Cleartext

Cleartext – July 10, 2026


Listen Later

Cleartext – July 10, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 4 topic areas, including: NSA revives 'Tailored Access Operations' name for elite hacking unit; China, India ran separate spying campaigns against same Pakistani police force; New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware.

Stories Covered
🌍 Geopolitical
NSA revives 'Tailored Access Operations' name for elite hacking unit

The Record (Recorded Future) Β· Jul 09 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

Why it matters to CISOs: The NSA's deliberate rebranding of its elite offensive cyber unit back to the historically significant TAO name is a public posture signal, suggesting a more assertive US offensive cyber stance that CISOs should factor into geopolitical threat modeling and potential blowback risk from adversary nations.

  • NSA renamed its Office of Computer Network Operations back to Tailored Access Operations (TAO) last week
  • TAO is NSA's premier offensive hacking unit with roots in the early 1990s and was previously publicly exposed in the Snowden disclosures
  • The rebranding is seen as a deliberate public posture signal about US offensive cyber intent
  • πŸ“– Read full article

    China, India ran separate spying campaigns against same Pakistani police force

    The Record (Recorded Future) Β· Jul 10 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

    Why it matters to CISOs: The simultaneous, independent compromise of the same systems by two nation-state actors illustrates how contested geopolitical terrain translates into overlapping threat actor presence on enterprise infrastructureβ€”particularly relevant for multinationals with operations or supply chain exposure in South Asia.

    • Both Chinese and Indian state-linked actors independently breached the same Pakistani police systems responsible for a conflict-affected southwestern province
    • The overlapping campaigns ran from February 2024 through April 2026
    • The incident demonstrates that high-value targets attract simultaneous nation-state intrusions, complicating attribution and incident response
    • πŸ“– Read full article

      New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

      The Hacker News Β· Jul 09 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

      Why it matters to CISOs: GigaWiper's modular designβ€”combining disk wipers, fake ransomware, and spyware in a single operator-selectable toolkitβ€”represents a strategic escalation in destructive malware capability that CISOs at critical infrastructure or geopolitically exposed organizations must incorporate into worst-case response planning.

      • Microsoft identified GigaWiper as a destructive Windows backdoor combining three payloads: full disk wiper, Windows drive overwriter, and fake ransomware with no recoverable key
      • The toolkit is modular, allowing operators to select which destructive method to deploy
      • The fake ransomware component is specifically designed to delay victim response by creating false hope of decryption
      • πŸ“– Read full article

        πŸ“‘ Macro Trends
        Ransomware ecosystem grows, but β€˜four-headed monster’ dominates

        Cybersecurity Dive Β· Jul 09 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

        Why it matters to CISOs: GuidePoint's findings that four dominant ransomware groups account for a disproportionate share of attacks, with AI automating human attacker behaviors rather than fundamentally changing them, gives CISOs a realistic threat landscape to brief boards against without overhyping AI-native threats.

        • Four dominant ransomware groups account for the majority of enterprise ransomware attacks despite overall ecosystem growth
        • AI is accelerating ransomware operations primarily by automating existing human-driven tasks such as reconnaissance and lure creation
        • The report provides empirical basis for prioritizing defenses against a concentrated set of well-resourced adversaries
        • πŸ“– Read full article

          πŸ”“ Data Breach
          Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

          The Hacker News Β· Jul 10 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

          Why it matters to CISOs: Threat actors are now specifically targeting the passkey enrollment process itself, undermining phishing-resistant MFA rollouts; CISOs accelerating Entra passkey adoption need to add enrollment verification controls and user education as a distinct attack surface.

          • Threat actor O-UNC-066 uses voice-based vishing to trick Microsoft 365 users into enrolling attacker-controlled passkeys into Entra
          • A panel-controlled phishing kit specifically targets the passkey enrollment workflow, bypassing the protection passkeys are meant to provide
          • Attacks span multiple sectors and culminate in data extortion
          • πŸ“– Read full article

            New Helix vishing group emerges in SharePoint data theft attacks

            BleepingComputer Β· Jul 09 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

            Why it matters to CISOs: Helix represents a new identity-focused extortion group combining vishing, device code phishing, and MFA abuse to exfiltrate SharePoint dataβ€”a direct threat to enterprises relying on Microsoft 365 as a collaboration backbone, requiring immediate review of device code flow permissions and MFA policies.

            • Helix is a newly identified data-extortion group using vishing, device code phishing, and MFA abuse in combination
            • Attacks specifically target SharePoint environments for data theft and extortion
            • The group's tactics overlap with and complement those of O-UNC-066 targeting Entra passkey enrollment, suggesting a broader wave of identity-focused Microsoft 365 attacks
            • πŸ“– Read full article

              βš–οΈ Governance & Policy
              EU takes member states to court over unimplemented cybersecurity law

              The Record (Recorded Future) Β· Jul 09 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

              Why it matters to CISOs: EU legal action against Ireland, Spain, France, and the Netherlands for NIS2 non-transposition signals escalating enforcement pressure; CISOs in or operating within those jurisdictions face compounding regulatory uncertainty and must track compliance obligations that may land unevenly across markets.

              • Ireland, Spain, France, and the Netherlands are more than 20 months late transposing the NIS2 Directive into national law
              • The European Commission has taken formal court action against these four member states
              • NIS2 governs cybersecurity obligations for critical infrastructure operators across the EU
              • πŸ“– Read full article

                Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail

                CyberScoop Β· Jul 10 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                Why it matters to CISOs: This case establishes a high-profile precedent for criminal liability arising from insider betrayal within the ransomware response supply chain, prompting CISOs to reassess vetting and oversight of third-party incident response and negotiation vendors who gain privileged access during crises.

                • Angelo Martino, a former DigitalMint employee, was sentenced to 70 months for feeding confidential client information to BlackCat ransomware co-conspirators
                • The scheme resulted in $75.3 million extorted from five U.S.-based victim organizations
                • Martino exploited his insider position as a ransomware negotiator to enable attacks on the very clients he was supposed to protect
                • πŸ“– Read full article

                  Microsoft is rewriting Windows patch guidance because of AI

                  Help Net Security Β· Jul 10 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                  Why it matters to CISOs: Microsoft is formally advising enterprises to compress their Windows patch deployment windows, citing AI-accelerated exploit development as shrinking the safe window between patch release and weaponizationβ€”a direct operational requirement for CISOs to bring to patch management governance conversations.

                  • Microsoft is recommending organizations shorten Windows update deployment timelines in response to AI reducing attacker time-to-exploit after patch release
                  • The guidance specifically targets devices where shorter deployment windows can be implemented without operational disruption
                  • This signals a structural shift in patch SLA expectations that enterprise security programs will need to formalize
                  • πŸ“– Read full article

                    Further Reading
                    • 🌍 NSA revives 'Tailored Access Operations' name for elite hacking unit β€” The Record (Recorded Future)
                    • 🌍 China, India ran separate spying campaigns against same Pakistani police force β€” The Record (Recorded Future)
                    • 🌍 New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware β€” The Hacker News
                    • πŸ“‘ Ransomware ecosystem grows, but β€˜four-headed monster’ dominates β€” Cybersecurity Dive
                    • πŸ”“ Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access β€” The Hacker News
                    • πŸ”“ New Helix vishing group emerges in SharePoint data theft attacks β€” BleepingComputer
                    • βš–οΈ EU takes member states to court over unimplemented cybersecurity law β€” The Record (Recorded Future)
                    • βš–οΈ Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail β€” CyberScoop
                    • βš–οΈ Microsoft is rewriting Windows patch guidance because of AI β€” Help Net Security
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext. It's Friday, July 10th, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves.

                      Alex: Jordan, you want to set the table for us?

                      Jordan: Yeah. So, the EU just took four of its own member states to court for failing to implement NIS2, the cybersecurity directive that was supposed to be law over twenty months ago. Ireland, Spain, France, the Netherlands. These aren't backwater jurisdictions. These are core EU economies. And the Commission isn't sending a polite letter anymore. They're filing in the European Court of Justice.

                      Alex: That's where we're starting today. We've also got the NSA bringing back the TAO name, which Jordan has feelings about. A genuinely disturbing new malware toolkit from Microsoft's threat intel team. A ransomware negotiator who went to prison for betraying his own clients. And a new wave of attacks that are specifically targeting passkey enrollment, which should worry anyone in the middle of a phishing-resistant MFA rollout. Let's get into it.

                      Jordan: Let's start with NIS2 because I think the CISO implications here are underappreciated. When four major member states are twenty months late transposing a directive, what you get is regulatory fragmentation. If you're a multinational operating across the EU, you don't have one cybersecurity compliance framework. You have a patchwork. Some countries have implemented, some haven't, and now there's active litigation creating even more uncertainty about timelines.

                      Alex: This is a board-level problem. I've been in rooms where the question is, "Are we NIS2 compliant?" And the honest answer for a lot of organizations operating in these four countries is, "We don't fully know what compliant means yet because the national transposition hasn't happened." That doesn't fly with a board. They want a yes or a no. So what do you do? You build to the directive's requirements as written and hope the national implementations don't diverge too far.

                      Jordan: Which is the right call, but it costs more. You're essentially over-engineering compliance in the absence of clarity. And now the Commission taking court action signals that enforcement pressure is only going up. This isn't going away quietly.

                      Alex: If you're a CISO in one of these jurisdictions, the action item is straightforward. Brief your legal team and your board that formal enforcement proceedings are underway. Document your compliance posture against the directive itself. And be prepared for an accelerated national implementation timeline, because court action tends to focus political attention.

                      Jordan: Alright, let's shift to something near and dear to my heart. The NSA has renamed its Office of Computer Network Operations back to Tailored Access Operations. TAO. For those who don't know the history, TAO was the name publicly exposed in the Snowden disclosures. It's the NSA's premier offensive hacking unit, operational since the early nineties.

                      Alex: And renaming it back is not nostalgia.

                      Jordan: No. It's a signal. You don't resurrect the most recognizable name in offensive cyber operations by accident. This is the agency telling adversaries, and frankly telling the domestic policy community, that the US is leaning into a more assertive offensive cyber posture. It's branding as strategy.

                      Alex: So what does this mean for CISOs?

                      Jordan: Two things. First, geopolitical threat modeling. When the US signals offensive escalation, adversaries respond. We should expect increased probing and retaliatory operations from the usual suspects: China, Russia, Iran. Not necessarily against the government, but against private sector targets that serve as proxies or pressure points. Second, if you're in defense industrial base, critical infrastructure, or technology sectors, your threat surface just got more interesting.

                      Alex: And that connects directly to our next story, which is a perfect case study in what overlapping nation-state operations actually look like on the ground. Researchers found that both Chinese and Indian state-linked threat actors independently compromised the same Pakistani police systems over a two-year period, February 2024 through April 2026. Same systems. Different campaigns. Neither apparently aware of the other.

                      Jordan: This is the reality of contested geopolitical terrain. When a target sits at the intersection of multiple nations' intelligence priorities, you don't get one adversary. You get several, and they stack up on the same infrastructure. For CISOs at multinationals with operations or supply chain exposure in South Asia, this is directly relevant. Your systems in those regions may already host more than one uninvited guest.

                      Alex: And the incident response implications are significant. When you discover a compromise, you can't assume you've found the only one. Attribution gets harder. Remediation gets more complex. You need to scope for multiple independent intrusions, not just one.

                      Jordan: Which is expensive and time-consuming. But it's the reality of operating in geopolitically contested environments.

                      Alex: Let's talk about GigaWiper, because this is a piece of malware that I think represents a meaningful escalation in destructive capability. Microsoft's threat intelligence team published analysis of a Windows backdoor that bundles three distinct destructive payloads into a single modular toolkit. Full disk wiper. Windows drive overwriter. And fake ransomware that encrypts files with a key it deliberately never saves.

                      Jordan: The modularity is what matters here. This isn't one tool that does one thing. It's an operator-selectable menu. The attacker gets in, assesses the situation, and picks which destruction method fits their objective. And that fake ransomware component is particularly nasty. It's designed to create false hope. The victim sees a ransom note, thinks there's a path to recovery, and wastes critical response hours pursuing a decryption key that doesn't exist.

                      Alex: That's time the attacker uses for lateral movement, additional exfiltration, or simply watching the chaos unfold. For CISOs at critical infrastructure organizations or anyone with geopolitical exposure, this needs to go into your worst-case tabletop scenarios. Are your response plans built for a scenario where what looks like ransomware is actually a wiper?

                      Jordan: And can your team distinguish between the two fast enough to make the right containment decisions? Because the playbooks are very different. If it's ransomware, you might negotiate. If it's a wiper masquerading as ransomware, every minute you spend negotiating is a minute you're not isolating.

                      Alex: Speaking of ransomware, let's hit the GuidePoint report quickly. Their latest findings show that despite the overall ecosystem growing, four dominant groups account for a disproportionate share of enterprise attacks. And the AI angle is more nuanced than the headlines suggest. AI is automating existing attacker behaviors, reconnaissance, lure creation, but it's not fundamentally changing the attack model.

                      Jordan: Which is actually useful information for CISOs. It means your existing defensive architecture is still relevant. You're not facing a paradigm shift. You're facing the same adversaries moving faster and at higher volume. And concentration matters. If four groups dominate, you can study their TTPs, map your defenses against them specifically, and brief your board with empirical data rather than vague AI fear.

                      Alex: Now, Microsoft picking up on that AI acceleration theme has rewritten its Windows patch deployment guidance. They're formally advising enterprises to compress deployment timelines because AI is shrinking the window between patch release and weaponized exploit.

                      Jordan: This is the operational consequence of what GuidePoint is describing. AI makes attackers faster at reverse-engineering patches. So the safe window between Patch Tuesday and active exploitation is narrowing. Microsoft is essentially telling you your current patch SLAs may be too slow.

                      Alex: For CISOs, this is a governance conversation. You need to revisit your patch management policies with your IT operations teams and formalize shorter deployment windows, at least for internet-facing and high-value assets. If your current SLA is fourteen days, that may need to come down to seven or less for critical patches. And yes, that's hard operationally. But Microsoft isn't making this recommendation casually.

                      Jordan: Alright, let's talk about what I think is the most operationally urgent cluster of stories this week. Two related campaigns targeting Microsoft 365 identity infrastructure. First, a threat actor tracked as O-UNC-066 is using vishing to trick users into enrolling attacker-controlled passkeys into Microsoft Entra. Second, a new group called Helix is combining vishing, device code phishing, and MFA abuse to exfiltrate data from SharePoint environments.

                      Alex: This is a direct attack on the thing we've been telling people to deploy. Passkeys are supposed to be the answer to phishing. They are phishing-resistant by design. But what these attackers have figured out is that the enrollment process itself is vulnerable. If you can social engineer someone into registering your passkey instead of their own, you've bypassed the protection entirely.

                      Jordan: And they're doing it at scale with a panel-controlled phishing kit. This isn't bespoke. It's tooled. Multiple sectors are being hit. The Helix group adds another layer by going after device code flows, which many organizations haven't locked down because they don't think of them as an attack surface.

                      Alex: The action items here are concrete. One, review and restrict who can enroll passkeys in Entra, and add out-of-band verification for new enrollments. Two, audit device code flow permissions and disable them where they're not operationally necessary. Three, update your user awareness training to specifically cover vishing scenarios targeting passkey enrollment. This is not generic phishing awareness. This is a specific, novel attack vector.

                      Jordan: And if you're in the middle of a passkey rollout, don't stop. But treat enrollment security as a first-class design requirement, not an afterthought.

                      Alex: Last story, and it's a striking one. Angelo Martino, a former ransomware negotiator at DigitalMint, was sentenced to seventy months in federal prison for feeding confidential client information to BlackCat ransomware affiliates. His betrayal enabled seventy-five million dollars in extortion across five US organizations. He was supposed to be helping victims. Instead, he was arming the attackers.

                      Jordan: This is the nightmare scenario for the incident response supply chain. During a ransomware event, you're at your most vulnerable. You're bringing in outside help, giving them privileged access to your most sensitive data, your financials, your negotiation strategy, your recovery capabilities. And this guy used all of that to help the other side.

                      Alex: The precedent matters. Seventy months is serious prison time. It signals that the justice system treats this kind of insider betrayal in the cyber response chain as a serious crime. But for CISOs, the lesson is about vendor risk management during crises. How well do you vet your incident response partners? Do you have contractual controls and monitoring in place for third parties who gain privileged access during an incident?

                      Jordan: Most organizations don't. In the heat of a crisis, you're not running background checks. You're trusting the firm's reputation. This case says that's not enough.

                      Alex: Alright, let's wrap with what we're watching. Jordan, what's the thread you're pulling on this week?

                      Jordan: Identity is the battlefield. Between the passkey enrollment attacks, Helix targeting SharePoint through MFA abuse, and the broader trend of social engineering bypassing technical controls, the message is clear. The perimeter has fully collapsed into identity. And the attackers are adapting faster than most enterprises are hardening their identity infrastructure.

                      Alex: I agree. And I'd add the regulatory dimension. Between NIS2 enforcement, Microsoft rewriting patch guidance, and a ransomware negotiator going to prison, the governance environment is tightening from every direction. Boards are going to be asking harder questions about compliance timelines, vendor oversight, and operational response speed. CISOs need to get ahead of those conversations, not react to them.

                      Jordan: And the TAO rebranding tells me the geopolitical temperature is going up, not down. Plan accordingly.

                      Alex: That's our show for Friday, July 10th. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend. Stay sharp.

                      Jordan: See you Monday.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-10.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext