
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
๐ง Listen to this episode
Today's episode covers 9 stories across 4 topic areas, including: China-Linked APT Expands Proxy Network With New Malware; Accenture faces massive data breach that could put clients at risk; Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours.
Infosecurity Magazine ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: China-linked UAT-7810 is actively scaling its operational relay box (ORB) proxy network with new malware, making attribution and traffic-based detection harder โ CISOs should review network egress monitoring capabilities and ensure threat intel feeds include ORB infrastructure indicators.
๐ Read full article
Cybersecurity Dive ยท Jul 08 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: Accenture's role as a top-tier systems integrator and managed services provider means stolen source code and encryption keys could expose clients across industries to downstream supply chain risk โ CISOs with Accenture relationships need to assess exposure immediately.
๐ Read full article
Dark Reading ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: A solo threat actor leveraging agentic AI compressed what previously required a team weeks of work into a 72-hour AWS compromise and extortion โ a concrete proof point that AI is lowering the barrier to sophisticated cloud attacks that CISOs must factor into risk models.
๐ Read full article
BleepingComputer ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: The Pink extortion group's vishing campaign weaponizes the trust employees place in IT helpdesk calls to hijack M365 accounts via fake Entra passkey enrollment โ CISOs rolling out passkeys as a phishing-resistant MFA upgrade must add out-of-band verification steps to counter social engineering of the enrollment process itself.
๐ Read full article
BleepingComputer ยท Jul 09 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: The breach of 6.9 million driver records from an insurance carrier is the largest known exposure of driver's license numbers in 2026 to date, raising third-party data aggregator risk considerations for CISOs whose employee or customer data may reside with insurance partners.
๐ Read full article
The Record (Recorded Future) ยท Jul 09 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: The EU's decision to sue Ireland, Spain, France, and the Netherlands for failing to transpose NIS2 signals that enforcement is accelerating โ CISOs at multinationals with EU operations must treat NIS2 compliance as urgent, not aspirational.
๐ Read full article
Risky Business News ยท Jul 09 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: A Supreme Court ruling threatening the EU-US Data Privacy Framework could again invalidate trans-Atlantic data transfer mechanisms, forcing CISOs at multinationals to revisit SCCs, data localization strategies, and legal bases for cross-border data flows.
๐ Read full article
The Record (Recorded Future) ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: A bipartisan, multi-state AG settlement against Block Inc. for misrepresenting Cash App's security protections as bank-equivalent reinforces that regulators will hold fintechs accountable for security marketing claims โ a precedent with implications for how CISOs draft public-facing security assurances.
๐ Read full article
Dark Reading ยท Jul 09 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: GodDamn ransomware is actively exploiting a Microsoft-signed malicious kernel driver via BYOVD to kill endpoint security tools at scale โ CISOs should verify their EDR vendor's kernel-level driver blocklist is current and assess exposure across Windows fleets.
๐ Read full article
Alex: Welcome to Cleartext for Thursday, July 9th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. So a solo attacker โ one person โ used AI to compromise an AWS environment and issue an extortion demand in 72 hours. Not a nation-state team. Not a ransomware crew with a dozen operators. One individual with agentic AI tooling. That's the story that should recalibrate how every CISO in this audience thinks about their threat model going into Q3.
Alex: We've got a packed show today. We're covering that AI-accelerated cloud breach, a potentially massive supply chain exposure from the Accenture breach, the EU taking its own member states to court over NIS2, a Supreme Court decision that could blow up transatlantic data transfers again, a clever vishing campaign weaponizing passkey enrollment, a ransomware crew using Microsoft-signed drivers to kill your EDR, and Chinese APT infrastructure scaling up. Let's get into it.
Jordan: Let's start with the Accenture breach because the blast radius on this one could be enormous. A threat actor is claiming they've stolen source code, encryption keys, and other sensitive data from Accenture. When we talk about supply chain risk, this is the scenario that keeps people up at night. Accenture isn't just a consultancy โ they're embedded in the infrastructure of Fortune 500 companies across every sector. They manage environments, they hold keys, they write code that runs inside your perimeter.
Alex: And the timing matters. This was reported yesterday, July 8th. The full scope is still being assessed. But if you're a CISO and Accenture touches your environment in any meaningful way โ and for a lot of our listeners, they do โ you can't wait for Accenture's incident response timeline. You need to be assessing your own exposure right now. What access do they have? What credentials are shared? What code did they deliver? This is the third-party risk management conversation that boards have been hearing about in the abstract for years, and here it is in the concrete.
Jordan: The encryption keys piece is particularly concerning. If those keys are tied to production environments at client organizations, the exposure isn't hypothetical. It's active. And the challenge is, Accenture's client list is essentially a who's who of global enterprise. So even if your organization isn't directly a client, your partners and suppliers may be.
Alex: Right. If you're a CISO listening to this, two immediate actions: pull your vendor risk file on Accenture and escalate it, and make sure your SOC is monitoring for any anomalous activity in environments where Accenture has or had access. Don't wait for the notification letter.
Jordan: Now let's talk about the story I opened with. Sygnia documented this incident โ a lone attacker using agentic AI workflows to chain together cloud misconfigurations and stolen credentials in an AWS environment. The entire attack cycle, from initial access to extortion demand, took 72 hours. To put that in context, comparable cloud compromises historically required a small team and took weeks.
Alex: This is the proof point a lot of us have been anticipating. We've been talking about AI-accelerated attacks in theoretical terms for two years. Now we have a documented case where AI compressed the attacker's timeline by an order of magnitude. And it wasn't a sophisticated nation-state actor โ it was a single individual. That's the part that should change your risk calculus.
Jordan: What it really does is collapse the assumption that complexity equals safety. If your AWS environment has misconfigurations โ and let's be honest, most do โ the window between those misconfigurations being discoverable and being exploited just got dramatically shorter. Your cloud security posture management tools need to be operating in near real-time, not weekly scan cadence.
Alex: And it raises a resource asymmetry question for defenders. If one person with AI tooling can do what a team of five used to do, then our defensive automation needs to keep pace. This isn't a scare story. It's a planning input for your 2027 budget conversations.
Jordan: Let's pivot to the vishing campaign because it's clever and it's hitting right now. The Pink extortion crew is calling employees, impersonating IT helpdesk, and walking them through enrolling attacker-controlled passkeys into Microsoft Entra ID. No malware required. The victim thinks they're being a good employee following IT instructions, and they're handing over their M365 account.
Alex: This is deeply ironic because passkeys are supposed to be the phishing-resistant upgrade. And they are โ against traditional phishing. But the enrollment process itself is the vulnerability here. If you can social engineer someone into registering your passkey on their account, you've bypassed the entire security model. This should be a wake-up call for any CISO in the middle of a passkey rollout.
Jordan: The fix isn't to stop rolling out passkeys. It's to add out-of-band verification to the enrollment process. A callback on a verified number. A ticket confirmation through a separate channel. Something that breaks the single-channel social engineering vector. If your enrollment process is "someone calls you and tells you to do a thing," you're exposed.
Alex: Agreed. And train your helpdesk staff that they should never be initiating unsolicited passkey enrollment calls. Make it policy, make it auditable.
Jordan: Now, governance. And today we've got two big ones. First, the EU is taking Ireland, Spain, France, and the Netherlands to court for failing to transpose NIS2 into national law. These are major economies, and they're more than 20 months late.
Alex: This is significant. The European Commission doesn't take member states to court casually. This is an escalation that signals NIS2 enforcement is no longer aspirational โ it's becoming adversarial. For CISOs at multinationals with EU operations, the message is clear: even if the country you operate in hasn't formally adopted NIS2 into local law, the directive's requirements are the standard the Commission expects. You need to be building to NIS2 requirements now, not waiting for your local regulator to catch up.
Jordan: And the fact that it's Ireland and the Netherlands โ two of the biggest hosting and data center jurisdictions in Europe โ makes this particularly relevant for cloud-first organizations. Those are the countries where a huge amount of EU data processing happens.
Alex: The second governance story is potentially even bigger in its long-term impact. A new Supreme Court decision is putting the EU-US Data Privacy Framework at legal risk. This is the successor to Privacy Shield, which was the successor to Safe Harbor. If this framework falls, we're looking at Schrems III.
Jordan: For those keeping score at home, this would be the third time the legal basis for transatlantic data transfers gets invalidated. The Supreme Court decision threatens the adequacy determination by weakening the judicial review protections that the EU required. Section 702 collection from Europe is at the center of it โ again.
Alex: If you're a CISO at a multinational, this needs to be on your legal team's radar yesterday. You should already have Standard Contractual Clauses in place as a backup, and you should be evaluating data localization options for your most sensitive EU data. We've been through this cycle twice before. The organizations that moved early came out ahead.
Jordan: And the intelligence community angle here is real. If this agreement collapses, Section 702 collection from European targets gets severely curtailed. That has downstream effects on the threat intelligence that feeds into cybersecurity defense. It's a lose-lose.
Alex: Let's touch on the Block settlement. Cash App's parent company is paying $45 million to settle multi-state AG allegations that they misrepresented Cash App's security protections as being equivalent to a bank's. This was bipartisan โ attorneys general from both parties.
Jordan: The precedent here is about security marketing claims. If your public-facing materials say "bank-grade security" or "enterprise-grade protection" and your actual controls don't support that, you're exposed to regulatory action. CISOs should be reviewing any public security assurances their marketing teams have put out.
Alex: It's a good reminder that your security posture and your security messaging need to be in alignment. And that's a CISO responsibility, not just a legal or marketing one.
Jordan: Moving to vulnerabilities and active threats. GodDamn ransomware โ apparently a rebrand of the Beast family, first spotted in the wild May 21st โ is using a Bring Your Own Vulnerable Driver technique with a twist. The PoisonX kernel driver they're using is actually signed by Microsoft. So it's a legitimate signed driver being used to kill endpoint security software before encryption.
Alex: This is a known technique category, but the Microsoft-signed driver detail is the concern. Your EDR blocklists need to include this specific driver. If your vendor hasn't updated their kernel driver blocklist to account for PoisonX, push them on it today. This is actively hitting US companies right now.
Jordan: And more broadly, BYOVD continues to be a gap in a lot of organizations' defensive posture. Windows Defender Application Control driver blocklists exist. Microsoft's vulnerable driver blocklist exists. But they're not always enabled or current. It's worth a quick audit.
Alex: Last story. Cisco Talos has identified China-linked APT UAT-7810 expanding its Operational Relay Box proxy network with new malware. ORB networks are the infrastructure layer Chinese APTs use to obfuscate their attack origins.
Jordan: This is an infrastructure story, not an attack story, and that's what makes it important. When a Chinese APT invests in scaling its proxy infrastructure, it means they're preparing for increased operational tempo. They're building capacity. Your threat intel feeds need to include ORB network indicators, and your network egress monitoring should be tuned to detect traffic patterns consistent with proxy relay communications.
Alex: It's the kind of story that doesn't have an immediate action item beyond "stay vigilant," but it's an important signal about the threat landscape trajectory.
Jordan: So stepping back and looking at the week, Alex, I see a convergence. The Accenture breach is supply chain risk materialized. The AI-enabled cloud attack is the attacker efficiency story we've been warning about. The passkey vishing campaign shows that even our best defensive technologies have enrollment-process vulnerabilities. And the governance stories โ NIS2, data transfers, the Block settlement โ all point to regulators tightening the screws from every direction.
Alex: The theme I'd pull out is this: the gap between where CISOs need to be and where many organizations actually are is widening. Attackers are moving faster thanks to AI. Regulators are moving faster thanks to political pressure. And the supply chain attack surface is expanding, not contracting. If your security program is running on 2024 assumptions, you're already behind.
Jordan: And I'd add โ watch the EU-US data transfer situation closely over the next 30 days. If that framework wobbles, it will consume enormous amounts of legal and compliance bandwidth at exactly the moment when operational security needs the most attention. Prioritize accordingly.
Alex: That's our show for Thursday, July 9th. Show notes and links to every story we covered today are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-09.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
๐ง Listen to this episode
Today's episode covers 9 stories across 4 topic areas, including: China-Linked APT Expands Proxy Network With New Malware; Accenture faces massive data breach that could put clients at risk; Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours.
Infosecurity Magazine ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: China-linked UAT-7810 is actively scaling its operational relay box (ORB) proxy network with new malware, making attribution and traffic-based detection harder โ CISOs should review network egress monitoring capabilities and ensure threat intel feeds include ORB infrastructure indicators.
๐ Read full article
Cybersecurity Dive ยท Jul 08 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: Accenture's role as a top-tier systems integrator and managed services provider means stolen source code and encryption keys could expose clients across industries to downstream supply chain risk โ CISOs with Accenture relationships need to assess exposure immediately.
๐ Read full article
Dark Reading ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: A solo threat actor leveraging agentic AI compressed what previously required a team weeks of work into a 72-hour AWS compromise and extortion โ a concrete proof point that AI is lowering the barrier to sophisticated cloud attacks that CISOs must factor into risk models.
๐ Read full article
BleepingComputer ยท Jul 08 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: The Pink extortion group's vishing campaign weaponizes the trust employees place in IT helpdesk calls to hijack M365 accounts via fake Entra passkey enrollment โ CISOs rolling out passkeys as a phishing-resistant MFA upgrade must add out-of-band verification steps to counter social engineering of the enrollment process itself.
๐ Read full article
BleepingComputer ยท Jul 09 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: The breach of 6.9 million driver records from an insurance carrier is the largest known exposure of driver's license numbers in 2026 to date, raising third-party data aggregator risk considerations for CISOs whose employee or customer data may reside with insurance partners.
๐ Read full article
The Record (Recorded Future) ยท Jul 09 ยท Relevance: โโโโโโโโโโ 9/10
Why it matters to CISOs: The EU's decision to sue Ireland, Spain, France, and the Netherlands for failing to transpose NIS2 signals that enforcement is accelerating โ CISOs at multinationals with EU operations must treat NIS2 compliance as urgent, not aspirational.
๐ Read full article
Risky Business News ยท Jul 09 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: A Supreme Court ruling threatening the EU-US Data Privacy Framework could again invalidate trans-Atlantic data transfer mechanisms, forcing CISOs at multinationals to revisit SCCs, data localization strategies, and legal bases for cross-border data flows.
๐ Read full article
The Record (Recorded Future) ยท Jul 08 ยท Relevance: โโโโโโโโโโ 7/10
Why it matters to CISOs: A bipartisan, multi-state AG settlement against Block Inc. for misrepresenting Cash App's security protections as bank-equivalent reinforces that regulators will hold fintechs accountable for security marketing claims โ a precedent with implications for how CISOs draft public-facing security assurances.
๐ Read full article
Dark Reading ยท Jul 09 ยท Relevance: โโโโโโโโโโ 8/10
Why it matters to CISOs: GodDamn ransomware is actively exploiting a Microsoft-signed malicious kernel driver via BYOVD to kill endpoint security tools at scale โ CISOs should verify their EDR vendor's kernel-level driver blocklist is current and assess exposure across Windows fleets.
๐ Read full article
Alex: Welcome to Cleartext for Thursday, July 9th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. So a solo attacker โ one person โ used AI to compromise an AWS environment and issue an extortion demand in 72 hours. Not a nation-state team. Not a ransomware crew with a dozen operators. One individual with agentic AI tooling. That's the story that should recalibrate how every CISO in this audience thinks about their threat model going into Q3.
Alex: We've got a packed show today. We're covering that AI-accelerated cloud breach, a potentially massive supply chain exposure from the Accenture breach, the EU taking its own member states to court over NIS2, a Supreme Court decision that could blow up transatlantic data transfers again, a clever vishing campaign weaponizing passkey enrollment, a ransomware crew using Microsoft-signed drivers to kill your EDR, and Chinese APT infrastructure scaling up. Let's get into it.
Jordan: Let's start with the Accenture breach because the blast radius on this one could be enormous. A threat actor is claiming they've stolen source code, encryption keys, and other sensitive data from Accenture. When we talk about supply chain risk, this is the scenario that keeps people up at night. Accenture isn't just a consultancy โ they're embedded in the infrastructure of Fortune 500 companies across every sector. They manage environments, they hold keys, they write code that runs inside your perimeter.
Alex: And the timing matters. This was reported yesterday, July 8th. The full scope is still being assessed. But if you're a CISO and Accenture touches your environment in any meaningful way โ and for a lot of our listeners, they do โ you can't wait for Accenture's incident response timeline. You need to be assessing your own exposure right now. What access do they have? What credentials are shared? What code did they deliver? This is the third-party risk management conversation that boards have been hearing about in the abstract for years, and here it is in the concrete.
Jordan: The encryption keys piece is particularly concerning. If those keys are tied to production environments at client organizations, the exposure isn't hypothetical. It's active. And the challenge is, Accenture's client list is essentially a who's who of global enterprise. So even if your organization isn't directly a client, your partners and suppliers may be.
Alex: Right. If you're a CISO listening to this, two immediate actions: pull your vendor risk file on Accenture and escalate it, and make sure your SOC is monitoring for any anomalous activity in environments where Accenture has or had access. Don't wait for the notification letter.
Jordan: Now let's talk about the story I opened with. Sygnia documented this incident โ a lone attacker using agentic AI workflows to chain together cloud misconfigurations and stolen credentials in an AWS environment. The entire attack cycle, from initial access to extortion demand, took 72 hours. To put that in context, comparable cloud compromises historically required a small team and took weeks.
Alex: This is the proof point a lot of us have been anticipating. We've been talking about AI-accelerated attacks in theoretical terms for two years. Now we have a documented case where AI compressed the attacker's timeline by an order of magnitude. And it wasn't a sophisticated nation-state actor โ it was a single individual. That's the part that should change your risk calculus.
Jordan: What it really does is collapse the assumption that complexity equals safety. If your AWS environment has misconfigurations โ and let's be honest, most do โ the window between those misconfigurations being discoverable and being exploited just got dramatically shorter. Your cloud security posture management tools need to be operating in near real-time, not weekly scan cadence.
Alex: And it raises a resource asymmetry question for defenders. If one person with AI tooling can do what a team of five used to do, then our defensive automation needs to keep pace. This isn't a scare story. It's a planning input for your 2027 budget conversations.
Jordan: Let's pivot to the vishing campaign because it's clever and it's hitting right now. The Pink extortion crew is calling employees, impersonating IT helpdesk, and walking them through enrolling attacker-controlled passkeys into Microsoft Entra ID. No malware required. The victim thinks they're being a good employee following IT instructions, and they're handing over their M365 account.
Alex: This is deeply ironic because passkeys are supposed to be the phishing-resistant upgrade. And they are โ against traditional phishing. But the enrollment process itself is the vulnerability here. If you can social engineer someone into registering your passkey on their account, you've bypassed the entire security model. This should be a wake-up call for any CISO in the middle of a passkey rollout.
Jordan: The fix isn't to stop rolling out passkeys. It's to add out-of-band verification to the enrollment process. A callback on a verified number. A ticket confirmation through a separate channel. Something that breaks the single-channel social engineering vector. If your enrollment process is "someone calls you and tells you to do a thing," you're exposed.
Alex: Agreed. And train your helpdesk staff that they should never be initiating unsolicited passkey enrollment calls. Make it policy, make it auditable.
Jordan: Now, governance. And today we've got two big ones. First, the EU is taking Ireland, Spain, France, and the Netherlands to court for failing to transpose NIS2 into national law. These are major economies, and they're more than 20 months late.
Alex: This is significant. The European Commission doesn't take member states to court casually. This is an escalation that signals NIS2 enforcement is no longer aspirational โ it's becoming adversarial. For CISOs at multinationals with EU operations, the message is clear: even if the country you operate in hasn't formally adopted NIS2 into local law, the directive's requirements are the standard the Commission expects. You need to be building to NIS2 requirements now, not waiting for your local regulator to catch up.
Jordan: And the fact that it's Ireland and the Netherlands โ two of the biggest hosting and data center jurisdictions in Europe โ makes this particularly relevant for cloud-first organizations. Those are the countries where a huge amount of EU data processing happens.
Alex: The second governance story is potentially even bigger in its long-term impact. A new Supreme Court decision is putting the EU-US Data Privacy Framework at legal risk. This is the successor to Privacy Shield, which was the successor to Safe Harbor. If this framework falls, we're looking at Schrems III.
Jordan: For those keeping score at home, this would be the third time the legal basis for transatlantic data transfers gets invalidated. The Supreme Court decision threatens the adequacy determination by weakening the judicial review protections that the EU required. Section 702 collection from Europe is at the center of it โ again.
Alex: If you're a CISO at a multinational, this needs to be on your legal team's radar yesterday. You should already have Standard Contractual Clauses in place as a backup, and you should be evaluating data localization options for your most sensitive EU data. We've been through this cycle twice before. The organizations that moved early came out ahead.
Jordan: And the intelligence community angle here is real. If this agreement collapses, Section 702 collection from European targets gets severely curtailed. That has downstream effects on the threat intelligence that feeds into cybersecurity defense. It's a lose-lose.
Alex: Let's touch on the Block settlement. Cash App's parent company is paying $45 million to settle multi-state AG allegations that they misrepresented Cash App's security protections as being equivalent to a bank's. This was bipartisan โ attorneys general from both parties.
Jordan: The precedent here is about security marketing claims. If your public-facing materials say "bank-grade security" or "enterprise-grade protection" and your actual controls don't support that, you're exposed to regulatory action. CISOs should be reviewing any public security assurances their marketing teams have put out.
Alex: It's a good reminder that your security posture and your security messaging need to be in alignment. And that's a CISO responsibility, not just a legal or marketing one.
Jordan: Moving to vulnerabilities and active threats. GodDamn ransomware โ apparently a rebrand of the Beast family, first spotted in the wild May 21st โ is using a Bring Your Own Vulnerable Driver technique with a twist. The PoisonX kernel driver they're using is actually signed by Microsoft. So it's a legitimate signed driver being used to kill endpoint security software before encryption.
Alex: This is a known technique category, but the Microsoft-signed driver detail is the concern. Your EDR blocklists need to include this specific driver. If your vendor hasn't updated their kernel driver blocklist to account for PoisonX, push them on it today. This is actively hitting US companies right now.
Jordan: And more broadly, BYOVD continues to be a gap in a lot of organizations' defensive posture. Windows Defender Application Control driver blocklists exist. Microsoft's vulnerable driver blocklist exists. But they're not always enabled or current. It's worth a quick audit.
Alex: Last story. Cisco Talos has identified China-linked APT UAT-7810 expanding its Operational Relay Box proxy network with new malware. ORB networks are the infrastructure layer Chinese APTs use to obfuscate their attack origins.
Jordan: This is an infrastructure story, not an attack story, and that's what makes it important. When a Chinese APT invests in scaling its proxy infrastructure, it means they're preparing for increased operational tempo. They're building capacity. Your threat intel feeds need to include ORB network indicators, and your network egress monitoring should be tuned to detect traffic patterns consistent with proxy relay communications.
Alex: It's the kind of story that doesn't have an immediate action item beyond "stay vigilant," but it's an important signal about the threat landscape trajectory.
Jordan: So stepping back and looking at the week, Alex, I see a convergence. The Accenture breach is supply chain risk materialized. The AI-enabled cloud attack is the attacker efficiency story we've been warning about. The passkey vishing campaign shows that even our best defensive technologies have enrollment-process vulnerabilities. And the governance stories โ NIS2, data transfers, the Block settlement โ all point to regulators tightening the screws from every direction.
Alex: The theme I'd pull out is this: the gap between where CISOs need to be and where many organizations actually are is widening. Attackers are moving faster thanks to AI. Regulators are moving faster thanks to political pressure. And the supply chain attack surface is expanding, not contracting. If your security program is running on 2024 assumptions, you're already behind.
Jordan: And I'd add โ watch the EU-US data transfer situation closely over the next 30 days. If that framework wobbles, it will consume enormous amounts of legal and compliance bandwidth at exactly the moment when operational security needs the most attention. Prioritize accordingly.
Alex: That's our show for Thursday, July 9th. Show notes and links to every story we covered today are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-09.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.