Cleartext

Cleartext – July 13, 2026


Listen Later

Cleartext – July 13, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 8 stories across 4 topic areas, including: Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions; EU sanctions Russian GRU military hackers over cyberattacks; US and allies warn of Russian critical infrastructure attacks.

Stories Covered
🌍 Geopolitical
Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions

The Record (Recorded Future) Β· Jul 12 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ 10/10

Why it matters to CISOs: The first joint UK-EU cyber sanctions package signals a major escalation in Western attribution and response posture toward Russian state hackers, with direct implications for critical infrastructure threat modeling and geopolitical risk assessments across energy, water, and related sectors.

  • Russia's FSB Center 16 (signals intelligence arm) attributed to cyberattacks on Poland's energy sector and water treatment facilities
  • First-ever joint UK-EU cyber sanctions package imposed on Russian individuals and entities
  • Allies cite 'growing severity' of Russian malicious cyber activities across Europe
  • πŸ“– Read full article

    EU sanctions Russian GRU military hackers over cyberattacks

    BleepingComputer Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

    Why it matters to CISOs: EU and UK sanctioning of GRU-linked hacking groups reinforces the attribution of state-sponsored threat actors and should prompt CISOs to reassess threat intelligence programs and escalate Russia-nexus adversary tracking within their security operations.

    • Dozens of Russian GRU-linked individuals and entities sanctioned jointly by EU and UK
    • Russia accused of coordinating a network of hacking groups responsible for attacks across Europe
    • Action taken alongside FSB attribution for Poland critical infrastructure attacks
    • πŸ“– Read full article

      US and allies warn of Russian critical infrastructure attacks

      BleepingComputer Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

      Why it matters to CISOs: A nine-nation joint advisory on Russian state hackers exploiting vulnerable routers to penetrate critical infrastructure networks is a direct call to action for CISOs to audit network edge device configurations and SNMP credential hygiene enterprise-wide.

      • Cybersecurity agencies from the US and eight allied nations issued a coordinated joint advisory
      • Russian state hackers are actively targeting vulnerable and misconfigured routers to infiltrate critical infrastructure
      • Weak SNMP credentials cited as a primary attack vector enabling initial access
      • πŸ“– Read full article

        πŸ“‘ Macro Trends
        Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools

        VentureBeat Security Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

        Why it matters to CISOs: Slopsquattingβ€”where attackers register fictitious package names hallucinated by LLM coding assistantsβ€”represents a novel and hard-to-detect software supply chain attack vector that CISOs must address through AI code governance policies and dependency vetting controls.

        • LLM coding assistants hallucinate non-existent package names, which attackers can register and populate with malicious code
        • The attack vector is active from day one of development, bypassing traditional supply chain controls that assume real package names
        • Enterprises with AI-assisted development pipelines are exposed without specific controls to validate package existence and provenance
        • πŸ“– Read full article

          βš–οΈ Governance & Policy
          Ransomware negotiator who betrayed clients sentenced to 70 months in prison

          Help Net Security Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

          Why it matters to CISOs: This case establishes that insider betrayal during incident response engagementsβ€”including sharing insurance limits and negotiating positions with ransomware operatorsβ€”carries serious criminal liability, and should force CISOs to scrutinize third-party IR and negotiation firm vetting and information-sharing controls.

          • Angelo Martino, a negotiator at IR firm DigitalMint, sentenced to 70 months for sharing client negotiation data with BlackCat ransomware operators starting April 2023
          • Leaked information included victims' insurance policy limits, negotiating positions, and internal assessments
          • Martino later participated directly in ransomware attacks against clients
          • πŸ“– Read full article

            AI-generated code has made security debt a governance problem

            CyberScoop Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

            Why it matters to CISOs: As AI coding tools accelerate software velocity, the accumulation of unreviewed, insecure AI-generated code is transitioning from a development hygiene issue to a board-level governance and liability risk that CISOs must now own and report on.

            • AI coding assistants are producing security debt at a pace that outstrips traditional review and remediation processes
            • The article argues CISOs must move beyond tool approval to formal AI code governance frameworks
            • Security debt from AI-generated code is increasingly framed as a governance and fiduciary risk, not just a technical one
            • πŸ“– Read full article

              🚨 Critical Vulnerability
              Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers

              Help Net Security Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

              Why it matters to CISOs: Progress Softwareβ€”the vendor behind the MOVEit breachβ€”is now responding to a credible external threat against ShareFile's on-premises Storage Zone Controllers by disabling accounts and urging server shutdowns, a crisis-level response that demands immediate inventory checks from any enterprise running ShareFile SZC deployments.

              • Progress Software issued emergency email alerts on July 10 warning of a 'credible external security threat' targeting ShareFile Storage Zone Controllers
              • The company proactively disabled access to ShareFile accounts using on-premises SZC components
              • Customers were instructed to manually shut down servers hosting Storage Zone Controllers pending further guidance
              • πŸ“– Read full article

                Fake OAuth client IDs are helping attackers slip past sign-in logs

                Help Net Security Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                Why it matters to CISOs: Attackers are exploiting a gap in Microsoft Entra ID's handling of unrecognized OAuth client IDs to conduct account enumeration while evading standard sign-in telemetry, directly undermining the detection efficacy of cloud identity monitoring in Microsoft 365 environments.

                • Threat actors are spoofing OAuth client_id values in authentication requests to Microsoft Entra ID to evade detection in sign-in logs
                • Entra ID's handling of unfamiliar application identifiers creates a blind spot in standard telemetry used by SOC and identity teams
                • The technique is being actively used for cloud tenant account enumeration as a precursor to credential attacks
                • πŸ“– Read full article

                  Further Reading
                  • 🌍 Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions β€” The Record (Recorded Future)
                  • 🌍 EU sanctions Russian GRU military hackers over cyberattacks β€” BleepingComputer
                  • 🌍 US and allies warn of Russian critical infrastructure attacks β€” BleepingComputer
                  • πŸ“‘ Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools β€” VentureBeat Security
                  • βš–οΈ Ransomware negotiator who betrayed clients sentenced to 70 months in prison β€” Help Net Security
                  • βš–οΈ AI-generated code has made security debt a governance problem β€” CyberScoop
                  • 🚨 Security threat prompts Progress to disable ShareFile accounts, tell customers to shut down servers β€” Help Net Security
                  • 🚨 Fake OAuth client IDs are helping attackers slip past sign-in logs β€” Help Net Security
                  • Full Transcript
                    Click to expand full episode transcript

                    Alex: Welcome to Cleartext. It's Monday, July 13th, 2026. I'm Alex Chen.

                    Jordan: And I'm Jordan Reeves. Let's get into it.

                    Alex: Jordan, quite a weekend.

                    Jordan: Quite a weekend. So here's where I want to start. The UK and the EU just issued their first ever joint cyber sanctions package. First ever. They named FSB Center 16, that's Russia's signals intelligence arm, for cyberattacks against Poland's energy grid and water treatment facilities. Alongside that, dozens of GRU-linked individuals and entities got sanctioned for a coordinated campaign of hacking across Europe. And then the US and eight allied nations dropped a joint advisory on Russian state hackers exploiting misconfigured routers to penetrate critical infrastructure. Three coordinated actions in essentially 48 hours. This is not routine. This is a posture shift.

                    Alex: Let me frame why this matters at the board level before we dig in. If you're a CISO at any organization that touches energy, water, transportation, or frankly any critical infrastructure adjacent sector, the threat model you presented to your board six months ago is now outdated. The Western alliance just made an explicit, coordinated, public statement that Russian cyber operations against civilian infrastructure are escalating in severity and that the response posture is escalating to match. That changes your risk calculus.

                    Jordan: Let's unpack what's actually new here. We've had Russian attribution before. We've had sanctions before. What we haven't had is the UK and EU acting jointly on cyber sanctions as a single package. Post-Brexit, these two have operated on parallel but separate tracks. The fact that they synchronized this tells you there was a political decision at the highest levels to send a unified signal. And the inclusion of both FSB and GRU operations in a single action suggests the Western intelligence community is presenting Russia's cyber apparatus as a coordinated whole, not just individual threat groups operating independently.

                    Alex: And for CISOs, that framing matters. When your board asks, "Are we a target?", the answer has to account for the fact that Western governments are now explicitly saying Russia is running a coordinated network of hacking groups. Not APT28 here, Sandworm there. A coordinated network. That means if you're tracking these threat actors in silos, you're likely missing the picture.

                    Jordan: The nine-nation joint advisory is the operational companion to the political action. And what it flags is almost embarrassingly basic. Weak SNMP credentials on network edge devices. Misconfigured routers. This is the initial access vector they're calling out. Not zero-days. Not sophisticated implants. Routers with default or weak SNMP community strings sitting on the network perimeter.

                    Alex: Which is exactly the kind of finding that makes CISOs uncomfortable, because it means the gap isn't in your next-gen tooling budget. It's in configuration hygiene on devices that nobody's looked at since they were racked. If you run critical infrastructure or if you supply it, Monday morning action item number one is an audit of every network edge device. SNMP credentials, firmware versions, access controls. Not next quarter. Now.

                    Jordan: I'll add one more layer. The geopolitical timing matters. We're in a period where NATO is actively reinforcing Eastern European defense posture. Poland has been a focal point. Targeting Polish energy and water is not random. It's coercive signaling. And if you're a CISO at a multinational with operations in Eastern Europe, or even supply chain dependencies there, you need to factor that into your continuity planning.

                    Alex: Good. Let's pivot to something that connects the geopolitical to the operational in a different way. Jordan, Progress Software. Again.

                    Jordan: Again. So the company behind the MOVEit breach, which, let's remember, compromised hundreds of organizations and tens of millions of records, is now dealing with what they're calling a credible external security threat targeting ShareFile Storage Zone Controllers. These are the on-premises, customer-managed server components. Progress sent emergency emails on July 10th, proactively disabled access to affected ShareFile accounts, and told customers to manually shut down their SZC servers pending further guidance.

                    Alex: Let me be direct. When a vendor proactively disables your accounts and tells you to shut down servers, that is a crisis-level response. That is not a precautionary advisory. That is a vendor telling you they believe exploitation is imminent or already occurring. If you have ShareFile SZC deployments, you should already be in incident response mode.

                    Jordan: What strikes me is the pattern with Progress Software. MOVEit was a managed file transfer product. ShareFile SZC is a file sharing and storage product. These are the workhorses of enterprise data movement. They sit at the intersection of sensitive data and network exposure, and they've now shown up twice as high-severity targets from the same vendor.

                    Alex: And the board question becomes a vendor concentration and third-party risk question. How many of your critical data flows run through Progress Software products? What's your fallback? This is the kind of scenario that tests whether your third-party risk program is a paper exercise or an operational capability.

                    Jordan: Shift gears. There's an interesting Entra ID story that I think a lot of SOC teams need to hear. Attackers are spoofing OAuth client IDs in authentication requests against Microsoft Entra ID. They're passing fabricated application identifiers in the client_id parameter. Entra ID logs whatever value it receives, and when the value doesn't match a known application, it creates a blind spot in the sign-in telemetry that most security teams rely on for detection.

                    Alex: So to be clear, the technique is being used for cloud tenant account enumeration, which is the precursor to credential stuffing and brute force. And the clever part is that by spoofing the client ID, the activity either doesn't appear in the logs your SOC is watching or it appears as noise that doesn't correlate to a known application.

                    Jordan: Exactly. Your detection logic that keys on application ID suddenly has a gap. If you're running detections on Entra ID sign-in logs, and most Microsoft 365 shops are, you need to evaluate whether your rules account for unrecognized or anomalous client_id values. This is a detection engineering problem, not a patching problem.

                    Alex: Alright, let's talk about two stories that I think are thematically linked around AI governance and trust. First, the sentencing of Angelo Martino. Former ransomware negotiator at DigitalMint. Seventy months in federal prison for sharing client confidential information, insurance policy limits, negotiating positions, internal assessments, directly with BlackCat ransomware operators. He later participated in attacks against clients.

                    Jordan: Seventy months. Almost six years. This is the most significant criminal case we've seen involving insider betrayal in the incident response ecosystem. And it should be deeply unsettling to every CISO who's ever brought in a third-party negotiation firm during a ransomware event.

                    Alex: Think about what you share with your IR and negotiation partners during a crisis. Policy limits. Board deliberations. Willingness to pay. Recovery timelines. Competitive exposure. That information is extraordinarily sensitive, and in this case it was handed directly to the adversary to maximize extraction. The vetting question here isn't just background checks on firms. It's information compartmentalization during incidents. Who has access to what? Are you sharing insurance details with negotiators who don't need them? Are you segregating legal strategy from technical response?

                    Jordan: And I'd argue this case should also change how you write your IR retainer agreements. Information handling, confidentiality controls, personnel vetting requirements. These need teeth now. Not boilerplate.

                    Alex: The second thread is slopsquatting, which is a fantastic and horrible name. The concept is straightforward. LLM coding assistants hallucinate package names that don't exist. Attackers register those hallucinated names on package repositories and populate them with malicious code. Developers using AI assistants then pull in the malicious package because the AI told them to.

                    Jordan: It's elegant in its simplicity. Traditional typosquatting requires you to guess what typos developers will make. Slopsquatting lets you just wait for the AI to make up a package name, register it, and let the AI do the distribution for you. The AI becomes the attack vector.

                    Alex: And this connects to the broader CyberScoop piece on AI-generated code as a governance problem. The argument, which I agree with, is that AI coding tools are producing security debt at a pace that outstrips review and remediation capacity. And that debt is no longer a development hygiene issue. It's a board-level governance and liability risk.

                    Jordan: If your developers are using Copilot or any LLM coding assistant, and statistically they almost certainly are even if you haven't formally approved it, you need dependency validation controls that specifically account for hallucinated package names. That means checking package existence and provenance before anything gets pulled into a build. And you need a governance framework that treats AI-generated code as a distinct risk category with its own review requirements.

                    Alex: Which brings us to the outlook. Jordan, what's the thread you're pulling on this week?

                    Jordan: The thread is trust boundaries under stress. Every story today is about a trust boundary that broke or is being tested. Geopolitical trust between nations driving unprecedented joint sanctions. Trust in critical infrastructure device configurations. Trust in vendor security with Progress Software. Trust in identity telemetry with the Entra ID blind spot. Trust in your incident response partners with the Martino case. Trust in your AI development tools with slopsquatting. The common theme is that assumptions about who and what you can trust are being invalidated faster than most organizations can adapt.

                    Alex: And I think the action item for CISOs this week is to pick two of those trust boundaries and pressure test them. Not theoretically. Operationally. Pull your router configs. Call your IR firm and ask about their personnel controls. Look at your Entra ID detection logic. Ask your engineering leadership what dependency validation looks like for AI-assisted code. Pick two, and actually test the assumption.

                    Jordan: Agreed. And if you're in critical infrastructure, the Russia actions aren't optional reading. Brief your board. Update your threat model. Audit your edge.

                    Alex: That's our show for Monday, July 13th. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.

                    Jordan: Stay sharp.

                    Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-13.

                    Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                    ...more
                    View all episodesView all episodes
                    Download on the App Store

                    CleartextBy Cleartext