
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 8 stories across 4 topic areas, including: Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions; EU sanctions Russian GRU military hackers over cyberattacks; US and allies warn of Russian critical infrastructure attacks.
The Record (Recorded Future) Β· Jul 12 Β· Relevance: ββββββββββ 10/10
Why it matters to CISOs: The first joint UK-EU cyber sanctions package signals a major escalation in Western attribution and response posture toward Russian state hackers, with direct implications for critical infrastructure threat modeling and geopolitical risk assessments across energy, water, and related sectors.
π Read full article
BleepingComputer Β· Jul 13 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: EU and UK sanctioning of GRU-linked hacking groups reinforces the attribution of state-sponsored threat actors and should prompt CISOs to reassess threat intelligence programs and escalate Russia-nexus adversary tracking within their security operations.
π Read full article
BleepingComputer Β· Jul 13 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A nine-nation joint advisory on Russian state hackers exploiting vulnerable routers to penetrate critical infrastructure networks is a direct call to action for CISOs to audit network edge device configurations and SNMP credential hygiene enterprise-wide.
π Read full article
VentureBeat Security Β· Jul 13 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Slopsquattingβwhere attackers register fictitious package names hallucinated by LLM coding assistantsβrepresents a novel and hard-to-detect software supply chain attack vector that CISOs must address through AI code governance policies and dependency vetting controls.
π Read full article
Help Net Security Β· Jul 13 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: This case establishes that insider betrayal during incident response engagementsβincluding sharing insurance limits and negotiating positions with ransomware operatorsβcarries serious criminal liability, and should force CISOs to scrutinize third-party IR and negotiation firm vetting and information-sharing controls.
π Read full article
CyberScoop Β· Jul 13 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: As AI coding tools accelerate software velocity, the accumulation of unreviewed, insecure AI-generated code is transitioning from a development hygiene issue to a board-level governance and liability risk that CISOs must now own and report on.
π Read full article
Help Net Security Β· Jul 13 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: Progress Softwareβthe vendor behind the MOVEit breachβis now responding to a credible external threat against ShareFile's on-premises Storage Zone Controllers by disabling accounts and urging server shutdowns, a crisis-level response that demands immediate inventory checks from any enterprise running ShareFile SZC deployments.
π Read full article
Help Net Security Β· Jul 13 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Attackers are exploiting a gap in Microsoft Entra ID's handling of unrecognized OAuth client IDs to conduct account enumeration while evading standard sign-in telemetry, directly undermining the detection efficacy of cloud identity monitoring in Microsoft 365 environments.
π Read full article
Alex: Welcome to Cleartext. It's Monday, July 13th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Let's get into it.
Alex: Jordan, quite a weekend.
Jordan: Quite a weekend. So here's where I want to start. The UK and the EU just issued their first ever joint cyber sanctions package. First ever. They named FSB Center 16, that's Russia's signals intelligence arm, for cyberattacks against Poland's energy grid and water treatment facilities. Alongside that, dozens of GRU-linked individuals and entities got sanctioned for a coordinated campaign of hacking across Europe. And then the US and eight allied nations dropped a joint advisory on Russian state hackers exploiting misconfigured routers to penetrate critical infrastructure. Three coordinated actions in essentially 48 hours. This is not routine. This is a posture shift.
Alex: Let me frame why this matters at the board level before we dig in. If you're a CISO at any organization that touches energy, water, transportation, or frankly any critical infrastructure adjacent sector, the threat model you presented to your board six months ago is now outdated. The Western alliance just made an explicit, coordinated, public statement that Russian cyber operations against civilian infrastructure are escalating in severity and that the response posture is escalating to match. That changes your risk calculus.
Jordan: Let's unpack what's actually new here. We've had Russian attribution before. We've had sanctions before. What we haven't had is the UK and EU acting jointly on cyber sanctions as a single package. Post-Brexit, these two have operated on parallel but separate tracks. The fact that they synchronized this tells you there was a political decision at the highest levels to send a unified signal. And the inclusion of both FSB and GRU operations in a single action suggests the Western intelligence community is presenting Russia's cyber apparatus as a coordinated whole, not just individual threat groups operating independently.
Alex: And for CISOs, that framing matters. When your board asks, "Are we a target?", the answer has to account for the fact that Western governments are now explicitly saying Russia is running a coordinated network of hacking groups. Not APT28 here, Sandworm there. A coordinated network. That means if you're tracking these threat actors in silos, you're likely missing the picture.
Jordan: The nine-nation joint advisory is the operational companion to the political action. And what it flags is almost embarrassingly basic. Weak SNMP credentials on network edge devices. Misconfigured routers. This is the initial access vector they're calling out. Not zero-days. Not sophisticated implants. Routers with default or weak SNMP community strings sitting on the network perimeter.
Alex: Which is exactly the kind of finding that makes CISOs uncomfortable, because it means the gap isn't in your next-gen tooling budget. It's in configuration hygiene on devices that nobody's looked at since they were racked. If you run critical infrastructure or if you supply it, Monday morning action item number one is an audit of every network edge device. SNMP credentials, firmware versions, access controls. Not next quarter. Now.
Jordan: I'll add one more layer. The geopolitical timing matters. We're in a period where NATO is actively reinforcing Eastern European defense posture. Poland has been a focal point. Targeting Polish energy and water is not random. It's coercive signaling. And if you're a CISO at a multinational with operations in Eastern Europe, or even supply chain dependencies there, you need to factor that into your continuity planning.
Alex: Good. Let's pivot to something that connects the geopolitical to the operational in a different way. Jordan, Progress Software. Again.
Jordan: Again. So the company behind the MOVEit breach, which, let's remember, compromised hundreds of organizations and tens of millions of records, is now dealing with what they're calling a credible external security threat targeting ShareFile Storage Zone Controllers. These are the on-premises, customer-managed server components. Progress sent emergency emails on July 10th, proactively disabled access to affected ShareFile accounts, and told customers to manually shut down their SZC servers pending further guidance.
Alex: Let me be direct. When a vendor proactively disables your accounts and tells you to shut down servers, that is a crisis-level response. That is not a precautionary advisory. That is a vendor telling you they believe exploitation is imminent or already occurring. If you have ShareFile SZC deployments, you should already be in incident response mode.
Jordan: What strikes me is the pattern with Progress Software. MOVEit was a managed file transfer product. ShareFile SZC is a file sharing and storage product. These are the workhorses of enterprise data movement. They sit at the intersection of sensitive data and network exposure, and they've now shown up twice as high-severity targets from the same vendor.
Alex: And the board question becomes a vendor concentration and third-party risk question. How many of your critical data flows run through Progress Software products? What's your fallback? This is the kind of scenario that tests whether your third-party risk program is a paper exercise or an operational capability.
Jordan: Shift gears. There's an interesting Entra ID story that I think a lot of SOC teams need to hear. Attackers are spoofing OAuth client IDs in authentication requests against Microsoft Entra ID. They're passing fabricated application identifiers in the client_id parameter. Entra ID logs whatever value it receives, and when the value doesn't match a known application, it creates a blind spot in the sign-in telemetry that most security teams rely on for detection.
Alex: So to be clear, the technique is being used for cloud tenant account enumeration, which is the precursor to credential stuffing and brute force. And the clever part is that by spoofing the client ID, the activity either doesn't appear in the logs your SOC is watching or it appears as noise that doesn't correlate to a known application.
Jordan: Exactly. Your detection logic that keys on application ID suddenly has a gap. If you're running detections on Entra ID sign-in logs, and most Microsoft 365 shops are, you need to evaluate whether your rules account for unrecognized or anomalous client_id values. This is a detection engineering problem, not a patching problem.
Alex: Alright, let's talk about two stories that I think are thematically linked around AI governance and trust. First, the sentencing of Angelo Martino. Former ransomware negotiator at DigitalMint. Seventy months in federal prison for sharing client confidential information, insurance policy limits, negotiating positions, internal assessments, directly with BlackCat ransomware operators. He later participated in attacks against clients.
Jordan: Seventy months. Almost six years. This is the most significant criminal case we've seen involving insider betrayal in the incident response ecosystem. And it should be deeply unsettling to every CISO who's ever brought in a third-party negotiation firm during a ransomware event.
Alex: Think about what you share with your IR and negotiation partners during a crisis. Policy limits. Board deliberations. Willingness to pay. Recovery timelines. Competitive exposure. That information is extraordinarily sensitive, and in this case it was handed directly to the adversary to maximize extraction. The vetting question here isn't just background checks on firms. It's information compartmentalization during incidents. Who has access to what? Are you sharing insurance details with negotiators who don't need them? Are you segregating legal strategy from technical response?
Jordan: And I'd argue this case should also change how you write your IR retainer agreements. Information handling, confidentiality controls, personnel vetting requirements. These need teeth now. Not boilerplate.
Alex: The second thread is slopsquatting, which is a fantastic and horrible name. The concept is straightforward. LLM coding assistants hallucinate package names that don't exist. Attackers register those hallucinated names on package repositories and populate them with malicious code. Developers using AI assistants then pull in the malicious package because the AI told them to.
Jordan: It's elegant in its simplicity. Traditional typosquatting requires you to guess what typos developers will make. Slopsquatting lets you just wait for the AI to make up a package name, register it, and let the AI do the distribution for you. The AI becomes the attack vector.
Alex: And this connects to the broader CyberScoop piece on AI-generated code as a governance problem. The argument, which I agree with, is that AI coding tools are producing security debt at a pace that outstrips review and remediation capacity. And that debt is no longer a development hygiene issue. It's a board-level governance and liability risk.
Jordan: If your developers are using Copilot or any LLM coding assistant, and statistically they almost certainly are even if you haven't formally approved it, you need dependency validation controls that specifically account for hallucinated package names. That means checking package existence and provenance before anything gets pulled into a build. And you need a governance framework that treats AI-generated code as a distinct risk category with its own review requirements.
Alex: Which brings us to the outlook. Jordan, what's the thread you're pulling on this week?
Jordan: The thread is trust boundaries under stress. Every story today is about a trust boundary that broke or is being tested. Geopolitical trust between nations driving unprecedented joint sanctions. Trust in critical infrastructure device configurations. Trust in vendor security with Progress Software. Trust in identity telemetry with the Entra ID blind spot. Trust in your incident response partners with the Martino case. Trust in your AI development tools with slopsquatting. The common theme is that assumptions about who and what you can trust are being invalidated faster than most organizations can adapt.
Alex: And I think the action item for CISOs this week is to pick two of those trust boundaries and pressure test them. Not theoretically. Operationally. Pull your router configs. Call your IR firm and ask about their personnel controls. Look at your Entra ID detection logic. Ask your engineering leadership what dependency validation looks like for AI-assisted code. Pick two, and actually test the assumption.
Jordan: Agreed. And if you're in critical infrastructure, the Russia actions aren't optional reading. Brief your board. Update your threat model. Audit your edge.
Alex: That's our show for Monday, July 13th. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.
Jordan: Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-13.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 8 stories across 4 topic areas, including: Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions; EU sanctions Russian GRU military hackers over cyberattacks; US and allies warn of Russian critical infrastructure attacks.
The Record (Recorded Future) Β· Jul 12 Β· Relevance: ββββββββββ 10/10
Why it matters to CISOs: The first joint UK-EU cyber sanctions package signals a major escalation in Western attribution and response posture toward Russian state hackers, with direct implications for critical infrastructure threat modeling and geopolitical risk assessments across energy, water, and related sectors.
π Read full article
BleepingComputer Β· Jul 13 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: EU and UK sanctioning of GRU-linked hacking groups reinforces the attribution of state-sponsored threat actors and should prompt CISOs to reassess threat intelligence programs and escalate Russia-nexus adversary tracking within their security operations.
π Read full article
BleepingComputer Β· Jul 13 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A nine-nation joint advisory on Russian state hackers exploiting vulnerable routers to penetrate critical infrastructure networks is a direct call to action for CISOs to audit network edge device configurations and SNMP credential hygiene enterprise-wide.
π Read full article
VentureBeat Security Β· Jul 13 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Slopsquattingβwhere attackers register fictitious package names hallucinated by LLM coding assistantsβrepresents a novel and hard-to-detect software supply chain attack vector that CISOs must address through AI code governance policies and dependency vetting controls.
π Read full article
Help Net Security Β· Jul 13 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: This case establishes that insider betrayal during incident response engagementsβincluding sharing insurance limits and negotiating positions with ransomware operatorsβcarries serious criminal liability, and should force CISOs to scrutinize third-party IR and negotiation firm vetting and information-sharing controls.
π Read full article
CyberScoop Β· Jul 13 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: As AI coding tools accelerate software velocity, the accumulation of unreviewed, insecure AI-generated code is transitioning from a development hygiene issue to a board-level governance and liability risk that CISOs must now own and report on.
π Read full article
Help Net Security Β· Jul 13 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: Progress Softwareβthe vendor behind the MOVEit breachβis now responding to a credible external threat against ShareFile's on-premises Storage Zone Controllers by disabling accounts and urging server shutdowns, a crisis-level response that demands immediate inventory checks from any enterprise running ShareFile SZC deployments.
π Read full article
Help Net Security Β· Jul 13 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Attackers are exploiting a gap in Microsoft Entra ID's handling of unrecognized OAuth client IDs to conduct account enumeration while evading standard sign-in telemetry, directly undermining the detection efficacy of cloud identity monitoring in Microsoft 365 environments.
π Read full article
Alex: Welcome to Cleartext. It's Monday, July 13th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Let's get into it.
Alex: Jordan, quite a weekend.
Jordan: Quite a weekend. So here's where I want to start. The UK and the EU just issued their first ever joint cyber sanctions package. First ever. They named FSB Center 16, that's Russia's signals intelligence arm, for cyberattacks against Poland's energy grid and water treatment facilities. Alongside that, dozens of GRU-linked individuals and entities got sanctioned for a coordinated campaign of hacking across Europe. And then the US and eight allied nations dropped a joint advisory on Russian state hackers exploiting misconfigured routers to penetrate critical infrastructure. Three coordinated actions in essentially 48 hours. This is not routine. This is a posture shift.
Alex: Let me frame why this matters at the board level before we dig in. If you're a CISO at any organization that touches energy, water, transportation, or frankly any critical infrastructure adjacent sector, the threat model you presented to your board six months ago is now outdated. The Western alliance just made an explicit, coordinated, public statement that Russian cyber operations against civilian infrastructure are escalating in severity and that the response posture is escalating to match. That changes your risk calculus.
Jordan: Let's unpack what's actually new here. We've had Russian attribution before. We've had sanctions before. What we haven't had is the UK and EU acting jointly on cyber sanctions as a single package. Post-Brexit, these two have operated on parallel but separate tracks. The fact that they synchronized this tells you there was a political decision at the highest levels to send a unified signal. And the inclusion of both FSB and GRU operations in a single action suggests the Western intelligence community is presenting Russia's cyber apparatus as a coordinated whole, not just individual threat groups operating independently.
Alex: And for CISOs, that framing matters. When your board asks, "Are we a target?", the answer has to account for the fact that Western governments are now explicitly saying Russia is running a coordinated network of hacking groups. Not APT28 here, Sandworm there. A coordinated network. That means if you're tracking these threat actors in silos, you're likely missing the picture.
Jordan: The nine-nation joint advisory is the operational companion to the political action. And what it flags is almost embarrassingly basic. Weak SNMP credentials on network edge devices. Misconfigured routers. This is the initial access vector they're calling out. Not zero-days. Not sophisticated implants. Routers with default or weak SNMP community strings sitting on the network perimeter.
Alex: Which is exactly the kind of finding that makes CISOs uncomfortable, because it means the gap isn't in your next-gen tooling budget. It's in configuration hygiene on devices that nobody's looked at since they were racked. If you run critical infrastructure or if you supply it, Monday morning action item number one is an audit of every network edge device. SNMP credentials, firmware versions, access controls. Not next quarter. Now.
Jordan: I'll add one more layer. The geopolitical timing matters. We're in a period where NATO is actively reinforcing Eastern European defense posture. Poland has been a focal point. Targeting Polish energy and water is not random. It's coercive signaling. And if you're a CISO at a multinational with operations in Eastern Europe, or even supply chain dependencies there, you need to factor that into your continuity planning.
Alex: Good. Let's pivot to something that connects the geopolitical to the operational in a different way. Jordan, Progress Software. Again.
Jordan: Again. So the company behind the MOVEit breach, which, let's remember, compromised hundreds of organizations and tens of millions of records, is now dealing with what they're calling a credible external security threat targeting ShareFile Storage Zone Controllers. These are the on-premises, customer-managed server components. Progress sent emergency emails on July 10th, proactively disabled access to affected ShareFile accounts, and told customers to manually shut down their SZC servers pending further guidance.
Alex: Let me be direct. When a vendor proactively disables your accounts and tells you to shut down servers, that is a crisis-level response. That is not a precautionary advisory. That is a vendor telling you they believe exploitation is imminent or already occurring. If you have ShareFile SZC deployments, you should already be in incident response mode.
Jordan: What strikes me is the pattern with Progress Software. MOVEit was a managed file transfer product. ShareFile SZC is a file sharing and storage product. These are the workhorses of enterprise data movement. They sit at the intersection of sensitive data and network exposure, and they've now shown up twice as high-severity targets from the same vendor.
Alex: And the board question becomes a vendor concentration and third-party risk question. How many of your critical data flows run through Progress Software products? What's your fallback? This is the kind of scenario that tests whether your third-party risk program is a paper exercise or an operational capability.
Jordan: Shift gears. There's an interesting Entra ID story that I think a lot of SOC teams need to hear. Attackers are spoofing OAuth client IDs in authentication requests against Microsoft Entra ID. They're passing fabricated application identifiers in the client_id parameter. Entra ID logs whatever value it receives, and when the value doesn't match a known application, it creates a blind spot in the sign-in telemetry that most security teams rely on for detection.
Alex: So to be clear, the technique is being used for cloud tenant account enumeration, which is the precursor to credential stuffing and brute force. And the clever part is that by spoofing the client ID, the activity either doesn't appear in the logs your SOC is watching or it appears as noise that doesn't correlate to a known application.
Jordan: Exactly. Your detection logic that keys on application ID suddenly has a gap. If you're running detections on Entra ID sign-in logs, and most Microsoft 365 shops are, you need to evaluate whether your rules account for unrecognized or anomalous client_id values. This is a detection engineering problem, not a patching problem.
Alex: Alright, let's talk about two stories that I think are thematically linked around AI governance and trust. First, the sentencing of Angelo Martino. Former ransomware negotiator at DigitalMint. Seventy months in federal prison for sharing client confidential information, insurance policy limits, negotiating positions, internal assessments, directly with BlackCat ransomware operators. He later participated in attacks against clients.
Jordan: Seventy months. Almost six years. This is the most significant criminal case we've seen involving insider betrayal in the incident response ecosystem. And it should be deeply unsettling to every CISO who's ever brought in a third-party negotiation firm during a ransomware event.
Alex: Think about what you share with your IR and negotiation partners during a crisis. Policy limits. Board deliberations. Willingness to pay. Recovery timelines. Competitive exposure. That information is extraordinarily sensitive, and in this case it was handed directly to the adversary to maximize extraction. The vetting question here isn't just background checks on firms. It's information compartmentalization during incidents. Who has access to what? Are you sharing insurance details with negotiators who don't need them? Are you segregating legal strategy from technical response?
Jordan: And I'd argue this case should also change how you write your IR retainer agreements. Information handling, confidentiality controls, personnel vetting requirements. These need teeth now. Not boilerplate.
Alex: The second thread is slopsquatting, which is a fantastic and horrible name. The concept is straightforward. LLM coding assistants hallucinate package names that don't exist. Attackers register those hallucinated names on package repositories and populate them with malicious code. Developers using AI assistants then pull in the malicious package because the AI told them to.
Jordan: It's elegant in its simplicity. Traditional typosquatting requires you to guess what typos developers will make. Slopsquatting lets you just wait for the AI to make up a package name, register it, and let the AI do the distribution for you. The AI becomes the attack vector.
Alex: And this connects to the broader CyberScoop piece on AI-generated code as a governance problem. The argument, which I agree with, is that AI coding tools are producing security debt at a pace that outstrips review and remediation capacity. And that debt is no longer a development hygiene issue. It's a board-level governance and liability risk.
Jordan: If your developers are using Copilot or any LLM coding assistant, and statistically they almost certainly are even if you haven't formally approved it, you need dependency validation controls that specifically account for hallucinated package names. That means checking package existence and provenance before anything gets pulled into a build. And you need a governance framework that treats AI-generated code as a distinct risk category with its own review requirements.
Alex: Which brings us to the outlook. Jordan, what's the thread you're pulling on this week?
Jordan: The thread is trust boundaries under stress. Every story today is about a trust boundary that broke or is being tested. Geopolitical trust between nations driving unprecedented joint sanctions. Trust in critical infrastructure device configurations. Trust in vendor security with Progress Software. Trust in identity telemetry with the Entra ID blind spot. Trust in your incident response partners with the Martino case. Trust in your AI development tools with slopsquatting. The common theme is that assumptions about who and what you can trust are being invalidated faster than most organizations can adapt.
Alex: And I think the action item for CISOs this week is to pick two of those trust boundaries and pressure test them. Not theoretically. Operationally. Pull your router configs. Call your IR firm and ask about their personnel controls. Look at your Entra ID detection logic. Ask your engineering leadership what dependency validation looks like for AI-assisted code. Pick two, and actually test the assumption.
Jordan: Agreed. And if you're in critical infrastructure, the Russia actions aren't optional reading. Brief your board. Update your threat model. Audit your edge.
Alex: That's our show for Monday, July 13th. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.
Jordan: Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-13.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.