
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
🎧 Listen to this episode
Today's episode covers 9 stories across 4 topic areas, including: EU sanctions Russian GRU military hackers over cyberattacks; Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’; Officials once again warn defenders that Russian hackers are targeting network devices.
BleepingComputer · Jul 13 · Relevance: ██████████ 10/10
Why it matters to CISOs: The first joint EU-UK cyber sanctions package against Russian GRU hackers signals a major escalation in Western cyber deterrence posture, with direct implications for critical infrastructure defenders and organizations operating in Europe who need to reassess their threat models.
📖 Read full article
CyberScoop · Jul 13 · Relevance: ██████████ 10/10
Why it matters to CISOs: Attribution of destructive cyberattacks on Poland's energy grid to the FSB's Turla group, combined with coordinated Western sanctions, marks a significant geopolitical escalation that enterprise CISOs in critical infrastructure sectors must factor into their threat intelligence and board communications.
📖 Read full article
CyberScoop · Jul 13 · Relevance: █████████░ 9/10
Why it matters to CISOs: A joint government advisory warning of Russian FSB exploitation of Cisco Smart Install vulnerabilities across defense, energy, finance, and healthcare sectors requires immediate action from CISOs operating in critical infrastructure to audit network device exposure.
📖 Read full article
BleepingComputer · Jul 14 · Relevance: ████████░░ 8/10
Why it matters to CISOs: OFAC's sanctioning of a VPN service provider and malware cryptor seller specifically for enabling ransomware operations signals that infrastructure enablers are now primary targets of US enforcement—CISOs should assess any third-party tools or services with potential sanctions exposure.
📖 Read full article
The Hacker News · Jul 14 · Relevance: █████████░ 9/10
Why it matters to CISOs: ShinyHunters' sustained exploitation of OAuth trust relationships in Salesforce environments—without exploiting any platform vulnerability—is a direct wake-up call for CISOs to audit third-party OAuth connections and inherited trust chains in their Salesforce deployments.
📖 Read full article
TechCrunch Security · Jul 13 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: This incident illustrates a critical gap in offboarding controls—a former employee retained access long after departure due to a system bug, highlighting the need for redundant access revocation verification especially when employees depart to competitors.
📖 Read full article
Krebs on Security · Jul 13 · Relevance: █████████░ 9/10
Why it matters to CISOs: CISA's own failure to detect dozens of leaked internal credentials—including AWS GovCloud keys—sitting in a public GitHub repo for nearly six months is a critical governance case study that every CISO should use to benchmark their own secrets management and contractor oversight programs.
📖 Read full article
Cybersecurity Dive · Jul 13 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A newly documented obfuscation technique allowing attackers to enumerate Microsoft Entra ID users without triggering alerts requires CISOs to proactively review log configurations and detection rules across their identity infrastructure.
📖 Read full article
Infosecurity Magazine · Jul 13 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Progress Software—maker of MOVEit, which was exploited in one of the largest breach campaigns in history—is now warning of an active external security threat to ShareFile's Storage Zone Controller, requiring immediate shutdown action from enterprise customers running on-premises deployments.
📖 Read full article
Alex: Welcome to Cleartext for Tuesday, July 14th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. So, Europe finally decided to name names. The EU and UK dropped the first joint cyber sanctions package yesterday, going directly after GRU operators and, perhaps more significantly, formally attributing the winter attacks on Poland's energy grid to the FSB's Turla group. If you run critical infrastructure anywhere in Europe or serve European markets, your threat model just changed.
Alex: That's where we're starting today, and there's a lot to unpack. We've got a coordinated Western sanctions package, a joint advisory on Russian exploitation of network devices, OFAC going after ransomware enablers for the first time, ShinyHunters spending a full year inside Salesforce environments without touching a single platform vulnerability, CISA's own embarrassing credential leak, and Progress Software telling customers to shut down ShareFile servers immediately. Plus Apple's offboarding controls apparently had a rather significant gap. Let's get into it.
Jordan: So let's talk about the sanctions. This isn't just another round of finger-wagging. The EU and UK coordinated simultaneously, sanctioning dozens of Russian individuals and entities. They publicly attributed specific campaigns to specific units within Russian intelligence. That's GRU for the broader European hacking operations, and FSB's Turla group specifically for the attacks on Poland's energy grid last winter. This is a deterrence posture shift, not just a diplomatic gesture.
Alex: And I think the Poland attribution is the piece that should get the most attention in the boardroom. Attributing destructive attacks on energy infrastructure to a named state intelligence unit is about as far as Western governments go short of kinetic response. For CISOs in energy, utilities, transportation, any critical infrastructure sector operating in Europe, this is the signal that says the threat is not theoretical and your government agrees.
Jordan: Right. And layered on top of that, we got the joint advisory, US authorities coordinating with international partners, specifically warning that Russian FSB actors are actively exploiting Cisco Smart Install vulnerabilities across defense, communications, energy, finance, government, and healthcare. This isn't new in concept. We've seen advisories about network device targeting before. But the timing alongside the sanctions tells you something about the intelligence community's current assessment of Russian operational tempo.
Alex: So what's the action item? If you're a CISO hearing this, the immediate move is to audit your Cisco Smart Install exposure. If you have it enabled and you're not actively using it, disable it. If you are using it, make sure it's not internet-facing and that you've applied every relevant patch. But the broader action is to revisit your network device hardening posture generally. Routers, switches, firewalls, these are the devices that attackers love because they often sit outside your EDR coverage, outside your normal logging pipeline, and they provide persistent access that survives endpoint reimaging.
Jordan: And frankly, most organizations still treat network device security as an infrastructure team problem rather than a security team problem. That gap is exactly what state actors exploit.
Alex: Staying on the sanctions theme but shifting to the US side, OFAC sanctioned a VPN service provider called First VPN Service, or 1VPNS, along with its Ukrainian administrator, specifically for providing infrastructure to ransomware groups. They also hit a Belarusian individual selling malware cryptor services. This is the first time a VPN provider has been sanctioned for ransomware enablement.
Jordan: This is significant because it signals that the US is now going after the enablement layer, not just the operators. If you're providing the infrastructure that makes ransomware possible, you are now a sanctions target. For CISOs, the practical concern is third-party risk. You need to be asking whether any of your vendors, any of your employees' tools, any shadow IT services have potential sanctions exposure. Because if your organization is transacting with a sanctioned entity, even unknowingly, that creates legal liability.
Alex: And this is a conversation your general counsel needs to be part of. Sanctions compliance isn't optional, and the scope of what constitutes a sanctionable entity in the cyber domain just expanded considerably.
Jordan: Let's shift to what I think is one of the most operationally important stories today. Microsoft published research mapping three distinct attack paths that ShinyHunters-linked actors used over the past year to compromise corporate Salesforce environments. And here's the critical detail: they didn't exploit a single Salesforce vulnerability. Not one. The entire attack surface was the OAuth trust relationships that organizations had configured between Salesforce and their third-party apps and vendors.
Alex: This is the story that should make every CISO uncomfortable, because it's not about a vendor failing you. It's about your own trust architecture failing you. When you connect a third-party app to Salesforce via OAuth, you're extending trust. And if that third party gets compromised, or if those OAuth tokens are mismanaged, the attacker inherits whatever access you granted. ShinyHunters apparently understood this better than most defenders do.
Jordan: Microsoft documented three paths. The specifics matter less than the pattern. Every one of them exploited inherited trust, the transitive trust problem that identity teams have been warning about for years. The action here is to audit every OAuth connection in your Salesforce environment. Know what apps have access, what scopes they were granted, whether those grants are still appropriate, and whether those third parties have adequate security controls. If you can't answer those questions, you have blind spots that are actively being exploited in the wild.
Alex: And this extends beyond Salesforce. Any SaaS platform with OAuth integrations has this same trust architecture. Salesforce just happens to be where ShinyHunters went hunting. The principle is universal.
Jordan: Speaking of trust architecture problems, let's talk about CISA's GitHub leak. Krebs reported that a contractor published dozens of internal CISA credentials, including AWS GovCloud keys, to a public GitHub repository. And those credentials sat there, publicly accessible, for almost six months before KrebsOnSecurity notified CISA.
Alex: Six months. The nation's cyber defense agency had live credentials exposed on a public repo for six months and didn't detect it. CISA deserves credit for publishing a formal postmortem, but this is a governance failure that every CISO should study carefully, because if CISA can miss this, so can you.
Jordan: The lessons from the postmortem are straightforward but apparently difficult to implement consistently. Secrets scanning needs to be automated and continuous, not just at commit time but across all repositories including contractor repos. Contractor oversight needs teeth. You need to know what your contractors are doing with your credentials, where they're storing them, and whether they're following your policies. And detection of credential exposure needs to be treated as a critical alerting use case, not a nice-to-have.
Alex: I'd add that this is a board-level conversation about contractor risk management. Most organizations have significant contractor populations with access to sensitive systems and credentials. If your secrets management program doesn't extend to contractors with the same rigor as employees, you have the same gap CISA had.
Jordan: Two more stories to cover. Proofpoint documented a technique for enumerating Microsoft Entra ID users without triggering standard detection. Attackers are exploiting how Entra handles certain authentication flows to identify valid accounts silently. This is pre-attack reconnaissance, the kind of thing that precedes credential stuffing or targeted phishing.
Alex: The action is to review Proofpoint's published indicators and check your Entra ID logs for signs of this enumeration technique. If your detection rules are built around standard failed authentication patterns, you may be missing this entirely. Identity infrastructure monitoring needs to evolve as fast as the evasion techniques, and right now, the attackers are ahead.
Jordan: And then there's Progress Software warning customers about what they're calling an external security threat to ShareFile's Storage Zone Controller. They're telling customers to shut down servers immediately.
Alex: If you're running ShareFile with on-premises Storage Zone Controllers, this is a drop-everything situation. Progress Software has earned a very specific reputation since the MOVEit campaign, and when they issue an urgent shutdown advisory, you take it at face value. Shut the servers down, wait for guidance, and have your incident response team review logs for any signs of compromise.
Jordan: The Apple story is worth a quick mention for the governance lesson. A former employee who left for OpenAI apparently exploited what Apple calls a rare bug to download confidential files after departure. The access should have been revoked. It wasn't, because of a system defect.
Alex: Every CISO should hear this and immediately ask: do we have redundant verification that access is actually revoked when someone leaves? Not just that the offboarding ticket was closed, but that every system, every credential, every token was actually deactivated. Because a single point of failure in your offboarding process is exactly the kind of thing that creates headlines.
Jordan: And when someone leaves for a direct competitor, the scrutiny should be even higher. That should trigger enhanced monitoring and verification as a matter of policy.
Alex: All right, let's talk about what's emerging here. The theme of the day, and frankly the theme of the quarter, is that the Western world is moving from passive cyber defense to active deterrence and enforcement. Coordinated sanctions, public attribution to specific intelligence units, OFAC going after enablement infrastructure. The policy environment is hardening rapidly.
Jordan: And that creates both protection and obligation for CISOs. Protection because these actions impose costs on adversaries and may reduce some threat volume over time. Obligation because your board is going to see these headlines and expect you to have a position on how your organization is responding to a threat environment that governments are calling serious enough to warrant sanctions and public attribution.
Alex: If you haven't updated your board briefing on the Russian cyber threat since the Ukraine invasion began, now is the time. The threat landscape has evolved. The policy landscape has evolved. Your board communication should reflect both.
Jordan: And on the operational side, the ShinyHunters Salesforce campaign and the CISA GitHub leak are both reminders that the most dangerous risks aren't exotic zero-days. They're trust relationships you've already established and credentials you've already issued. The basics still matter more than anything.
Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-14.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
🎧 Listen to this episode
Today's episode covers 9 stories across 4 topic areas, including: EU sanctions Russian GRU military hackers over cyberattacks; Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’; Officials once again warn defenders that Russian hackers are targeting network devices.
BleepingComputer · Jul 13 · Relevance: ██████████ 10/10
Why it matters to CISOs: The first joint EU-UK cyber sanctions package against Russian GRU hackers signals a major escalation in Western cyber deterrence posture, with direct implications for critical infrastructure defenders and organizations operating in Europe who need to reassess their threat models.
📖 Read full article
CyberScoop · Jul 13 · Relevance: ██████████ 10/10
Why it matters to CISOs: Attribution of destructive cyberattacks on Poland's energy grid to the FSB's Turla group, combined with coordinated Western sanctions, marks a significant geopolitical escalation that enterprise CISOs in critical infrastructure sectors must factor into their threat intelligence and board communications.
📖 Read full article
CyberScoop · Jul 13 · Relevance: █████████░ 9/10
Why it matters to CISOs: A joint government advisory warning of Russian FSB exploitation of Cisco Smart Install vulnerabilities across defense, energy, finance, and healthcare sectors requires immediate action from CISOs operating in critical infrastructure to audit network device exposure.
📖 Read full article
BleepingComputer · Jul 14 · Relevance: ████████░░ 8/10
Why it matters to CISOs: OFAC's sanctioning of a VPN service provider and malware cryptor seller specifically for enabling ransomware operations signals that infrastructure enablers are now primary targets of US enforcement—CISOs should assess any third-party tools or services with potential sanctions exposure.
📖 Read full article
The Hacker News · Jul 14 · Relevance: █████████░ 9/10
Why it matters to CISOs: ShinyHunters' sustained exploitation of OAuth trust relationships in Salesforce environments—without exploiting any platform vulnerability—is a direct wake-up call for CISOs to audit third-party OAuth connections and inherited trust chains in their Salesforce deployments.
📖 Read full article
TechCrunch Security · Jul 13 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: This incident illustrates a critical gap in offboarding controls—a former employee retained access long after departure due to a system bug, highlighting the need for redundant access revocation verification especially when employees depart to competitors.
📖 Read full article
Krebs on Security · Jul 13 · Relevance: █████████░ 9/10
Why it matters to CISOs: CISA's own failure to detect dozens of leaked internal credentials—including AWS GovCloud keys—sitting in a public GitHub repo for nearly six months is a critical governance case study that every CISO should use to benchmark their own secrets management and contractor oversight programs.
📖 Read full article
Cybersecurity Dive · Jul 13 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A newly documented obfuscation technique allowing attackers to enumerate Microsoft Entra ID users without triggering alerts requires CISOs to proactively review log configurations and detection rules across their identity infrastructure.
📖 Read full article
Infosecurity Magazine · Jul 13 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Progress Software—maker of MOVEit, which was exploited in one of the largest breach campaigns in history—is now warning of an active external security threat to ShareFile's Storage Zone Controller, requiring immediate shutdown action from enterprise customers running on-premises deployments.
📖 Read full article
Alex: Welcome to Cleartext for Tuesday, July 14th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. So, Europe finally decided to name names. The EU and UK dropped the first joint cyber sanctions package yesterday, going directly after GRU operators and, perhaps more significantly, formally attributing the winter attacks on Poland's energy grid to the FSB's Turla group. If you run critical infrastructure anywhere in Europe or serve European markets, your threat model just changed.
Alex: That's where we're starting today, and there's a lot to unpack. We've got a coordinated Western sanctions package, a joint advisory on Russian exploitation of network devices, OFAC going after ransomware enablers for the first time, ShinyHunters spending a full year inside Salesforce environments without touching a single platform vulnerability, CISA's own embarrassing credential leak, and Progress Software telling customers to shut down ShareFile servers immediately. Plus Apple's offboarding controls apparently had a rather significant gap. Let's get into it.
Jordan: So let's talk about the sanctions. This isn't just another round of finger-wagging. The EU and UK coordinated simultaneously, sanctioning dozens of Russian individuals and entities. They publicly attributed specific campaigns to specific units within Russian intelligence. That's GRU for the broader European hacking operations, and FSB's Turla group specifically for the attacks on Poland's energy grid last winter. This is a deterrence posture shift, not just a diplomatic gesture.
Alex: And I think the Poland attribution is the piece that should get the most attention in the boardroom. Attributing destructive attacks on energy infrastructure to a named state intelligence unit is about as far as Western governments go short of kinetic response. For CISOs in energy, utilities, transportation, any critical infrastructure sector operating in Europe, this is the signal that says the threat is not theoretical and your government agrees.
Jordan: Right. And layered on top of that, we got the joint advisory, US authorities coordinating with international partners, specifically warning that Russian FSB actors are actively exploiting Cisco Smart Install vulnerabilities across defense, communications, energy, finance, government, and healthcare. This isn't new in concept. We've seen advisories about network device targeting before. But the timing alongside the sanctions tells you something about the intelligence community's current assessment of Russian operational tempo.
Alex: So what's the action item? If you're a CISO hearing this, the immediate move is to audit your Cisco Smart Install exposure. If you have it enabled and you're not actively using it, disable it. If you are using it, make sure it's not internet-facing and that you've applied every relevant patch. But the broader action is to revisit your network device hardening posture generally. Routers, switches, firewalls, these are the devices that attackers love because they often sit outside your EDR coverage, outside your normal logging pipeline, and they provide persistent access that survives endpoint reimaging.
Jordan: And frankly, most organizations still treat network device security as an infrastructure team problem rather than a security team problem. That gap is exactly what state actors exploit.
Alex: Staying on the sanctions theme but shifting to the US side, OFAC sanctioned a VPN service provider called First VPN Service, or 1VPNS, along with its Ukrainian administrator, specifically for providing infrastructure to ransomware groups. They also hit a Belarusian individual selling malware cryptor services. This is the first time a VPN provider has been sanctioned for ransomware enablement.
Jordan: This is significant because it signals that the US is now going after the enablement layer, not just the operators. If you're providing the infrastructure that makes ransomware possible, you are now a sanctions target. For CISOs, the practical concern is third-party risk. You need to be asking whether any of your vendors, any of your employees' tools, any shadow IT services have potential sanctions exposure. Because if your organization is transacting with a sanctioned entity, even unknowingly, that creates legal liability.
Alex: And this is a conversation your general counsel needs to be part of. Sanctions compliance isn't optional, and the scope of what constitutes a sanctionable entity in the cyber domain just expanded considerably.
Jordan: Let's shift to what I think is one of the most operationally important stories today. Microsoft published research mapping three distinct attack paths that ShinyHunters-linked actors used over the past year to compromise corporate Salesforce environments. And here's the critical detail: they didn't exploit a single Salesforce vulnerability. Not one. The entire attack surface was the OAuth trust relationships that organizations had configured between Salesforce and their third-party apps and vendors.
Alex: This is the story that should make every CISO uncomfortable, because it's not about a vendor failing you. It's about your own trust architecture failing you. When you connect a third-party app to Salesforce via OAuth, you're extending trust. And if that third party gets compromised, or if those OAuth tokens are mismanaged, the attacker inherits whatever access you granted. ShinyHunters apparently understood this better than most defenders do.
Jordan: Microsoft documented three paths. The specifics matter less than the pattern. Every one of them exploited inherited trust, the transitive trust problem that identity teams have been warning about for years. The action here is to audit every OAuth connection in your Salesforce environment. Know what apps have access, what scopes they were granted, whether those grants are still appropriate, and whether those third parties have adequate security controls. If you can't answer those questions, you have blind spots that are actively being exploited in the wild.
Alex: And this extends beyond Salesforce. Any SaaS platform with OAuth integrations has this same trust architecture. Salesforce just happens to be where ShinyHunters went hunting. The principle is universal.
Jordan: Speaking of trust architecture problems, let's talk about CISA's GitHub leak. Krebs reported that a contractor published dozens of internal CISA credentials, including AWS GovCloud keys, to a public GitHub repository. And those credentials sat there, publicly accessible, for almost six months before KrebsOnSecurity notified CISA.
Alex: Six months. The nation's cyber defense agency had live credentials exposed on a public repo for six months and didn't detect it. CISA deserves credit for publishing a formal postmortem, but this is a governance failure that every CISO should study carefully, because if CISA can miss this, so can you.
Jordan: The lessons from the postmortem are straightforward but apparently difficult to implement consistently. Secrets scanning needs to be automated and continuous, not just at commit time but across all repositories including contractor repos. Contractor oversight needs teeth. You need to know what your contractors are doing with your credentials, where they're storing them, and whether they're following your policies. And detection of credential exposure needs to be treated as a critical alerting use case, not a nice-to-have.
Alex: I'd add that this is a board-level conversation about contractor risk management. Most organizations have significant contractor populations with access to sensitive systems and credentials. If your secrets management program doesn't extend to contractors with the same rigor as employees, you have the same gap CISA had.
Jordan: Two more stories to cover. Proofpoint documented a technique for enumerating Microsoft Entra ID users without triggering standard detection. Attackers are exploiting how Entra handles certain authentication flows to identify valid accounts silently. This is pre-attack reconnaissance, the kind of thing that precedes credential stuffing or targeted phishing.
Alex: The action is to review Proofpoint's published indicators and check your Entra ID logs for signs of this enumeration technique. If your detection rules are built around standard failed authentication patterns, you may be missing this entirely. Identity infrastructure monitoring needs to evolve as fast as the evasion techniques, and right now, the attackers are ahead.
Jordan: And then there's Progress Software warning customers about what they're calling an external security threat to ShareFile's Storage Zone Controller. They're telling customers to shut down servers immediately.
Alex: If you're running ShareFile with on-premises Storage Zone Controllers, this is a drop-everything situation. Progress Software has earned a very specific reputation since the MOVEit campaign, and when they issue an urgent shutdown advisory, you take it at face value. Shut the servers down, wait for guidance, and have your incident response team review logs for any signs of compromise.
Jordan: The Apple story is worth a quick mention for the governance lesson. A former employee who left for OpenAI apparently exploited what Apple calls a rare bug to download confidential files after departure. The access should have been revoked. It wasn't, because of a system defect.
Alex: Every CISO should hear this and immediately ask: do we have redundant verification that access is actually revoked when someone leaves? Not just that the offboarding ticket was closed, but that every system, every credential, every token was actually deactivated. Because a single point of failure in your offboarding process is exactly the kind of thing that creates headlines.
Jordan: And when someone leaves for a direct competitor, the scrutiny should be even higher. That should trigger enhanced monitoring and verification as a matter of policy.
Alex: All right, let's talk about what's emerging here. The theme of the day, and frankly the theme of the quarter, is that the Western world is moving from passive cyber defense to active deterrence and enforcement. Coordinated sanctions, public attribution to specific intelligence units, OFAC going after enablement infrastructure. The policy environment is hardening rapidly.
Jordan: And that creates both protection and obligation for CISOs. Protection because these actions impose costs on adversaries and may reduce some threat volume over time. Obligation because your board is going to see these headlines and expect you to have a position on how your organization is responding to a threat environment that governments are calling serious enough to warrant sanctions and public attribution.
Alex: If you haven't updated your board briefing on the Russian cyber threat since the Ukraine invasion began, now is the time. The threat landscape has evolved. The policy landscape has evolved. Your board communication should reflect both.
Jordan: And on the operational side, the ShinyHunters Salesforce campaign and the CISA GitHub leak are both reminders that the most dangerous risks aren't exotic zero-days. They're trust relationships you've already established and credentials you've already issued. The basics still matter more than anything.
Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-14.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.