Cleartext

Cleartext – July 16, 2026


Listen Later

Cleartext – July 16, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: US charges Russian β€˜bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims; Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife; Identity Attacks Overtake Exploits as Top Ransomware Cause.

Stories Covered
🌍 Geopolitical
US charges Russian β€˜bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims

TechCrunch Security Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

Why it matters to CISOs: The unsealing of this indictment against Russian bulletproof hosting operators who enabled large-scale cybercrime confirms continued US DOJ pressure on the criminal infrastructure layer; CISOs should treat these hosting networks as ongoing threat infrastructure still in partial operation.

  • A 2024 indictment now unsealed charges three Russian nationals and two web hosting entities
  • The accused allegedly aided hackers and directly profited from cybercrime netting $62 million from victims
  • Bulletproof hosting remains a key enabler of ransomware, fraud, and malware distribution operations targeting enterprises
  • πŸ“– Read full article

    Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife

    Dark Reading Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

    Why it matters to CISOs: US export restrictions on frontier AI models are accelerating European and UK digital sovereignty initiatives, which will affect enterprise AI security tooling procurement, vendor lock-in risk assessments, and compliance obligations for multinationals operating across jurisdictions.

    • US government restrictions on Anthropic and OpenAI frontier models have intensified UK and European calls to reduce reliance on US tech
    • The sovereignty push has significant implications for cloud and AI security architecture decisions in multinational enterprises
    • CISOs in regulated industries may face new data residency and AI governance requirements as a result of emerging regional policies
    • πŸ“– Read full article

      πŸ“‘ Macro Trends
      Identity Attacks Overtake Exploits as Top Ransomware Cause

      Dark Reading Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

      Why it matters to CISOs: The finding that MFA was present in 97% of credential-based ransomware attacks yet still failed to prevent compromise should directly inform CISO board reporting and drive investment in phishing-resistant MFA, identity threat detection, and privileged access controls.

      • Identity and credential-based attacks have surpassed software exploits as the leading ransomware initial access vector
      • MFA was deployed in 97% of credential-compromise incidents but failed to stop the breach in those cases
      • Phishing and brute-force attacks are now the primary ransomware delivery mechanisms according to Sophos incident data
      • πŸ“– Read full article

        πŸ”“ Data Breach
        Scattered Spider hackers sentenced to 5.5 years over Β£29 million Transport for London hack

        The Record (Recorded Future) Β· Jul 16 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

        Why it matters to CISOs: The sentencing of key Scattered Spider members marks a notable deterrence milestone for a group that successfully compromised major enterprises including MGM and Caesars; CISOs should note the social engineering and SIM-swapping TTPs used remain active across the group's broader membership.

        • Two leading Scattered Spider members were sentenced to five years and six months in prison each
        • The 2024 TfL attack caused an estimated Β£29 million in damages
        • Convictions were secured under the Computer Misuse Act following guilty pleas
        • πŸ“– Read full article

          Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies

          The Record (Recorded Future) Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

          Why it matters to CISOs: The Nichirei Logistics attack demonstrates that third-party operational technology and logistics providers remain high-impact ransomware targets with cascading supply chain consequences, a direct concern for CISOs managing vendor risk in critical supply chains.

          • Nichirei Logistics Group, Japan's largest cold-chain operator, suffered a cyberattack that disrupted food supply chains
          • KFC restaurants in Japan were left short on ingredients due to the disruption
          • The attack highlights OT and logistics sector vulnerability to ransomware with real-world supply chain consequences
          • πŸ“– Read full article

            βš–οΈ Governance & Policy
            Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities

            The Record (Recorded Future) Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

            Why it matters to CISOs: Gold Eagle represents a significant shift in how the US government will coordinate vulnerability discovery and prioritization at scale using AI, potentially reshaping patch management timelines and vendor disclosure obligations for critical infrastructure operators.

            • The White House launched the Gold Eagle program to use AI to accelerate vulnerability discovery, prioritization, and patching
            • The program involves industry, critical infrastructure operators, and government agencies
            • Launch comes amid a record 570 CVEs patched by Microsoft in a single Patch Tuesday, attributed partly to AI-assisted discovery
            • πŸ“– Read full article

              23andMe reaches $18 million settlement with states for massive breach

              The Record (Recorded Future) Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

              Why it matters to CISOs: A 42-state AG coalition settlement sets a precedent for multi-jurisdictional accountability following a single breach, signaling that state-level enforcement will be an increasingly significant liability vector alongside federal action for organizations holding sensitive personal data.

              • 23andMe reached an $18 million settlement with 42 state attorneys general over the 2023 breach
              • The settlement reflects cybersecurity failings as the basis for state-level regulatory action
              • The breach exposed genetic and health data of millions, making it a high-profile test case for sensitive data liability
              • πŸ“– Read full article

                🚨 Critical Vulnerability
                SonicWall customers under threat as attackers exploit 2 zero-days

                CyberScoop Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                Why it matters to CISOs: SonicWall is pervasive in enterprise network perimeters; chained zero-days being actively exploited weeks before disclosure and patching means organizations need to audit exposure and apply patches immediately or consider compensating controls.

                • Two SonicWall zero-day vulnerabilities are being actively chained together by attackers
                • Exploitation began approximately three weeks before the vendor disclosed and patched the flaws
                • The delayed disclosure window means many organizations may already be compromised
                • πŸ“– Read full article

                  CISA warns that multiple vulnerabilities in SharePoint are under exploitation

                  Cybersecurity Dive Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                  Why it matters to CISOs: SharePoint is a core collaboration platform in most enterprises; active chained exploitation with no patch until August creates a material, time-bounded risk window requiring immediate mitigations or isolation decisions.

                  • Multiple SharePoint vulnerabilities are being chained and actively exploited
                  • A patch will not be available until August, leaving a significant exposure window
                  • CISA has issued a formal warning to federal agencies and by extension enterprise defenders
                  • πŸ“– Read full article

                    Further Reading
                    • 🌍 US charges Russian β€˜bulletproof’ web hosts over cyberattacks that netted $62M from cybercrime victims β€” TechCrunch Security
                    • 🌍 Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife β€” Dark Reading
                    • πŸ“‘ Identity Attacks Overtake Exploits as Top Ransomware Cause β€” Dark Reading
                    • πŸ”“ Scattered Spider hackers sentenced to 5.5 years over Β£29 million Transport for London hack β€” The Record (Recorded Future)
                    • πŸ”“ Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies β€” The Record (Recorded Future)
                    • βš–οΈ Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities β€” The Record (Recorded Future)
                    • βš–οΈ 23andMe reaches $18 million settlement with states for massive breach β€” The Record (Recorded Future)
                    • 🚨 SonicWall customers under threat as attackers exploit 2 zero-days β€” CyberScoop
                    • 🚨 CISA warns that multiple vulnerabilities in SharePoint are under exploitation β€” Cybersecurity Dive
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext. It's Thursday, July 16th, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves. Let's get into it.

                      Alex: We've got a packed show today. Two actively exploited zero-day chains that need your attention this morning, SonicWall and SharePoint. A landmark identity and ransomware study that should change how you talk to your board about MFA. The White House launches Gold Eagle, an AI-powered vulnerability clearinghouse. Scattered Spider members get sentenced. A cold-chain attack in Japan takes out KFC's supply chain. The 23andMe settlement sets a new bar for state-level enforcement. And we'll touch on the UK's sovereignty push and a Russian bulletproof hosting indictment. Let's start where your SOC should be starting this morning.

                      Jordan: Yeah, let's lead with the two vulnerability stories because these are time-sensitive. SonicWall disclosed and patched two zero-days that attackers have been chaining together, but here's the part that matters: exploitation started approximately three weeks before the vendor disclosed. Three weeks. If you're running SonicWall on your perimeter, the question isn't whether to patch. The question is whether you're already compromised. You need to audit your exposure, apply the patches, and hunt for indicators of compromise in that three-week window. That's your priority one action item today.

                      Alex: And priority two isn't far behind. CISA formally warned that multiple SharePoint vulnerabilities are being chained and actively exploited. SharePoint sits at the center of collaboration infrastructure in most enterprises. The complicating factor here is there's no patch until August. So you're looking at a material exposure window where you need to make real decisions. Do you apply compensating controls? Do you isolate? Do you restrict access? This is exactly the kind of risk decision that separates mature programs from reactive ones.

                      Jordan: And I'll note the uncomfortable pattern: both of these are perimeter or core enterprise platforms, both involve chained exploits, and both have timing gaps that favor the attacker. This is the new normal. Vulnerability management is no longer just about patching fast. It's about assuming the window between exploitation and disclosure is getting longer, not shorter.

                      Alex: Which actually connects to the Gold Eagle story. The White House launched this program to use AI to accelerate vulnerability discovery, prioritization, and patching across government and critical infrastructure. The timing is notable. Microsoft just patched 570 CVEs in a single Patch Tuesday, and they attribute part of that volume to AI-assisted discovery. Gold Eagle is essentially the government's attempt to operationalize that at national scale.

                      Jordan: I have mixed feelings. On one hand, the intent is right. The vulnerability ecosystem is drowning in volume, and we need better signal-to-noise. AI can genuinely help with prioritization. On the other hand, if you accelerate discovery without proportionally accelerating remediation, you've just made the problem worse. You've given defenders a bigger backlog and potentially given adversaries more targets if any of this leaks or is independently discovered. The execution here will matter enormously. But for CISOs, the takeaway is straightforward: expect the volume of disclosed vulnerabilities to continue increasing. Your patch management program needs to be built for that trajectory, not for last year's volume.

                      Alex: Let's shift to the identity and ransomware story, because this one has direct board-level implications. Sophos published incident data showing that identity and credential-based attacks have now surpassed software exploits as the leading initial access vector for ransomware. That shift has been coming, but here's the statistic that should stop you: MFA was deployed in 97 percent of the credential-compromise incidents. Ninety-seven percent. And it still failed.

                      Jordan: This is the number that needs to be in your next board presentation. Not because MFA is useless, but because most organizations are still running legacy MFA, push notifications, SMS codes, time-based tokens, that are vulnerable to adversary-in-the-middle attacks, MFA fatigue, and SIM swapping. The attackers have adapted. Phishing kits now routinely include real-time proxy capabilities that intercept MFA tokens as they're entered. The control that your board thinks is protecting you is being systematically defeated.

                      Alex: So what's the action? First, accelerate the move to phishing-resistant MFA, FIDO2 keys, passkeys, hardware-bound credentials. Second, invest in identity threat detection and response. You need behavioral analytics on authentication patterns, impossible travel detection, token replay detection. Third, tighten privileged access controls. If an attacker gets a credential, the blast radius should be contained by just-in-time access and segmentation. This isn't a technology gap. The solutions exist. It's a deployment and prioritization gap.

                      Jordan: And I'd add, stop reporting MFA coverage percentage as a security metric to your board without qualifying it. Saying "we have 98 percent MFA coverage" is meaningless if 100 percent of that is push-based MFA that can be phished. The metric needs to reflect the quality of the control, not just its presence.

                      Alex: Speaking of social engineering, let's talk about Scattered Spider. Two leading members were sentenced to five and a half years each for the 2024 Transport for London attack, which caused an estimated 29 million pounds in damages. Guilty pleas under the Computer Misuse Act.

                      Jordan: Five and a half years is meaningful. For a group that hit MGM, Caesars, TfL, and a string of other major targets, this is the first real deterrence signal. But I want to be clear about the operational picture: Scattered Spider is a loosely affiliated collective. These convictions take out two individuals. The TTPs, social engineering help desks, SIM swapping, exploiting identity providers, those are still active across the broader group. The playbook hasn't been arrested, just two of the players.

                      Alex: And those TTPs connect directly back to the identity conversation we just had. SIM swapping defeats SMS-based MFA. Social engineering help desks defeats knowledge-based authentication. These are the same weaknesses the Sophos data is highlighting at scale.

                      Jordan: Exactly. Different angle, same problem.

                      Alex: Let's move to the Nichirei Logistics attack in Japan. Japan's largest cold-chain operator was hit by a cyberattack that disrupted food supply chains, leaving KFC restaurants short on ingredients and multiple restaurant chains struggling with deliveries.

                      Jordan: This is a textbook third-party OT risk scenario. Your organization might not operate cold-chain logistics, but your supply chain almost certainly depends on someone who does. The cascading impact here, from a single logistics provider to consumer-facing food shortages, is exactly the kind of scenario that CISOs managing vendor risk need to model. If your critical vendors went down for a week, do you know what breaks? Most organizations still can't answer that question with confidence.

                      Alex: And it reinforces that ransomware operators are deliberately targeting operational chokepoints, logistics, healthcare, utilities, because the pressure to pay is highest when real-world operations are disrupted. This is rational adversary behavior, and it should inform your third-party risk tiering.

                      Jordan: Let's talk about the 23andMe settlement. Eighteen million dollars across 42 state attorneys general for the 2023 breach that exposed genetic and health data.

                      Alex: The dollar amount is almost secondary to the precedent. A 42-state AG coalition acting in concert against a single organization for cybersecurity failings. This is the enforcement model that's scaling. Federal regulation remains fragmented, but state-level enforcement is becoming highly coordinated and effective. If you're holding sensitive personal data, particularly health or biometric data, your liability surface now includes 50 potential state-level regulators acting collectively.

                      Jordan: And genetic data is about as sensitive as it gets. You can change a password. You can't change your genome. The reputational and legal exposure for organizations handling this class of data is in a different category entirely. This settlement will be cited in every future state AG action involving sensitive data breaches.

                      Alex: Two more stories to cover. The UK sovereignty push, which Dark Reading is framing as a potential "Tech-xit." US export restrictions on frontier AI models from Anthropic and OpenAI are accelerating calls in the UK and Europe to reduce dependence on American tech. For CISOs at multinationals, this has practical implications. New data residency requirements, AI governance obligations, potential restrictions on which AI-powered security tools you can deploy where. If you're building your security architecture on US-based AI platforms, you need to be scenario-planning for a world where those platforms face access restrictions in key markets.

                      Jordan: And on the Russian bulletproof hosting indictment, DOJ unsealed charges against three Russian nationals and two hosting entities that enabled 62 million dollars in cybercrime. Bulletproof hosting remains the foundational infrastructure layer for ransomware, fraud, and malware distribution. The indictment is a deterrence signal, but the realistic assessment is that this infrastructure is still partially operational and the operators who haven't been charged are still in business. For threat intelligence teams, these hosting networks should remain on your watchlist as known-bad infrastructure.

                      Alex: Let's close with the outlook. Jordan, what's the thread you're pulling across today's stories?

                      Jordan: The theme is the gap between the controls we think we have and the protection they actually provide. MFA is deployed but defeated. Patches exist but arrive weeks after exploitation begins. Vendor risk programs exist but don't model cascading failures. The maturity gap in most organizations isn't in policy or tooling. It's in the honest assessment of whether those controls work against the current threat reality. CISOs who close that gap, who pressure-test their assumptions rather than report their coverage metrics, are the ones who'll be ahead of this.

                      Alex: I'd add that the enforcement and geopolitical landscape is forcing strategic decisions that can't be delegated. AI sovereignty, state AG coalitions, government vulnerability programs. These aren't tactical issues. They're board-level questions about where your organization operates, what data you hold, and who you depend on. The CISO role is increasingly about navigating those strategic decisions, not just running the security program.

                      Jordan: Agreed. Watch the SharePoint exposure window closely over the next few weeks. And if you haven't started your phishing-resistant MFA migration, today's a good day to put that business case together.

                      Alex: That's Cleartext for Thursday, July 16th, 2026. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.

                      Jordan: See you then.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-16.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext