
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 9 stories across 6 topic areas, including: CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy; Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry; US government says Iran-linked hackers are disrupting American water and energy providers.
Cybersecurity Dive Β· Jul 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: Iranian threat actors are actively disrupting US critical infrastructureβwater and energyβby exploiting vulnerable Siemens and Schneider PLC devices, raising immediate OT/ICS security posture concerns for any enterprise with operational technology or critical infrastructure exposure.
π Read full article
The Hacker News Β· Jul 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: This is the first widely reported operational use of an autonomous AI agent for unattended post-exploitation against a national finance ministry, marking a qualitative escalation in attacker capability that CISOs must factor into threat models for AI-era incident response.
π Read full article
TechCrunch Security Β· Jul 23 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Companion coverage of the CISA/FBI Iran ICS advisory confirming active disruptionβnot just intrusionβof US water and energy systems, reinforcing the operational severity for CISOs with OT environments or critical infrastructure vendor relationships.
π Read full article
Infosecurity Magazine Β· Jul 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Survey data showing security leadership is actively blocking or delaying Microsoft Copilot rollouts due to data exposure concerns validates the CISO role as a meaningful gate on enterprise AI adoption and highlights the data governance prerequisites that must be addressed before deployment.
π Read full article
BleepingComputer Β· Jul 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Clop is now targeting internet-exposed PTC Windchill and FlexPLM instancesβenterprise PLM platforms holding sensitive product design and supply chain dataβrequiring immediate exposure audits for any manufacturing, aerospace, or defense-adjacent organization running these platforms.
π Read full article
Cybersecurity Dive Β· Jul 23 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: A GAO report formally documenting the scale of conflicting and duplicative cybersecurity reporting requirements gives CISOs ammunition for board-level and regulatory conversations about compliance cost, resource allocation, and the urgent need for harmonization.
π Read full article
BleepingComputer Β· Jul 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: CISOs at companies selling to or procuring from federal cloud vendors need to understand the FedRAMP 20X shift from periodic assessments to continuous machine-readable evidence, which will materially change vendor qualification timelines and internal compliance architectures.
π Read full article
TechCrunch Security Β· Jul 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A $36M Series A from former Google security leaders targeting AI-generated spear phishing signals that the email threat landscape has shifted enough to attract significant capital into a purpose-built AI detection category that CISOs should evaluate alongside existing SEG investments.
π Read full article
The Hacker News Β· Jul 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A zero-click, joint-advisory-backed Russian state espionage campaign exploiting Zimbra at scaleβstealing 90 days of email, directory data, browser-saved passwords, and 2FA recovery codesβdemands immediate patch verification and Zimbra inventory audits across any enterprise or partner running the platform.
π Read full article
Alex: Good morning. It's Friday, July 24th, 2026. This is Cleartext. I'm Alex Chen, alongside Jordan Reeves. We've got a packed Friday show. Iran is actively disrupting U.S. water and energy systems, not just poking around β disrupting. We'll unpack a landmark moment in AI-enabled offense: an autonomous agent running post-exploitation against a national finance ministry with no human in the loop. Clop is back with a new target set that should worry anyone in manufacturing or aerospace. We've got a GAO report that finally quantifies the regulatory mess CISOs have been complaining about for years, the FedRAMP 20X transition, Microsoft Copilot delays, a Zimbra zero-day that's still being exploited by Russian intelligence, and a startup that just raised thirty-six million dollars to tackle AI-generated phishing. Let's get into it. Jordan, take us into Iran.
Jordan: So CISA and FBI dropped a joint advisory yesterday confirming what a lot of OT security teams have feared. Iranian-linked threat actors are actively disrupting β that word matters β U.S. water and energy providers. Not pre-positioning. Not reconnaissance. Disruption. They're exploiting vulnerable Siemens and Schneider Electric PLC devices, which, as everyone listening knows, are the backbone of industrial control systems across American critical infrastructure. The advisory explicitly notes an expanding target set, meaning the scope of this campaign is growing, not contracting.
Alex: And this is the key point for CISOs. Even if you don't run a water utility or a power plant, if you have any OT exposure, if you have Schneider or Siemens PLCs anywhere in your environment, you need to be auditing your exposure right now. The expanding target set language in the advisory is a signal that these actors are moving laterally across sectors. If you're in chemicals, if you're in manufacturing, if you have building automation systems running on these platforms, you are in the blast radius.
Jordan: What I find notable is the geopolitical context. Iran has historically used cyber operations as asymmetric leverage during periods of diplomatic tension. We're seeing this campaign intensify at the same time nuclear negotiations are stalled and regional tensions are elevated. This isn't random. For board conversations, the framing should be: nation-state actors are treating U.S. critical infrastructure as a pressure lever, and the government is telling you this explicitly.
Alex: If you're a CISO briefing your board this quarter, this advisory is Exhibit A for why OT security investment isn't optional. The government is essentially saying: we know they're inside, we know they're causing harm, and we're telling you to act. That's about as clear as it gets.
Jordan: Let's pivot to something that I think is going to define the next chapter of offensive operations. A threat actor deployed the Hermes AI agent β this is an open-source agentic AI tool β on a rented server, turned off the human-approval safeguards, and pointed it at Thailand's Ministry of Finance. The agent autonomously performed host enumeration, privilege escalation, and file system hunting across treasury and tax systems. No human in the loop. No operator sitting at a keyboard approving each step.
Alex: Let's be clear about why this is a milestone. We've been talking about AI-enabled attacks for two years. Most of what we've seen has been AI-assisted β better phishing, faster vulnerability scanning, improved social engineering. This is qualitatively different. This is an autonomous agent conducting post-exploitation. It's the difference between a power tool and a robot. The attacker set the objective and walked away.
Jordan: Exactly. And the implications for incident response are significant. Your IR team is now potentially responding to an adversary that doesn't sleep, doesn't make typos, doesn't take breaks, and can iterate faster than a human operator. The dwell time calculus changes. The detection window changes. If your threat model still assumes a human at the other end of every session, it's outdated as of this week.
Alex: For CISOs, the action item is straightforward but uncomfortable. You need to war-game AI-agentic attack scenarios with your detection and response teams. How does your SOC respond when the attacker's pace of operations doubles or triples? Do your detection rules catch the behavioral patterns of an automated agent versus a human? These are questions you need answers to now, not after the first domestic incident.
Jordan: Shifting to Clop. They're back, and they're targeting PTC Windchill and FlexPLM instances exposed to the internet. For anyone not familiar, these are product lifecycle management platforms. They hold CAD files, product specifications, bill of materials data, supply chain information β the crown jewels of manufacturing and aerospace IP.
Alex: This follows Clop's established playbook. MOVEit, GoAnywhere, now PLM platforms. They find widely deployed enterprise software with internet-exposed instances, they exploit at scale, they exfiltrate data, and they extort. No encryption necessary. The pattern is predictable at this point, and yet organizations keep getting caught because they don't have accurate inventories of their internet-facing attack surface.
Jordan: If you're in manufacturing, aerospace, defense-adjacent, or retail apparel β FlexPLM is big in fashion and retail β you need an exposure audit today. Not Monday. Today. Check whether any Windchill or FlexPLM instances are reachable from the internet. If they are, pull them behind a VPN or zero-trust access layer immediately. The data in these systems is exactly what nation-states and competitors would pay for, which means the extortion leverage is enormous.
Alex: Let's talk about the Zimbra zero-day, because this one has been quietly devastating. Russian espionage group Laundry Bear β also tracked as Void Blizzard β exploited CVE-2025-66376 for five months before it was patched last November. And they're still hitting unpatched environments. This is a zero-click exploit. Opening or previewing the phishing email triggers the payload. No attachment to click, no link to follow. Just viewing the message.
Jordan: The exfiltration scope is breathtaking. Ninety days of email history, the organization's entire email directory, browser-saved passwords, and two-factor recovery codes. That last one is critical β they're not just reading your mail, they're harvesting the keys to bypass your MFA. The joint advisory backing this comes from NSA, CISA, FBI, and agencies from the Netherlands, UK, Australia, Canada, and over a dozen other countries. When you see that many flags on an advisory, you know the targeting is broad and the damage is real.
Alex: The action here is binary. If you run Zimbra anywhere in your environment or your supply chain does, verify the patch is applied. If it's not, assume compromise and scope an investigation. And honestly, if you're still running Zimbra for sensitive communications in a government or government-adjacent context, this should accelerate your migration planning.
Jordan: Now let's talk governance, because the GAO just handed CISOs a gift. They published a report formally documenting what every CISO already knows: cybersecurity reporting requirements across federal frameworks are duplicative, overlapping, and in some cases directly contradictory. You can be in compliance with one rule and in violation of another for reporting the same incident.
Alex: This is the report you print out and bring to your next board meeting. When your board asks why compliance costs keep rising, when your CFO pushes back on headcount for your GRC team, this is your evidence. The GAO β a nonpartisan congressional watchdog β is saying the system is broken. It's not just CISOs complaining. It's the government's own auditors confirming it. And the fact that some rules directly conflict creates genuine legal risk for organizations acting in good faith. That's a liability conversation your general counsel needs to be in.
Jordan: Related to this, FedRAMP is transitioning from Rev5 to 20X, which is a fundamental shift from point-in-time assessments to continuous, machine-readable evidence of security control efficacy. If you sell cloud services to the federal government or rely on FedRAMP-authorized vendors, this changes your compliance operating model. You're moving from annual audit cycles to automated evidence pipelines. That's an engineering problem, not a documentation problem.
Alex: The CISOs who get ahead of this will be the ones who start building those automated evidence capabilities now, before the deadline forces a scramble. And for enterprises consuming FedRAMP services, your third-party risk assessment process needs to account for vendor readiness for 20X. If your cloud providers can't make the transition, that's your risk.
Jordan: Quick hit on Microsoft Copilot. CoreView research confirms what we've been hearing anecdotally: security leadership is actively blocking or delaying Copilot deployments because the tool surfaces data that users shouldn't have access to. The problem isn't Copilot. The problem is that most enterprises have a decade of over-permissioned data, broken access controls, and nonexistent data classification. Copilot just makes that debt visible.
Alex: Right. And this validates something I've been saying to CISOs for a year: your AI readiness is a function of your data governance maturity. If you can't classify your data, if you can't enforce least privilege, if you don't know where your sensitive information lives, you're not ready for enterprise AI assistants. Full stop. The good news is that CISOs are being recognized as legitimate gates on AI adoption. That's real influence. Use it.
Jordan: Last one. AegisAI, founded by former Google security executives, raised thirty-six million in a Series A to build AI agents that detect AI-generated spear phishing. The pitch is contextual, behavioral analysis that catches what rule-based systems miss. The funding signals market conviction that AI-generated phishing has outpaced legacy email security.
Alex: It's a crowded space, but the pedigree is real and the problem is real. If your secure email gateway was deployed before the current generation of AI-crafted phishing, you should be evaluating supplementary detection layers. Don't rip and replace β augment.
Jordan: So, Alex, looking across this week, what's the thread?
Alex: The thread is that the tempo of offensive operations β whether it's nation-states hitting critical infrastructure, autonomous AI agents running post-exploitation, or Clop industrializing data theft β is outpacing the defensive architectures most enterprises have in place. And at the same time, the governance and regulatory environment is adding friction, not reducing it. The CISOs who are going to navigate this successfully are the ones who can simultaneously accelerate defensive modernization and make the business case for why that's a strategic investment, not a cost center.
Jordan: I'd add that we're watching the attacker toolkit undergo a generational shift. Autonomous AI agents in post-exploitation, zero-click exploits harvesting MFA recovery codes, mass exploitation of PLM platforms. The sophistication floor is rising. The barrier to entry for advanced operations is dropping. That combination compresses the time CISOs have to respond. If your security program is built for last year's threat landscape, you're already behind.
Alex: Well said. That's our show for today, Friday, July 24th. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, everyone. Stay sharp.
Jordan: See you Monday.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-24.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 9 stories across 6 topic areas, including: CISA, FBI warn that Iran-linked hackers are expanding target set for water, energy; Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry; US government says Iran-linked hackers are disrupting American water and energy providers.
Cybersecurity Dive Β· Jul 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: Iranian threat actors are actively disrupting US critical infrastructureβwater and energyβby exploiting vulnerable Siemens and Schneider PLC devices, raising immediate OT/ICS security posture concerns for any enterprise with operational technology or critical infrastructure exposure.
π Read full article
The Hacker News Β· Jul 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: This is the first widely reported operational use of an autonomous AI agent for unattended post-exploitation against a national finance ministry, marking a qualitative escalation in attacker capability that CISOs must factor into threat models for AI-era incident response.
π Read full article
TechCrunch Security Β· Jul 23 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Companion coverage of the CISA/FBI Iran ICS advisory confirming active disruptionβnot just intrusionβof US water and energy systems, reinforcing the operational severity for CISOs with OT environments or critical infrastructure vendor relationships.
π Read full article
Infosecurity Magazine Β· Jul 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Survey data showing security leadership is actively blocking or delaying Microsoft Copilot rollouts due to data exposure concerns validates the CISO role as a meaningful gate on enterprise AI adoption and highlights the data governance prerequisites that must be addressed before deployment.
π Read full article
BleepingComputer Β· Jul 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Clop is now targeting internet-exposed PTC Windchill and FlexPLM instancesβenterprise PLM platforms holding sensitive product design and supply chain dataβrequiring immediate exposure audits for any manufacturing, aerospace, or defense-adjacent organization running these platforms.
π Read full article
Cybersecurity Dive Β· Jul 23 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: A GAO report formally documenting the scale of conflicting and duplicative cybersecurity reporting requirements gives CISOs ammunition for board-level and regulatory conversations about compliance cost, resource allocation, and the urgent need for harmonization.
π Read full article
BleepingComputer Β· Jul 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: CISOs at companies selling to or procuring from federal cloud vendors need to understand the FedRAMP 20X shift from periodic assessments to continuous machine-readable evidence, which will materially change vendor qualification timelines and internal compliance architectures.
π Read full article
TechCrunch Security Β· Jul 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A $36M Series A from former Google security leaders targeting AI-generated spear phishing signals that the email threat landscape has shifted enough to attract significant capital into a purpose-built AI detection category that CISOs should evaluate alongside existing SEG investments.
π Read full article
The Hacker News Β· Jul 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A zero-click, joint-advisory-backed Russian state espionage campaign exploiting Zimbra at scaleβstealing 90 days of email, directory data, browser-saved passwords, and 2FA recovery codesβdemands immediate patch verification and Zimbra inventory audits across any enterprise or partner running the platform.
π Read full article
Alex: Good morning. It's Friday, July 24th, 2026. This is Cleartext. I'm Alex Chen, alongside Jordan Reeves. We've got a packed Friday show. Iran is actively disrupting U.S. water and energy systems, not just poking around β disrupting. We'll unpack a landmark moment in AI-enabled offense: an autonomous agent running post-exploitation against a national finance ministry with no human in the loop. Clop is back with a new target set that should worry anyone in manufacturing or aerospace. We've got a GAO report that finally quantifies the regulatory mess CISOs have been complaining about for years, the FedRAMP 20X transition, Microsoft Copilot delays, a Zimbra zero-day that's still being exploited by Russian intelligence, and a startup that just raised thirty-six million dollars to tackle AI-generated phishing. Let's get into it. Jordan, take us into Iran.
Jordan: So CISA and FBI dropped a joint advisory yesterday confirming what a lot of OT security teams have feared. Iranian-linked threat actors are actively disrupting β that word matters β U.S. water and energy providers. Not pre-positioning. Not reconnaissance. Disruption. They're exploiting vulnerable Siemens and Schneider Electric PLC devices, which, as everyone listening knows, are the backbone of industrial control systems across American critical infrastructure. The advisory explicitly notes an expanding target set, meaning the scope of this campaign is growing, not contracting.
Alex: And this is the key point for CISOs. Even if you don't run a water utility or a power plant, if you have any OT exposure, if you have Schneider or Siemens PLCs anywhere in your environment, you need to be auditing your exposure right now. The expanding target set language in the advisory is a signal that these actors are moving laterally across sectors. If you're in chemicals, if you're in manufacturing, if you have building automation systems running on these platforms, you are in the blast radius.
Jordan: What I find notable is the geopolitical context. Iran has historically used cyber operations as asymmetric leverage during periods of diplomatic tension. We're seeing this campaign intensify at the same time nuclear negotiations are stalled and regional tensions are elevated. This isn't random. For board conversations, the framing should be: nation-state actors are treating U.S. critical infrastructure as a pressure lever, and the government is telling you this explicitly.
Alex: If you're a CISO briefing your board this quarter, this advisory is Exhibit A for why OT security investment isn't optional. The government is essentially saying: we know they're inside, we know they're causing harm, and we're telling you to act. That's about as clear as it gets.
Jordan: Let's pivot to something that I think is going to define the next chapter of offensive operations. A threat actor deployed the Hermes AI agent β this is an open-source agentic AI tool β on a rented server, turned off the human-approval safeguards, and pointed it at Thailand's Ministry of Finance. The agent autonomously performed host enumeration, privilege escalation, and file system hunting across treasury and tax systems. No human in the loop. No operator sitting at a keyboard approving each step.
Alex: Let's be clear about why this is a milestone. We've been talking about AI-enabled attacks for two years. Most of what we've seen has been AI-assisted β better phishing, faster vulnerability scanning, improved social engineering. This is qualitatively different. This is an autonomous agent conducting post-exploitation. It's the difference between a power tool and a robot. The attacker set the objective and walked away.
Jordan: Exactly. And the implications for incident response are significant. Your IR team is now potentially responding to an adversary that doesn't sleep, doesn't make typos, doesn't take breaks, and can iterate faster than a human operator. The dwell time calculus changes. The detection window changes. If your threat model still assumes a human at the other end of every session, it's outdated as of this week.
Alex: For CISOs, the action item is straightforward but uncomfortable. You need to war-game AI-agentic attack scenarios with your detection and response teams. How does your SOC respond when the attacker's pace of operations doubles or triples? Do your detection rules catch the behavioral patterns of an automated agent versus a human? These are questions you need answers to now, not after the first domestic incident.
Jordan: Shifting to Clop. They're back, and they're targeting PTC Windchill and FlexPLM instances exposed to the internet. For anyone not familiar, these are product lifecycle management platforms. They hold CAD files, product specifications, bill of materials data, supply chain information β the crown jewels of manufacturing and aerospace IP.
Alex: This follows Clop's established playbook. MOVEit, GoAnywhere, now PLM platforms. They find widely deployed enterprise software with internet-exposed instances, they exploit at scale, they exfiltrate data, and they extort. No encryption necessary. The pattern is predictable at this point, and yet organizations keep getting caught because they don't have accurate inventories of their internet-facing attack surface.
Jordan: If you're in manufacturing, aerospace, defense-adjacent, or retail apparel β FlexPLM is big in fashion and retail β you need an exposure audit today. Not Monday. Today. Check whether any Windchill or FlexPLM instances are reachable from the internet. If they are, pull them behind a VPN or zero-trust access layer immediately. The data in these systems is exactly what nation-states and competitors would pay for, which means the extortion leverage is enormous.
Alex: Let's talk about the Zimbra zero-day, because this one has been quietly devastating. Russian espionage group Laundry Bear β also tracked as Void Blizzard β exploited CVE-2025-66376 for five months before it was patched last November. And they're still hitting unpatched environments. This is a zero-click exploit. Opening or previewing the phishing email triggers the payload. No attachment to click, no link to follow. Just viewing the message.
Jordan: The exfiltration scope is breathtaking. Ninety days of email history, the organization's entire email directory, browser-saved passwords, and two-factor recovery codes. That last one is critical β they're not just reading your mail, they're harvesting the keys to bypass your MFA. The joint advisory backing this comes from NSA, CISA, FBI, and agencies from the Netherlands, UK, Australia, Canada, and over a dozen other countries. When you see that many flags on an advisory, you know the targeting is broad and the damage is real.
Alex: The action here is binary. If you run Zimbra anywhere in your environment or your supply chain does, verify the patch is applied. If it's not, assume compromise and scope an investigation. And honestly, if you're still running Zimbra for sensitive communications in a government or government-adjacent context, this should accelerate your migration planning.
Jordan: Now let's talk governance, because the GAO just handed CISOs a gift. They published a report formally documenting what every CISO already knows: cybersecurity reporting requirements across federal frameworks are duplicative, overlapping, and in some cases directly contradictory. You can be in compliance with one rule and in violation of another for reporting the same incident.
Alex: This is the report you print out and bring to your next board meeting. When your board asks why compliance costs keep rising, when your CFO pushes back on headcount for your GRC team, this is your evidence. The GAO β a nonpartisan congressional watchdog β is saying the system is broken. It's not just CISOs complaining. It's the government's own auditors confirming it. And the fact that some rules directly conflict creates genuine legal risk for organizations acting in good faith. That's a liability conversation your general counsel needs to be in.
Jordan: Related to this, FedRAMP is transitioning from Rev5 to 20X, which is a fundamental shift from point-in-time assessments to continuous, machine-readable evidence of security control efficacy. If you sell cloud services to the federal government or rely on FedRAMP-authorized vendors, this changes your compliance operating model. You're moving from annual audit cycles to automated evidence pipelines. That's an engineering problem, not a documentation problem.
Alex: The CISOs who get ahead of this will be the ones who start building those automated evidence capabilities now, before the deadline forces a scramble. And for enterprises consuming FedRAMP services, your third-party risk assessment process needs to account for vendor readiness for 20X. If your cloud providers can't make the transition, that's your risk.
Jordan: Quick hit on Microsoft Copilot. CoreView research confirms what we've been hearing anecdotally: security leadership is actively blocking or delaying Copilot deployments because the tool surfaces data that users shouldn't have access to. The problem isn't Copilot. The problem is that most enterprises have a decade of over-permissioned data, broken access controls, and nonexistent data classification. Copilot just makes that debt visible.
Alex: Right. And this validates something I've been saying to CISOs for a year: your AI readiness is a function of your data governance maturity. If you can't classify your data, if you can't enforce least privilege, if you don't know where your sensitive information lives, you're not ready for enterprise AI assistants. Full stop. The good news is that CISOs are being recognized as legitimate gates on AI adoption. That's real influence. Use it.
Jordan: Last one. AegisAI, founded by former Google security executives, raised thirty-six million in a Series A to build AI agents that detect AI-generated spear phishing. The pitch is contextual, behavioral analysis that catches what rule-based systems miss. The funding signals market conviction that AI-generated phishing has outpaced legacy email security.
Alex: It's a crowded space, but the pedigree is real and the problem is real. If your secure email gateway was deployed before the current generation of AI-crafted phishing, you should be evaluating supplementary detection layers. Don't rip and replace β augment.
Jordan: So, Alex, looking across this week, what's the thread?
Alex: The thread is that the tempo of offensive operations β whether it's nation-states hitting critical infrastructure, autonomous AI agents running post-exploitation, or Clop industrializing data theft β is outpacing the defensive architectures most enterprises have in place. And at the same time, the governance and regulatory environment is adding friction, not reducing it. The CISOs who are going to navigate this successfully are the ones who can simultaneously accelerate defensive modernization and make the business case for why that's a strategic investment, not a cost center.
Jordan: I'd add that we're watching the attacker toolkit undergo a generational shift. Autonomous AI agents in post-exploitation, zero-click exploits harvesting MFA recovery codes, mass exploitation of PLM platforms. The sophistication floor is rising. The barrier to entry for advanced operations is dropping. That combination compresses the time CISOs have to respond. If your security program is built for last year's threat landscape, you're already behind.
Alex: Well said. That's our show for today, Friday, July 24th. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, everyone. Stay sharp.
Jordan: See you Monday.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-24.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.