooling exists. The question isn't whether agentic AI will be used offensively โ it's whether your defensive automation can match the tempo. For most organizations, honestly, the answer today is no.
Alex: Staying on the identity and access front โ the DEBULL tooling campaign is worth sixty seconds because it's clever and it's actively running. This exploits Microsoft's legitimate device-code authentication flow. No fake login page. The attacker sends a collaboration-themed lure โ looks like a Teams invite, a SharePoint share โ and it pushes the user into the real Microsoft device login experience. The user authenticates against Microsoft's actual infrastructure, and the attacker captures the token.
Jordan: This is hard to detect because there's no malicious infrastructure to block. It's Microsoft's own authentication flow. Your phishing detection that keys on fake login pages misses this entirely. CISOs need to validate that conditional access policies restrict device-code flow to managed devices only, and that user awareness training covers this specific scenario. It's an active campaign running since late June.
Alex: Two governance items to close the segments. The European Commission adopted a formal communication on July 7th aimed at reducing reliance on foreign AI in cybersecurity contexts. Three pillars โ making frontier AI safe and accessible for European cybersecurity, preparing the EU's cyber ecosystem, and scaling European AI capabilities. This is regulatory direction, not regulation yet, but it signals where procurement requirements and vendor due diligence standards are heading for anyone operating in European markets.
Jordan: And the DHS Inspector General has opened an investigation into forced reassignments of CISA personnel. I'll be direct โ if you rely on CISA for threat intelligence, advisories, or coordination during incidents, you should be factoring in diminished operational capacity. The agency's independence and staffing are under pressure, and that has practical implications for the quality and timeliness of the support you can expect.
Alex: Alright, Jordan, looking at today's stories together โ what's the emerging theme?
Jordan: The theme is that the assumptions underlying most security architectures are being invalidated simultaneously. Kernel isolation โ broken by GhostLock and Januscape. IP-based detection โ defeated by ORB networks. Human-speed attack timelines โ obsoleted by agentic AI. Credential-page phishing detection โ bypassed by device-code flow abuse. Hypervisor boundaries โ compromised by VM escape. Every one of these is a foundational assumption that security programs are built on, and every one of them took a hit today.
Alex: And the meta-point for CISOs is that this isn't about any single vulnerability or technique. It's about the rate at which your defensive model's core assumptions are being challenged. The question for every security leader this week is โ when was the last time you stress-tested your architecture against the failure of its own foundational assumptions? Not individual controls, but the assumptions those controls are built on. Container isolation works. VMs are isolated from hosts. Attackers move at human speed. IP reputation is meaningful. If those assumptions fail, does your program still hold?
Jordan: That's the conversation to have with your team this week. Not just patch GhostLock โ though do that immediately โ but what else are we assuming that might not be true anymore?
Alex: That's our show for Wednesday, July 8th. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. Patch your kernels. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-08.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.