
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 10 stories across 4 topic areas, including: Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime; Sandworm hackers have a CAPTCHA trick for Ukrainians; Now, even Russia's most elite hackers are using Clickfix to infect devices.
CyberScoop Β· Jul 16 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: US indictment of the infrastructure layer enabling ransomware and cybercrime across 21 states is a strategic disruption signalβCISOs should monitor for threat actor rehosting activity and expect potential retaliation campaigns targeting US enterprises.
π Read full article
The Record (Recorded Future) Β· Jul 16 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Russia's Sandwormβa top-tier APT with a history of targeting critical infrastructure globallyβis now operationalizing ClickFix-style CAPTCHA social engineering at scale, a technique that bypasses technical controls and requires updated user awareness training.
π Read full article
Ars Technica Security Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The mainstreaming of ClickFix social engineering among nation-state APT groups means CISOs must revisit browser controls, PowerShell execution policies, and security awareness programs to account for this rapidly proliferating attack vector.
π Read full article
Cybersecurity Dive Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Iranian state-linked and hacktivist groups actively using frontier AI tools for malware development, phishing, and ICS/OT reconnaissance raises the threat baseline for enterprises in critical infrastructure sectors and those with operations in the Middle East.
π Read full article
Help Net Security Β· Jul 17 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A Fortune 500 company filing an SEC 8-K over a ransomware-induced OT/production shutdown is a landmark disclosure moment that will be scrutinized by boards and regulatorsβCISOs should use this to stress-test their own OT/IT incident response and SEC disclosure readiness.
π Read full article
BleepingComputer Β· Jul 16 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: A 43-state AG coalition securing an $18M settlement over failure to protect highly sensitive genetic data sets a meaningful precedent for state-level regulatory coordination and liability exposure for any enterprise holding sensitive health or biometric data.
π Read full article
The Record (Recorded Future) Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The UK sentencing of teenage Scattered Spider members to 5.5 years is a landmark deterrence signal for social-engineering-driven cybercrime, and reinforces to CISOs that identity-based attacks on enterprise helpdesks carry serious criminal consequences internationally.
π Read full article
Cybersecurity Dive Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A GAO audit exposing material weaknesses in FAA and TSA aviation cybersecurity oversight signals potential regulatory tightening aheadβCISOs in aviation, aerospace, and adjacent critical infrastructure should anticipate new compliance mandates.
π Read full article
The Hacker News Β· Jul 17 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A CVSS 9.8 critical deserialization RCE in Microsoft SharePoint Server being actively exploited and added to KEV with a 48-hour federal patch deadline demands immediate enterprise prioritization, as SharePoint is deeply embedded in most large organizations' collaboration infrastructure.
π Read full article
BleepingComputer Β· Jul 17 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Actively exploited critical vulnerabilities in Fortinet FortiSandboxβa perimeter security product present in many enterprise environmentsβwith a 48-hour federal patch window signal urgency for any CISO running this platform.
π Read full article
Alex: Welcome to Cleartext for Friday, July 17th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Let's start here: Coca-Cola filed an 8-K yesterday because ransomware shut down every Fairlife milk production line in the United States. A Fortune 500 company, SEC disclosure, physical production halted. If you're a CISO who's been trying to get your board to fund OT segmentation, your exhibit A just arrived.
Alex: That's where we're going to start today, and we've got a packed show. We'll cover that Fairlife incident and what it means for SEC disclosure playbooks, a critical SharePoint zero-day that CISA wants patched by Sunday, Fortinet flaws on the same timeline, bulletproof hosting indictments targeting the infrastructure layer of cybercrime, Sandworm adopting ClickFix social engineering, Iran using AI to sharpen its cyber playbook, the 23andMe eighteen million dollar settlement, Scattered Spider members going to prison, and a GAO report that should concern anyone in aviation. Let's get into it.
Jordan: So the Fairlife ransomware incident. The 8-K was filed July 16th. All US milk production suspended. Canadian operations apparently unaffected. Coca-Cola says product quality and safety weren't compromised, but the operational disruption is total on the US side. This is ransomware doing what ransomware does best in 2026: it doesn't just encrypt your files, it stops your factory.
Alex: And from a governance perspective, this is the SEC materiality disclosure framework working exactly as designed. Coca-Cola had to determine that a production shutdown across an entire subsidiary's US operations was material, and they disclosed within the required window. What I want every CISO listening to take from this is: do you have your materiality determination process rehearsed for an OT event? Not an IT event, an OT event. Because the calculus is different. When production stops, materiality is almost self-evident, and the clock starts immediately.
Jordan: The other angle here is supply chain. Fairlife is a major protein shake and milk brand. Retailers are going to feel this within days. If you're in consumer packaged goods, food and beverage, manufacturing, this is your threat model. Ransomware actors know that operational downtime in physical production creates enormous pressure to pay. The leverage is the production line itself.
Alex: Use this as your board conversation on Monday. Not fear-mongering, just pointing to a peer company's SEC filing and asking: are we ready for this exact scenario?
Jordan: Let's pivot to the vulnerability side, because CISOs have a very busy weekend ahead. CISA added CVE-2026-58644 to the Known Exploited Vulnerabilities catalog yesterday. This is a critical deserialization flaw in Microsoft SharePoint Server. CVSS 9.8. Active exploitation confirmed. Federal agencies have until July 19th, which is Sunday, to patch.
Alex: SharePoint Server on-premises is still deeply embedded in a lot of large enterprises. This isn't SharePoint Online, this is the on-prem footprint that many organizations haven't fully migrated away from. If you're running it, this is a drop-everything priority. Deserialization to RCE at 9.8 with active exploitation, there's no ambiguity here.
Jordan: And on the same timeline, CISA is also ordering patches for two critical Fortinet FortiSandbox vulnerabilities, also actively exploited, also due Sunday. Fortinet perimeter devices have been a persistent target for nation-state and ransomware operators. If you're running FortiSandbox, check your versions today, not Monday.
Alex: Two critical, actively exploited vulnerability sets with a forty-eight hour patch window. That's your weekend, unfortunately.
Jordan: Now let's talk about the infrastructure layer. The DOJ unsealed indictments against three Russian nationals and their entities, Media Land and ML.Cloud, for operating bulletproof hosting that enabled cyberattacks across twenty-one US states and multiple countries. Losses attributed to the cybercrime facilitated by this infrastructure exceed sixty-two million dollars.
Alex: This is strategically significant because it targets the logistical backbone, not individual threat actors. Bulletproof hosting is the real estate of cybercrime. Ransomware operators, phishing campaigns, command and control infrastructure, they all need somewhere to live. When you take down or indict the landlords, you force displacement across the entire ecosystem.
Jordan: Right, and displacement creates signal. When threat actors have to rehost, they make mistakes, they leave traces, they sometimes fragment. But it also means there's a transition period where groups may accelerate operations before they lose infrastructure, or lash out in retaliation. CISOs should be watching their threat intelligence feeds for indicators of migration and for any uptick in activity from groups that were known customers of these hosting providers.
Alex: It's also worth noting that indictments against Russian nationals are, in practice, more about disruption and deterrence than extradition. But the intelligence value of the investigation itself is enormous, and it gives law enforcement tools to seize assets and block infrastructure.
Jordan: Let's stay in Russia's orbit. Sandworm is now using ClickFix. For those who haven't tracked this, ClickFix is a social engineering technique where a target is presented with a fake CAPTCHA that instructs them to copy and paste a PowerShell command into their machine. It originated with financially motivated criminals, and now Russia's most capable APT group is deploying it against Ukrainian targets at scale.
Alex: This is a significant development because it represents a technique that bypasses almost every technical control you've deployed. The user is the execution engine. They're literally pasting malicious code into their own terminal. Endpoint detection can catch the payload after execution, but the initial compromise relies entirely on human behavior.
Jordan: And Ars Technica covered the broader trend in a companion piece. ClickFix isn't just Sandworm now. It's proliferating across the nation-state landscape precisely because it works. The technique exploits trust in CAPTCHA flows that users encounter dozens of times a week. The defense here isn't a new tool, it's updated awareness training that specifically addresses this scenario, and it's PowerShell execution policies that constrain what a standard user can run.
Alex: If your organization hasn't added ClickFix-style scenarios to your phishing simulation program, you're behind. And revisit your PowerShell constrained language mode policies. There's no reason most end users need unrestricted PowerShell execution.
Jordan: Staying on the nation-state theme, Cybersecurity Dive reported that Iran-nexus actors, both state-linked groups and affiliated hacktivists, are actively using ChatGPT and similar frontier AI tools for malware development, phishing campaign creation, and, critically, mapping industrial control system sites.
Alex: That last point is the one that should get attention. ICS and OT reconnaissance using AI tools means these groups can move faster in identifying targets and understanding industrial environments. If you're in critical infrastructure, energy, water, manufacturing, and you have any exposure to the Middle East or are in a sector Iran has historically targeted, your threat baseline just moved up.
Jordan: The broader signal is that AI is lowering the barrier to entry and accelerating the playbook for second-tier nation-state actors. Iran doesn't have Russia or China's bench depth in cyber operations, but AI is a force multiplier that narrows that gap.
Alex: Let's shift to governance. 23andMe agreed to pay eighteen million dollars to settle claims from forty-three state attorneys general over the 2023 genetic data breach. Forty-three states coordinating on a single enforcement action. That's the story within the story.
Jordan: The underlying attack was credential stuffing. Password reuse. A foundational identity hygiene failure. And it resulted in the exposure of genetic data, which is about as sensitive as data gets. The legal theory here is straightforward: you held extraordinarily sensitive data, you didn't enforce adequate authentication controls, and now forty-three states are holding you accountable.
Alex: For CISOs, the precedent is the coordinated multistate AG action. This is becoming a standard enforcement model. If you're holding biometric data, genetic data, health data, sensitive PII at scale, your regulatory exposure isn't just federal. It's fifty potential state-level actions, and they're increasingly working together. Make sure your legal and compliance teams are modeling this.
Jordan: On the criminal enforcement side, two Scattered Spider members were sentenced to five and a half years each at Woolwich Crown Court for the 2024 Transport for London hack. Owen Flowers, eighteen, and Thalha Jubair, twenty. The attack rendered a hundred and forty-eight systems inoperable and forced all twenty-seven thousand TfL employees to reset passwords in person. Cost: twenty-nine million pounds.
Alex: The sentencing is meaningful as a deterrence signal for the social-engineering-driven cybercrime model that Scattered Spider pioneered. These are young operators who targeted enterprise helpdesks with social engineering, and they're now going to prison for more than five years. The NCA also confirmed that the arrests disrupted Scattered Spider's broader operations, which is the more operationally significant outcome.
Jordan: And finally, a GAO audit found material weaknesses in both FAA and TSA cybersecurity programs for aviation. Network security gaps, oversight strategy deficiencies. When GAO publishes findings like this, Congress typically follows with new requirements.
Alex: If you're in aviation, aerospace, or adjacent critical infrastructure, start anticipating new compliance mandates. GAO reports are leading indicators of regulatory action. Don't wait for the rule to start preparing.
Jordan: So looking at the week as a whole, what's the thread?
Alex: The thread is convergence. Nation-state techniques are converging with criminal techniques. Regulatory enforcement is converging across jurisdictions. And the attack surface is converging IT and OT in ways that create physical-world consequences. The Fairlife 8-K, the ClickFix adoption by Sandworm, the multistate AG action on 23andMe, these aren't isolated events. They're all manifestations of a threat and regulatory environment that's compressing. The distance between a phishing email and a factory shutdown, between a credential stuffing attack and a forty-three state lawsuit, that distance is shrinking.
Jordan: And next week, watch for the fallout from that SharePoint zero-day. Active exploitation plus a weekend patch deadline means Monday morning is going to reveal who was ready and who wasn't.
Alex: That's our show for today. Thanks for listening to Cleartext. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, and patch your SharePoint.
Jordan: And your Fortinet. See you Monday.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-17.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 10 stories across 4 topic areas, including: Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime; Sandworm hackers have a CAPTCHA trick for Ukrainians; Now, even Russia's most elite hackers are using Clickfix to infect devices.
CyberScoop Β· Jul 16 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: US indictment of the infrastructure layer enabling ransomware and cybercrime across 21 states is a strategic disruption signalβCISOs should monitor for threat actor rehosting activity and expect potential retaliation campaigns targeting US enterprises.
π Read full article
The Record (Recorded Future) Β· Jul 16 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Russia's Sandwormβa top-tier APT with a history of targeting critical infrastructure globallyβis now operationalizing ClickFix-style CAPTCHA social engineering at scale, a technique that bypasses technical controls and requires updated user awareness training.
π Read full article
Ars Technica Security Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The mainstreaming of ClickFix social engineering among nation-state APT groups means CISOs must revisit browser controls, PowerShell execution policies, and security awareness programs to account for this rapidly proliferating attack vector.
π Read full article
Cybersecurity Dive Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Iranian state-linked and hacktivist groups actively using frontier AI tools for malware development, phishing, and ICS/OT reconnaissance raises the threat baseline for enterprises in critical infrastructure sectors and those with operations in the Middle East.
π Read full article
Help Net Security Β· Jul 17 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A Fortune 500 company filing an SEC 8-K over a ransomware-induced OT/production shutdown is a landmark disclosure moment that will be scrutinized by boards and regulatorsβCISOs should use this to stress-test their own OT/IT incident response and SEC disclosure readiness.
π Read full article
BleepingComputer Β· Jul 16 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: A 43-state AG coalition securing an $18M settlement over failure to protect highly sensitive genetic data sets a meaningful precedent for state-level regulatory coordination and liability exposure for any enterprise holding sensitive health or biometric data.
π Read full article
The Record (Recorded Future) Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The UK sentencing of teenage Scattered Spider members to 5.5 years is a landmark deterrence signal for social-engineering-driven cybercrime, and reinforces to CISOs that identity-based attacks on enterprise helpdesks carry serious criminal consequences internationally.
π Read full article
Cybersecurity Dive Β· Jul 16 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A GAO audit exposing material weaknesses in FAA and TSA aviation cybersecurity oversight signals potential regulatory tightening aheadβCISOs in aviation, aerospace, and adjacent critical infrastructure should anticipate new compliance mandates.
π Read full article
The Hacker News Β· Jul 17 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A CVSS 9.8 critical deserialization RCE in Microsoft SharePoint Server being actively exploited and added to KEV with a 48-hour federal patch deadline demands immediate enterprise prioritization, as SharePoint is deeply embedded in most large organizations' collaboration infrastructure.
π Read full article
BleepingComputer Β· Jul 17 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Actively exploited critical vulnerabilities in Fortinet FortiSandboxβa perimeter security product present in many enterprise environmentsβwith a 48-hour federal patch window signal urgency for any CISO running this platform.
π Read full article
Alex: Welcome to Cleartext for Friday, July 17th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Let's start here: Coca-Cola filed an 8-K yesterday because ransomware shut down every Fairlife milk production line in the United States. A Fortune 500 company, SEC disclosure, physical production halted. If you're a CISO who's been trying to get your board to fund OT segmentation, your exhibit A just arrived.
Alex: That's where we're going to start today, and we've got a packed show. We'll cover that Fairlife incident and what it means for SEC disclosure playbooks, a critical SharePoint zero-day that CISA wants patched by Sunday, Fortinet flaws on the same timeline, bulletproof hosting indictments targeting the infrastructure layer of cybercrime, Sandworm adopting ClickFix social engineering, Iran using AI to sharpen its cyber playbook, the 23andMe eighteen million dollar settlement, Scattered Spider members going to prison, and a GAO report that should concern anyone in aviation. Let's get into it.
Jordan: So the Fairlife ransomware incident. The 8-K was filed July 16th. All US milk production suspended. Canadian operations apparently unaffected. Coca-Cola says product quality and safety weren't compromised, but the operational disruption is total on the US side. This is ransomware doing what ransomware does best in 2026: it doesn't just encrypt your files, it stops your factory.
Alex: And from a governance perspective, this is the SEC materiality disclosure framework working exactly as designed. Coca-Cola had to determine that a production shutdown across an entire subsidiary's US operations was material, and they disclosed within the required window. What I want every CISO listening to take from this is: do you have your materiality determination process rehearsed for an OT event? Not an IT event, an OT event. Because the calculus is different. When production stops, materiality is almost self-evident, and the clock starts immediately.
Jordan: The other angle here is supply chain. Fairlife is a major protein shake and milk brand. Retailers are going to feel this within days. If you're in consumer packaged goods, food and beverage, manufacturing, this is your threat model. Ransomware actors know that operational downtime in physical production creates enormous pressure to pay. The leverage is the production line itself.
Alex: Use this as your board conversation on Monday. Not fear-mongering, just pointing to a peer company's SEC filing and asking: are we ready for this exact scenario?
Jordan: Let's pivot to the vulnerability side, because CISOs have a very busy weekend ahead. CISA added CVE-2026-58644 to the Known Exploited Vulnerabilities catalog yesterday. This is a critical deserialization flaw in Microsoft SharePoint Server. CVSS 9.8. Active exploitation confirmed. Federal agencies have until July 19th, which is Sunday, to patch.
Alex: SharePoint Server on-premises is still deeply embedded in a lot of large enterprises. This isn't SharePoint Online, this is the on-prem footprint that many organizations haven't fully migrated away from. If you're running it, this is a drop-everything priority. Deserialization to RCE at 9.8 with active exploitation, there's no ambiguity here.
Jordan: And on the same timeline, CISA is also ordering patches for two critical Fortinet FortiSandbox vulnerabilities, also actively exploited, also due Sunday. Fortinet perimeter devices have been a persistent target for nation-state and ransomware operators. If you're running FortiSandbox, check your versions today, not Monday.
Alex: Two critical, actively exploited vulnerability sets with a forty-eight hour patch window. That's your weekend, unfortunately.
Jordan: Now let's talk about the infrastructure layer. The DOJ unsealed indictments against three Russian nationals and their entities, Media Land and ML.Cloud, for operating bulletproof hosting that enabled cyberattacks across twenty-one US states and multiple countries. Losses attributed to the cybercrime facilitated by this infrastructure exceed sixty-two million dollars.
Alex: This is strategically significant because it targets the logistical backbone, not individual threat actors. Bulletproof hosting is the real estate of cybercrime. Ransomware operators, phishing campaigns, command and control infrastructure, they all need somewhere to live. When you take down or indict the landlords, you force displacement across the entire ecosystem.
Jordan: Right, and displacement creates signal. When threat actors have to rehost, they make mistakes, they leave traces, they sometimes fragment. But it also means there's a transition period where groups may accelerate operations before they lose infrastructure, or lash out in retaliation. CISOs should be watching their threat intelligence feeds for indicators of migration and for any uptick in activity from groups that were known customers of these hosting providers.
Alex: It's also worth noting that indictments against Russian nationals are, in practice, more about disruption and deterrence than extradition. But the intelligence value of the investigation itself is enormous, and it gives law enforcement tools to seize assets and block infrastructure.
Jordan: Let's stay in Russia's orbit. Sandworm is now using ClickFix. For those who haven't tracked this, ClickFix is a social engineering technique where a target is presented with a fake CAPTCHA that instructs them to copy and paste a PowerShell command into their machine. It originated with financially motivated criminals, and now Russia's most capable APT group is deploying it against Ukrainian targets at scale.
Alex: This is a significant development because it represents a technique that bypasses almost every technical control you've deployed. The user is the execution engine. They're literally pasting malicious code into their own terminal. Endpoint detection can catch the payload after execution, but the initial compromise relies entirely on human behavior.
Jordan: And Ars Technica covered the broader trend in a companion piece. ClickFix isn't just Sandworm now. It's proliferating across the nation-state landscape precisely because it works. The technique exploits trust in CAPTCHA flows that users encounter dozens of times a week. The defense here isn't a new tool, it's updated awareness training that specifically addresses this scenario, and it's PowerShell execution policies that constrain what a standard user can run.
Alex: If your organization hasn't added ClickFix-style scenarios to your phishing simulation program, you're behind. And revisit your PowerShell constrained language mode policies. There's no reason most end users need unrestricted PowerShell execution.
Jordan: Staying on the nation-state theme, Cybersecurity Dive reported that Iran-nexus actors, both state-linked groups and affiliated hacktivists, are actively using ChatGPT and similar frontier AI tools for malware development, phishing campaign creation, and, critically, mapping industrial control system sites.
Alex: That last point is the one that should get attention. ICS and OT reconnaissance using AI tools means these groups can move faster in identifying targets and understanding industrial environments. If you're in critical infrastructure, energy, water, manufacturing, and you have any exposure to the Middle East or are in a sector Iran has historically targeted, your threat baseline just moved up.
Jordan: The broader signal is that AI is lowering the barrier to entry and accelerating the playbook for second-tier nation-state actors. Iran doesn't have Russia or China's bench depth in cyber operations, but AI is a force multiplier that narrows that gap.
Alex: Let's shift to governance. 23andMe agreed to pay eighteen million dollars to settle claims from forty-three state attorneys general over the 2023 genetic data breach. Forty-three states coordinating on a single enforcement action. That's the story within the story.
Jordan: The underlying attack was credential stuffing. Password reuse. A foundational identity hygiene failure. And it resulted in the exposure of genetic data, which is about as sensitive as data gets. The legal theory here is straightforward: you held extraordinarily sensitive data, you didn't enforce adequate authentication controls, and now forty-three states are holding you accountable.
Alex: For CISOs, the precedent is the coordinated multistate AG action. This is becoming a standard enforcement model. If you're holding biometric data, genetic data, health data, sensitive PII at scale, your regulatory exposure isn't just federal. It's fifty potential state-level actions, and they're increasingly working together. Make sure your legal and compliance teams are modeling this.
Jordan: On the criminal enforcement side, two Scattered Spider members were sentenced to five and a half years each at Woolwich Crown Court for the 2024 Transport for London hack. Owen Flowers, eighteen, and Thalha Jubair, twenty. The attack rendered a hundred and forty-eight systems inoperable and forced all twenty-seven thousand TfL employees to reset passwords in person. Cost: twenty-nine million pounds.
Alex: The sentencing is meaningful as a deterrence signal for the social-engineering-driven cybercrime model that Scattered Spider pioneered. These are young operators who targeted enterprise helpdesks with social engineering, and they're now going to prison for more than five years. The NCA also confirmed that the arrests disrupted Scattered Spider's broader operations, which is the more operationally significant outcome.
Jordan: And finally, a GAO audit found material weaknesses in both FAA and TSA cybersecurity programs for aviation. Network security gaps, oversight strategy deficiencies. When GAO publishes findings like this, Congress typically follows with new requirements.
Alex: If you're in aviation, aerospace, or adjacent critical infrastructure, start anticipating new compliance mandates. GAO reports are leading indicators of regulatory action. Don't wait for the rule to start preparing.
Jordan: So looking at the week as a whole, what's the thread?
Alex: The thread is convergence. Nation-state techniques are converging with criminal techniques. Regulatory enforcement is converging across jurisdictions. And the attack surface is converging IT and OT in ways that create physical-world consequences. The Fairlife 8-K, the ClickFix adoption by Sandworm, the multistate AG action on 23andMe, these aren't isolated events. They're all manifestations of a threat and regulatory environment that's compressing. The distance between a phishing email and a factory shutdown, between a credential stuffing attack and a forty-three state lawsuit, that distance is shrinking.
Jordan: And next week, watch for the fallout from that SharePoint zero-day. Active exploitation plus a weekend patch deadline means Monday morning is going to reveal who was ready and who wasn't.
Alex: That's our show for today. Thanks for listening to Cleartext. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, and patch your SharePoint.
Jordan: And your Fortinet. See you Monday.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-17.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.