Cleartext

Cleartext – June 19, 2026


Listen Later

Cleartext – June 19, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: Authorities disrupt Evil Corp’s SocGholish botnet; DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic; INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023.

Stories Covered
🌍 Geopolitical
Authorities disrupt Evil Corp’s SocGholish botnet

CyberScoop · Jun 18 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The multinational takedown of Evil Corp's SocGholish infrastructure—106 servers seized and 15,000 infected sites remediated—represents a significant disruption to a ransomware-delivery network that has been an initial access vector for major enterprise breaches; CISOs should use this moment to verify that their web proxies and endpoint controls would have blocked SocGholish drive-by downloads.

  • International law enforcement seized 106 servers and cleaned nearly 15,000 SocGholish-infected WordPress sites linked to Russian cybercrime group Evil Corp
  • SocGholish has served as a primary initial access mechanism for multiple ransomware operations targeting enterprises
  • Operation conducted under 'Operation Endgame' framework with coordination across multiple countries and private security firms
  • 📖 Read full article

    DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

    The Hacker News · Jun 18 · Relevance: ████████░░ 8/10

    Why it matters to CISOs: DragonForce's technique of routing ransomware C2 traffic through legitimate Microsoft Teams relay infrastructure directly defeats network-based detection that relies on blocklists or anomaly thresholds against known-bad infrastructure—CISOs must validate whether their NDR and SIEM rules can detect behavioral anomalies in Teams traffic rather than relying on domain or IP reputation.

    • DragonForce ransomware actors deployed a custom Go-based RAT called Backdoor.Turn that conceals C2 communications inside Microsoft Teams relay infrastructure
    • A major U.S. services firm was confirmed as a victim in research published by Symantec and Carbon Black
    • The technique bypasses conventional C2 detection by blending malicious traffic with legitimate enterprise collaboration platform traffic
    • 📖 Read full article

      📡 Macro Trends
      INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023

      The Hacker News · Jun 18 · Relevance: ███████░░░ 7/10

      Why it matters to CISOs: INC ransomware has quietly absorbed affiliates displaced by the LockBit and BlackCat takedowns and now ranks among the most prolific RaaS operations—CISOs updating their threat models and cyber insurance submissions should incorporate INC's growing TTPs and sector targeting patterns.

      • INC ransomware-as-a-service has claimed 830+ victims since August 2023, with accelerated growth in 2026 following LockBit and BlackCat disruptions
      • Affiliate migration from disrupted groups has fueled INC's rapid expansion across sectors
      • Research published by Acronis documents INC's evolution from nascent operation to top-tier RaaS threat
      • 📖 Read full article

        🔓 Data Breach
        Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks

        BleepingComputer · Jun 18 · Relevance: █████████░ 9/10

        Why it matters to CISOs: The Klue-Salesforce-Huntress breach chain is a textbook third-party OAuth integration attack that cascaded into CRM data theft across multiple enterprises—including a cybersecurity vendor—illustrating systemic risk in how organizations grant persistent OAuth access to SaaS integrations. CISOs should immediately audit all third-party OAuth and connected-app permissions within Salesforce and similar CRM platforms.

        • Threat actor 'Icarus' exploited compromised OAuth credentials in the Klue Battlecards integration to steal Salesforce CRM data from multiple organizations
        • Salesforce disabled the Klue app integration entirely; this is reportedly the third Salesforce-connected app compromised in an ongoing extortion campaign
        • Cybersecurity vendor Huntress confirmed it was among the victims, publishing a detailed post-mortem describing a 'security domino effect' from one compromised integration credential
        • 📖 Read full article

          Novo Nordisk Breach Exposes Software Development Pipeline Risk

          Dark Reading · Jun 18 · Relevance: ███████░░░ 7/10

          Why it matters to CISOs: A leaked GitHub token at a global pharmaceutical leader highlights that secrets management in CI/CD pipelines remains a critical governance gap—CISOs at organizations with active software development operations should benchmark their secrets scanning posture and ensure developer credentials are treated as privileged identities, not tooling artifacts.

          • Novo Nordisk suffered a breach originating from a leaked GitHub token that exposed its software development pipeline
          • The incident underscores the framing of secrets as an identity and access management problem rather than a developer tooling problem
          • Pharmaceutical and life sciences sector continues to be a high-value target for attackers leveraging developer pipeline access
          • 📖 Read full article

            Texas government data breach allowed hackers to steal 3 million driver’s licenses and passports

            TechCrunch Security · Jun 18 · Relevance: ███████░░░ 7/10

            Why it matters to CISOs: The theft of 3 million government-issued identity documents from a Texas state system is a high-severity identity data breach with downstream fraud implications for enterprise identity verification programs and HR onboarding processes that rely on driver's licenses and passports as identity proofing documents.

            • Hackers stole over 3 million driver's licenses and passport records from a Texas government system
            • The breach affects government-issued identity documents with high fraud-enablement potential
            • Incident highlights persistent vulnerabilities in state and local government data custodianship of sensitive identity records
            • 📖 Read full article

              🚀 Startup Ecosystem
              Accenture to buy Dragos, runZero, and NetRise in $4.2 billion cybersecurity deal

              Help Net Security · Jun 19 · Relevance: █████████░ 9/10

              Why it matters to CISOs: The $4.2B deal consolidates three leading OT/ICS security and asset-visibility platforms under a global consulting giant, reshaping the vendor landscape for critical infrastructure security programs and signaling that OT risk has reached boardroom-level investment priority. CISOs at industrial, energy, and manufacturing enterprises need to reassess their Dragos, runZero, and NetRise roadmaps under new ownership.

              • Accenture is acquiring a majority stake in Dragos plus full ownership of runZero and NetRise for approximately $4.18–4.2 billion
              • The deal targets end-to-end OT security across power grids, pipelines, manufacturing, and data centers
              • Move is Accenture's first major push into operational technology software as AI-driven threats to critical infrastructure intensify
              • 📖 Read full article

                🚨 Critical Vulnerability
                CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices

                The Hacker News · Jun 19 · Relevance: ██████████ 10/10

                Why it matters to CISOs: Active Russian-attributed campaign compromising tens of thousands of FortiGate firewalls and VPN devices demands immediate inventory audit and credential rotation across any enterprise running Fortinet edge infrastructure. The scale—86,000+ devices—and CISA's formal warning make this an executive-level emergency requiring board communication.

                • 86,644 FortiGate devices compromised in a campaign codenamed FortiBleed, attributed to Russian-speaking threat actors
                • CISA issued an urgent advisory directing Fortinet customers to take immediate hardening steps
                • Companion story (index 50) confirms ~74,000 VPN credentials exposed in the associated data leak
                • 📖 Read full article

                  Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)

                  Help Net Security · Jun 19 · Relevance: █████████░ 9/10

                  Why it matters to CISOs: Splunk Enterprise is a critical detection and logging backbone for most enterprise SOCs; an unauthenticated RCE being actively exploited with a federal patch deadline of June 21 means any organization running Splunk must treat this as an emergency patch-or-isolate decision this weekend. Full system compromise potential directly undermines an organization's ability to detect other incidents.

                  • CVE-2026-20253 is a critical unauthenticated RCE in Splunk Enterprise, added to CISA's Known Exploited Vulnerabilities catalog
                  • US federal civilian agencies ordered to apply mitigations by June 21, 2026 (Sunday)
                  • Vendor and Resecurity have both confirmed in-the-wild exploitation; indicators include path traversal sequences and anomalous PostgreSQL connections
                  • 📖 Read full article

                    Further Reading
                    • 🌍 Authorities disrupt Evil Corp’s SocGholish botnetCyberScoop
                    • 🌍 DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 TrafficThe Hacker News
                    • 📡 INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023The Hacker News
                    • 🔓 Klue OAuth breach linked to 'Icarus' Salesforce data theft attacksBleepingComputer
                    • 🔓 Novo Nordisk Breach Exposes Software Development Pipeline RiskDark Reading
                    • 🔓 Texas government data breach allowed hackers to steal 3 million driver’s licenses and passportsTechCrunch Security
                    • 🚀 Accenture to buy Dragos, runZero, and NetRise in $4.2 billion cybersecurity dealHelp Net Security
                    • 🚨 CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate DevicesThe Hacker News
                    • 🚨 Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)Help Net Security
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext. It's Friday, June 19th, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves. Let's get into it.

                      Alex: We have a packed show today. Two critical vulnerabilities that need weekend action, a massive acquisition that reshapes the OT security landscape, a sophisticated supply chain breach that should make every CISO audit their OAuth integrations before Monday, and some meaningful law enforcement wins against the ransomware ecosystem. Let's start where the pain is most immediate.

                      Jordan: Yeah, let's talk about FortiBleed, because eighty-six thousand compromised FortiGate devices is not a drill. CISA put out a formal advisory yesterday directing Fortinet customers to take immediate hardening steps. The campaign is attributed to Russian-speaking threat actors, and there's a companion data leak of roughly seventy-four thousand VPN credentials floating around. If you're running Fortinet edge infrastructure, this is your weekend.

                      Alex: And what makes this board-level rather than just a SOC problem is the scale and the credential exposure. We're not talking about a theoretical vulnerability waiting to be exploited. These devices are already compromised. The credential dump means even if you patch the underlying issue, you've got a rotation problem. Every service account, every VPN credential that touched those appliances needs to be treated as burned.

                      Jordan: The attribution to Russian-speaking actors is worth noting but shouldn't change your response calculus. Whether it's state-sponsored or criminal, the remediation is the same: inventory every FortiGate device in your environment, validate firmware versions, rotate credentials, and check for persistence mechanisms. If you're a CISO and you don't have a complete inventory of your Fortinet footprint by end of day today, that's your first problem.

                      Alex: And the second emergency is arguably worse in a different way. CVE-2026-20253, an unauthenticated remote code execution vulnerability in Splunk Enterprise, is under active exploitation right now. CISA has given federal agencies until Sunday to apply mitigations. Sunday.

                      Jordan: This one is genuinely alarming because of what Splunk is. It's the detection backbone for most enterprise SOCs. If an attacker compromises your Splunk infrastructure, they don't just own a server. They own your visibility. They can manipulate logs, suppress alerts, blind your detection pipeline. It's the equivalent of someone taking out the security cameras and the alarm system simultaneously.

                      Alex: The indicators include path traversal sequences and anomalous PostgreSQL connections, so there are things your teams can hunt for right now. But the patch-or-isolate decision needs to happen today. If you can't patch by Sunday, isolate the instance from the internet and restrict access to trusted networks only. This is not a Monday morning conversation.

                      Jordan: And for the CISOs listening who are thinking about how to communicate this upward, frame it simply: our ability to detect attacks is itself under attack. That lands in the boardroom.

                      Alex: Let's pivot to a story that I think is going to have ripple effects across enterprise security programs for months. The Klue OAuth breach. A threat actor called Icarus exploited compromised OAuth credentials in Klue's Battlecards integration to steal Salesforce CRM data from multiple organizations. And this is reportedly the third Salesforce-connected app compromised in an ongoing extortion campaign.

                      Jordan: What makes this story so instructive is the cascade. One compromised OAuth credential in a third-party integration turned into CRM data theft across multiple enterprises. And one of the victims was Huntress, a cybersecurity vendor, who to their credit published a detailed post-mortem describing what they called a security domino effect. Salesforce has now disabled the Klue integration entirely.

                      Alex: This is a systemic architectural problem. Most enterprises have dozens, sometimes hundreds of third-party OAuth integrations into Salesforce, HubSpot, ServiceNow, you name it. Each one of those is a persistent access grant that rarely gets audited after initial approval. The Klue breach proves that your SaaS supply chain is only as strong as the weakest connected app.

                      Jordan: And the fact that this is the third Salesforce-connected app hit in this campaign tells you Icarus has a playbook. They're systematically targeting the integration layer. If I'm a CISO, I'm pulling a report of every OAuth grant and connected app in my Salesforce instance before the weekend. Look for apps with broad data access scopes, apps that haven't been used recently, apps from vendors you've never heard of. Revoke first, ask questions later.

                      Alex: The Novo Nordisk story reinforces the same theme from a different angle. A leaked GitHub token exposed their software development pipeline. Dark Reading framed it correctly: secrets management is an identity and access management problem, not a developer tooling problem. If your organization treats developer credentials as anything less than privileged identities, you have a governance gap.

                      Jordan: Now let's talk about a story that broke this morning that's going to reshape vendor strategy conversations for a lot of CISOs. Accenture announced it's acquiring a majority stake in Dragos plus full ownership of runZero and NetRise for four point two billion dollars.

                      Alex: This is significant on multiple levels. First, the dollar figure. Four point two billion for OT security and asset visibility platforms signals that operational technology risk has definitively reached boardroom investment priority. This isn't a niche anymore. Second, it consolidates three of the leading platforms in OT security, asset discovery, and firmware and software supply chain analysis under one consulting giant.

                      Jordan: For CISOs at industrial, energy, and manufacturing enterprises who are currently Dragos, runZero, or NetRise customers, you need to start thinking about what this means for your roadmaps. Accenture is a services company. Their incentive structure is to wrap these tools in managed services and consulting engagements. That could be great if you want a turnkey solution. It could be problematic if you've built custom integrations and want to maintain operational independence.

                      Alex: And the competitive dynamics shift too. Accenture just became a major OT security platform company overnight. That changes the conversation with Claroty, Nozomi, Armis, and every other player in the space. If you're in an active procurement cycle for OT visibility or ICS security, pause and reassess the landscape.

                      Jordan: My take is that this is a net positive signal for the market. It validates that OT security is a strategic priority, not a compliance checkbox. But the execution risk of integrating three distinct engineering cultures under Accenture is real. I'd watch the next two quarters closely before making any long-term bets on the combined platform.

                      Alex: Let's shift to the law enforcement side, which had a genuinely good week. Operation Endgame's takedown of Evil Corp's SocGholish botnet. A hundred and six servers seized, nearly fifteen thousand infected WordPress sites remediated.

                      Jordan: SocGholish has been one of the most effective initial access mechanisms in the ransomware ecosystem for years. It's a drive-by download operation. You visit a compromised website, you get a fake browser update prompt, and if someone clicks it, the malware deploys and phones home for the next stage, which is typically ransomware or a hands-on-keyboard intrusion. The infrastructure takedown is meaningful because SocGholish depended on a large distributed network of compromised WordPress sites. Cleaning fifteen thousand of those disrupts the delivery mechanism significantly.

                      Alex: For CISOs, the actionable takeaway is to use this moment to validate your controls. Would your web proxies and endpoint detection have blocked a SocGholish drive-by download? The answer should be yes, but verify. Run the known indicators through your detection stack. And if you've got users on unmanaged devices accessing the web without proxy coverage, that's your gap.

                      Jordan: The SocGholish takedown also connects to our third story about INC ransomware absorbing affiliates displaced by the LockBit and BlackCat disruptions. The ransomware ecosystem is remarkably resilient. You take out one operation, the talent migrates. INC has now claimed over eight hundred thirty victims since 2023, with accelerated growth this year specifically because it absorbed operators from disrupted groups.

                      Alex: If you're updating threat models or cyber insurance submissions, INC needs to be in your analysis. They've moved from a nascent operation to a top-tier RaaS threat, and their affiliate base now includes experienced operators who cut their teeth on LockBit and BlackCat campaigns. These are not amateurs.

                      Jordan: And the DragonForce story adds another layer of sophistication to the ransomware landscape. They're routing C2 traffic through legitimate Microsoft Teams relay infrastructure using a custom Go-based RAT called Backdoor.Turn. This is clever because it defeats network-based detection that relies on domain reputation or IP blocklists. The traffic looks like normal Teams usage.

                      Alex: This is a fundamental challenge for network detection and response. If your NDR strategy is primarily reputation-based, you will miss this. You need behavioral analytics that can identify anomalous patterns within legitimate platform traffic. And honestly, most organizations aren't there yet. This is a gap that needs investment.

                      Jordan: Briefly on the Texas breach, three million driver's licenses and passport records stolen from a state government system. The downstream implications for enterprise are real. If your organization uses driver's licenses or passports for identity proofing during onboarding or account recovery, those documents are now less trustworthy for three million people. Identity verification programs need to account for this.

                      Alex: Alright, looking at the week as a whole, Jordan, what's the thread you see?

                      Jordan: The theme is trust boundaries collapsing. FortiBleed compromises the network edge. Splunk exploitation compromises detection. The Klue breach compromises SaaS integrations. DragonForce compromises the legitimacy of collaboration platform traffic. Every layer of assumed trust in our security architectures is being tested simultaneously. The organizations that will fare best are the ones that have moved past implicit trust at any layer and are actively validating at every boundary.

                      Alex: I agree. And I'd add that the Accenture acquisition signals that the market is starting to price in the reality that operational technology and the physical world are now part of the same threat surface. The convergence of IT and OT security isn't a future state. It's the current state. CISOs who are still treating these as separate programs are behind.

                      Jordan: Next week, watch for exploitation activity around the Splunk vulnerability to intensify. The Sunday patch deadline for federal agencies means there will be a window of opportunity for attackers against organizations that don't move as fast. And keep an eye on the Icarus campaign. Three Salesforce-connected apps compromised suggests there will be a fourth.

                      Alex: That's our show for today. Show notes, links to every story we covered, and additional context are all at cleartext.fm. Have a good weekend, everyone, but maybe not too relaxed a weekend given what's on the board. We'll be back Monday.

                      Jordan: Patch your Splunk. Rotate your Fortinet credentials. Audit your OAuth grants. Then enjoy your weekend. See you Monday.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-19.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext