Cleartext

Cleartext – July 14, 2026


Listen Later

Cleartext – July 14, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 4 topic areas, including: EU sanctions Russian GRU military hackers over cyberattacks; Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’; Officials once again warn defenders that Russian hackers are targeting network devices.

Stories Covered
🌍 Geopolitical
EU sanctions Russian GRU military hackers over cyberattacks

BleepingComputer · Jul 13 · Relevance: ██████████ 10/10

Why it matters to CISOs: The first joint EU-UK cyber sanctions package against Russian GRU hackers signals a major escalation in Western cyber deterrence posture, with direct implications for critical infrastructure defenders and organizations operating in Europe who need to reassess their threat models.

  • EU and UK jointly sanctioned dozens of Russian individuals and entities in an unprecedented coordinated cyber sanctions package
  • Russia accused of coordinating a network of hacking groups responsible for attacks across Europe
  • Sanctions attributed attacks to GRU military intelligence hackers
  • 📖 Read full article

    Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’

    CyberScoop · Jul 13 · Relevance: ██████████ 10/10

    Why it matters to CISOs: Attribution of destructive cyberattacks on Poland's energy grid to the FSB's Turla group, combined with coordinated Western sanctions, marks a significant geopolitical escalation that enterprise CISOs in critical infrastructure sectors must factor into their threat intelligence and board communications.

    • EU and UK attributed winter cyberattacks on Poland's energy grid directly to Russia's FSB
    • Turla APT group specifically named for espionage and destructive attack campaigns
    • Joint sanctions represent a coordinated European deterrence mechanism against state-sponsored cyber operations
    • 📖 Read full article

      Officials once again warn defenders that Russian hackers are targeting network devices

      CyberScoop · Jul 13 · Relevance: █████████░ 9/10

      Why it matters to CISOs: A joint government advisory warning of Russian FSB exploitation of Cisco Smart Install vulnerabilities across defense, energy, finance, and healthcare sectors requires immediate action from CISOs operating in critical infrastructure to audit network device exposure.

      • State-sponsored Russian hackers targeting network devices across defense, communications, energy, finance, government, and healthcare sectors
      • Cisco Smart Install vulnerabilities specifically flagged as actively exploited
      • Joint advisory issued by US authorities coordinating with international partners
      • 📖 Read full article

        US sanctions VPN, malware providers for enabling ransomware attacks

        BleepingComputer · Jul 14 · Relevance: ████████░░ 8/10

        Why it matters to CISOs: OFAC's sanctioning of a VPN service provider and malware cryptor seller specifically for enabling ransomware operations signals that infrastructure enablers are now primary targets of US enforcement—CISOs should assess any third-party tools or services with potential sanctions exposure.

        • US Treasury OFAC sanctioned First VPN Service (1VPNS) and its Ukrainian administrator for providing tools to ransomware groups
        • A Belarusian individual separately sanctioned for selling malware cryptor services used to evade detection
        • Marks the first time a VPN service provider has been sanctioned for ransomware enablement
        • 📖 Read full article

          🔓 Data Breach
          Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

          The Hacker News · Jul 14 · Relevance: █████████░ 9/10

          Why it matters to CISOs: ShinyHunters' sustained exploitation of OAuth trust relationships in Salesforce environments—without exploiting any platform vulnerability—is a direct wake-up call for CISOs to audit third-party OAuth connections and inherited trust chains in their Salesforce deployments.

          • ShinyHunters-linked actors spent a year compromising corporate Salesforce environments without exploiting any Salesforce platform vulnerability
          • Attack vector relied entirely on OAuth connections between Salesforce and third-party vendors and apps
          • Microsoft documented three distinct attack paths used in the campaign
          • 📖 Read full article

            Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI

            TechCrunch Security · Jul 13 · Relevance: ███████░░░ 7/10

            Why it matters to CISOs: This incident illustrates a critical gap in offboarding controls—a former employee retained access long after departure due to a system bug, highlighting the need for redundant access revocation verification especially when employees depart to competitors.

            • A former Apple employee exploited a system bug to download confidential files from Apple's network after leaving the company
            • The former employee had joined rival OpenAI before the access was exploited
            • Apple described the vulnerability enabling persistent post-departure access as a 'rare' bug
            • 📖 Read full article

              ⚖️ Governance & Policy
              Lessons Learned from CISA’s Recent GitHub Leak

              Krebs on Security · Jul 13 · Relevance: █████████░ 9/10

              Why it matters to CISOs: CISA's own failure to detect dozens of leaked internal credentials—including AWS GovCloud keys—sitting in a public GitHub repo for nearly six months is a critical governance case study that every CISO should use to benchmark their own secrets management and contractor oversight programs.

              • A contractor published dozens of internal CISA credentials including AWS GovCloud keys to a public GitHub repository
              • The exposure went undetected for almost six months before KrebsOnSecurity notified CISA
              • CISA issued a formal postmortem identifying gaps in detection and contractor oversight
              • 📖 Read full article

                Hackers have found a new trick to collect Microsoft Entra user data without raising red flags

                Cybersecurity Dive · Jul 13 · Relevance: ███████░░░ 7/10

                Why it matters to CISOs: A newly documented obfuscation technique allowing attackers to enumerate Microsoft Entra ID users without triggering alerts requires CISOs to proactively review log configurations and detection rules across their identity infrastructure.

                • Attackers are using a novel technique to enumerate Microsoft Entra ID user accounts while evading standard detection mechanisms
                • Proofpoint researchers identified and published the technique with guidance on log indicators to review
                • The method exploits how Entra ID handles certain authentication flows to avoid generating suspicious signals
                • 📖 Read full article

                  🚨 Critical Vulnerability
                  Progress Software Warns of "External Security Threat" to ShareFile

                  Infosecurity Magazine · Jul 13 · Relevance: ████████░░ 8/10

                  Why it matters to CISOs: Progress Software—maker of MOVEit, which was exploited in one of the largest breach campaigns in history—is now warning of an active external security threat to ShareFile's Storage Zone Controller, requiring immediate shutdown action from enterprise customers running on-premises deployments.

                  • Progress Software issued an urgent warning about an external security threat targeting ShareFile Storage Zone Controller
                  • Customers were urged to immediately shut down servers hosting the Storage Zone Controller
                  • Progress Software has a history of critical vulnerabilities in file transfer products including the MOVEit mass exploitation campaign
                  • 📖 Read full article

                    Further Reading
                    • 🌍 EU sanctions Russian GRU military hackers over cyberattacksBleepingComputer
                    • 🌍 Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’CyberScoop
                    • 🌍 Officials once again warn defenders that Russian hackers are targeting network devicesCyberScoop
                    • 🌍 US sanctions VPN, malware providers for enabling ransomware attacksBleepingComputer
                    • 🔓 Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters ActivityThe Hacker News
                    • 🔓 Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAITechCrunch Security
                    • ⚖️ Lessons Learned from CISA’s Recent GitHub LeakKrebs on Security
                    • ⚖️ Hackers have found a new trick to collect Microsoft Entra user data without raising red flagsCybersecurity Dive
                    • 🚨 Progress Software Warns of "External Security Threat" to ShareFileInfosecurity Magazine
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext for Tuesday, July 14th, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves. So, Europe finally decided to name names. The EU and UK dropped the first joint cyber sanctions package yesterday, going directly after GRU operators and, perhaps more significantly, formally attributing the winter attacks on Poland's energy grid to the FSB's Turla group. If you run critical infrastructure anywhere in Europe or serve European markets, your threat model just changed.

                      Alex: That's where we're starting today, and there's a lot to unpack. We've got a coordinated Western sanctions package, a joint advisory on Russian exploitation of network devices, OFAC going after ransomware enablers for the first time, ShinyHunters spending a full year inside Salesforce environments without touching a single platform vulnerability, CISA's own embarrassing credential leak, and Progress Software telling customers to shut down ShareFile servers immediately. Plus Apple's offboarding controls apparently had a rather significant gap. Let's get into it.

                      Jordan: So let's talk about the sanctions. This isn't just another round of finger-wagging. The EU and UK coordinated simultaneously, sanctioning dozens of Russian individuals and entities. They publicly attributed specific campaigns to specific units within Russian intelligence. That's GRU for the broader European hacking operations, and FSB's Turla group specifically for the attacks on Poland's energy grid last winter. This is a deterrence posture shift, not just a diplomatic gesture.

                      Alex: And I think the Poland attribution is the piece that should get the most attention in the boardroom. Attributing destructive attacks on energy infrastructure to a named state intelligence unit is about as far as Western governments go short of kinetic response. For CISOs in energy, utilities, transportation, any critical infrastructure sector operating in Europe, this is the signal that says the threat is not theoretical and your government agrees.

                      Jordan: Right. And layered on top of that, we got the joint advisory, US authorities coordinating with international partners, specifically warning that Russian FSB actors are actively exploiting Cisco Smart Install vulnerabilities across defense, communications, energy, finance, government, and healthcare. This isn't new in concept. We've seen advisories about network device targeting before. But the timing alongside the sanctions tells you something about the intelligence community's current assessment of Russian operational tempo.

                      Alex: So what's the action item? If you're a CISO hearing this, the immediate move is to audit your Cisco Smart Install exposure. If you have it enabled and you're not actively using it, disable it. If you are using it, make sure it's not internet-facing and that you've applied every relevant patch. But the broader action is to revisit your network device hardening posture generally. Routers, switches, firewalls, these are the devices that attackers love because they often sit outside your EDR coverage, outside your normal logging pipeline, and they provide persistent access that survives endpoint reimaging.

                      Jordan: And frankly, most organizations still treat network device security as an infrastructure team problem rather than a security team problem. That gap is exactly what state actors exploit.

                      Alex: Staying on the sanctions theme but shifting to the US side, OFAC sanctioned a VPN service provider called First VPN Service, or 1VPNS, along with its Ukrainian administrator, specifically for providing infrastructure to ransomware groups. They also hit a Belarusian individual selling malware cryptor services. This is the first time a VPN provider has been sanctioned for ransomware enablement.

                      Jordan: This is significant because it signals that the US is now going after the enablement layer, not just the operators. If you're providing the infrastructure that makes ransomware possible, you are now a sanctions target. For CISOs, the practical concern is third-party risk. You need to be asking whether any of your vendors, any of your employees' tools, any shadow IT services have potential sanctions exposure. Because if your organization is transacting with a sanctioned entity, even unknowingly, that creates legal liability.

                      Alex: And this is a conversation your general counsel needs to be part of. Sanctions compliance isn't optional, and the scope of what constitutes a sanctionable entity in the cyber domain just expanded considerably.

                      Jordan: Let's shift to what I think is one of the most operationally important stories today. Microsoft published research mapping three distinct attack paths that ShinyHunters-linked actors used over the past year to compromise corporate Salesforce environments. And here's the critical detail: they didn't exploit a single Salesforce vulnerability. Not one. The entire attack surface was the OAuth trust relationships that organizations had configured between Salesforce and their third-party apps and vendors.

                      Alex: This is the story that should make every CISO uncomfortable, because it's not about a vendor failing you. It's about your own trust architecture failing you. When you connect a third-party app to Salesforce via OAuth, you're extending trust. And if that third party gets compromised, or if those OAuth tokens are mismanaged, the attacker inherits whatever access you granted. ShinyHunters apparently understood this better than most defenders do.

                      Jordan: Microsoft documented three paths. The specifics matter less than the pattern. Every one of them exploited inherited trust, the transitive trust problem that identity teams have been warning about for years. The action here is to audit every OAuth connection in your Salesforce environment. Know what apps have access, what scopes they were granted, whether those grants are still appropriate, and whether those third parties have adequate security controls. If you can't answer those questions, you have blind spots that are actively being exploited in the wild.

                      Alex: And this extends beyond Salesforce. Any SaaS platform with OAuth integrations has this same trust architecture. Salesforce just happens to be where ShinyHunters went hunting. The principle is universal.

                      Jordan: Speaking of trust architecture problems, let's talk about CISA's GitHub leak. Krebs reported that a contractor published dozens of internal CISA credentials, including AWS GovCloud keys, to a public GitHub repository. And those credentials sat there, publicly accessible, for almost six months before KrebsOnSecurity notified CISA.

                      Alex: Six months. The nation's cyber defense agency had live credentials exposed on a public repo for six months and didn't detect it. CISA deserves credit for publishing a formal postmortem, but this is a governance failure that every CISO should study carefully, because if CISA can miss this, so can you.

                      Jordan: The lessons from the postmortem are straightforward but apparently difficult to implement consistently. Secrets scanning needs to be automated and continuous, not just at commit time but across all repositories including contractor repos. Contractor oversight needs teeth. You need to know what your contractors are doing with your credentials, where they're storing them, and whether they're following your policies. And detection of credential exposure needs to be treated as a critical alerting use case, not a nice-to-have.

                      Alex: I'd add that this is a board-level conversation about contractor risk management. Most organizations have significant contractor populations with access to sensitive systems and credentials. If your secrets management program doesn't extend to contractors with the same rigor as employees, you have the same gap CISA had.

                      Jordan: Two more stories to cover. Proofpoint documented a technique for enumerating Microsoft Entra ID users without triggering standard detection. Attackers are exploiting how Entra handles certain authentication flows to identify valid accounts silently. This is pre-attack reconnaissance, the kind of thing that precedes credential stuffing or targeted phishing.

                      Alex: The action is to review Proofpoint's published indicators and check your Entra ID logs for signs of this enumeration technique. If your detection rules are built around standard failed authentication patterns, you may be missing this entirely. Identity infrastructure monitoring needs to evolve as fast as the evasion techniques, and right now, the attackers are ahead.

                      Jordan: And then there's Progress Software warning customers about what they're calling an external security threat to ShareFile's Storage Zone Controller. They're telling customers to shut down servers immediately.

                      Alex: If you're running ShareFile with on-premises Storage Zone Controllers, this is a drop-everything situation. Progress Software has earned a very specific reputation since the MOVEit campaign, and when they issue an urgent shutdown advisory, you take it at face value. Shut the servers down, wait for guidance, and have your incident response team review logs for any signs of compromise.

                      Jordan: The Apple story is worth a quick mention for the governance lesson. A former employee who left for OpenAI apparently exploited what Apple calls a rare bug to download confidential files after departure. The access should have been revoked. It wasn't, because of a system defect.

                      Alex: Every CISO should hear this and immediately ask: do we have redundant verification that access is actually revoked when someone leaves? Not just that the offboarding ticket was closed, but that every system, every credential, every token was actually deactivated. Because a single point of failure in your offboarding process is exactly the kind of thing that creates headlines.

                      Jordan: And when someone leaves for a direct competitor, the scrutiny should be even higher. That should trigger enhanced monitoring and verification as a matter of policy.

                      Alex: All right, let's talk about what's emerging here. The theme of the day, and frankly the theme of the quarter, is that the Western world is moving from passive cyber defense to active deterrence and enforcement. Coordinated sanctions, public attribution to specific intelligence units, OFAC going after enablement infrastructure. The policy environment is hardening rapidly.

                      Jordan: And that creates both protection and obligation for CISOs. Protection because these actions impose costs on adversaries and may reduce some threat volume over time. Obligation because your board is going to see these headlines and expect you to have a position on how your organization is responding to a threat environment that governments are calling serious enough to warrant sanctions and public attribution.

                      Alex: If you haven't updated your board briefing on the Russian cyber threat since the Ukraine invasion began, now is the time. The threat landscape has evolved. The policy landscape has evolved. Your board communication should reflect both.

                      Jordan: And on the operational side, the ShinyHunters Salesforce campaign and the CISA GitHub leak are both reminders that the most dangerous risks aren't exotic zero-days. They're trust relationships you've already established and credentials you've already issued. The basics still matter more than anything.

                      Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.

                      Jordan: I'm Jordan Reeves. We'll see you tomorrow.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-14.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext