
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 9 stories across 5 topic areas, including: Intel agencies: Frontier AI models will reshape cybersecurity faster than expected; Microsoft Attributes Mastra AI Supply Chain Attack to North Korea; Suspected cyberattack triggers false emergency alerts across parts of Brazil.
CyberScoop Β· Jun 22 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A Five Eyes joint warning signals that AI-enabled offensive capabilities are arriving on a compressed timeline, requiring CISOs to accelerate defensive AI investments and threat model updates now rather than in multi-year planning cycles.
π Read full article
Infosecurity Magazine Β· Jun 22 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: North Korean state actor Sapphire Sleet targeting a widely-used AI framework signals that AI development toolchains are now high-priority nation-state targets, forcing CISOs to extend supply chain security controls to AI/ML infrastructure.
π Read full article
The Record (Recorded Future) Β· Jun 22 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: The compromise of Brazil's national emergency alert infrastructure to broadcast false warnings demonstrates that critical public-warning systems are viable targets for disruption operations, a template CISOs supporting government or critical infrastructure clients must account for.
π Read full article
BankInfoSecurity Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: U.S. government restrictions on Anthropic's most advanced models directly affect enterprise security teams evaluating or deploying frontier AI for defensive use cases, forcing strategic reconsideration of AI vendor selection and deployment architectures.
π Read full article
BankInfoSecurity Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: New CISO research quantifying organizations' inability to track AI agent data access confirms that identity and access management frameworks designed for human actors create dangerous blind spots when AI agents inherit enterprise permissions at machine speed.
π Read full article
TechCrunch Security Β· Jun 22 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: A breach at market research platform Klue propagated through OAuth/Salesforce integrations to compromise data at multiple major security vendors, illustrating how SaaS supply chain trust relationships create systemic third-party risk even within the security industry itself.
π Read full article
Infosecurity Magazine Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The Gentlemen ransomware gang distributing a purpose-built EDR-killer framework to affiliates as a service raises the baseline capability of ransomware operators and directly challenges EDR as a last line of defense in enterprise environments.
π Read full article
The Hacker News Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Canada's CSIS obtaining judicial authority to remotely remediate privately-owned infected devices sets a legal precedent for government-mandated active cyber defense on enterprise infrastructure, with significant implications for corporate network sovereignty and incident response obligations.
π Read full article
Cybersecurity Dive Β· Jun 22 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A months-long campaign (FortiBleed) actively harvesting Fortinet credentials at scale across western enterprises requires immediate verification of device hardening posture and credential rotation for any internet-facing Fortinet infrastructure.
π Read full article
Jordan: Five Eyes just told every CISO on the planet that AI-enabled offensive capabilities aren't a planning-cycle problem β they're a this-quarter problem. Meanwhile, North Korea is poisoning AI development frameworks, Brazil's emergency alert system got hijacked, and a breach at a market research platform cascaded through OAuth tokens into Huntress, HackerOne, Recorded Future, and half a dozen other security vendors. It's Monday, June 22nd. Let's get into it.
Alex: Welcome to Cleartext. I'm Alex Chen, alongside Jordan Reeves. We've got a dense show today. We're going to spend real time on that Five Eyes warning because it changes planning assumptions. We'll connect it to the Anthropic export restrictions and the AI permissions blind spot that's widening across enterprises. Then we'll hit the North Korea supply chain attack on Mastra, the Klue breach that embarrassed our own industry, a new EDR-killer framework going affiliate, a Canadian legal precedent for government-mandated remediation on private infrastructure, and a Fortinet credential harvesting campaign that CISA wants you acting on right now. Jordan, take us into the Five Eyes piece.
Jordan: So all five agencies β NSA, GCHQ, CSE, ASD, GCSB β put their names on a joint assessment that frontier AI models capable of meaningfully augmenting offensive cyber operations are months away, not years. That's the headline. But the real story is the subtext. Intelligence agencies issue joint warnings when they want to create political cover for accelerated spending and policy. This is a signal to governments and to the private sector that the threat model is compressing.
Alex: And the timing matters. This validates what researchers at Anthropic, DeepMind, and several academic labs have been publishing over the last twelve months. But there's a difference between a research paper and a Five Eyes joint advisory. The advisory is what your board will read. It's what your general counsel will forward you. If you haven't updated your threat models to account for AI-augmented reconnaissance, AI-generated exploit chains, and AI-assisted social engineering operating at scale, you're behind. Not behind the curve β behind the threat.
Jordan: I want to be specific about what "months away" means operationally. We're not talking about AGI writing zero-days from scratch. We're talking about models that can take a known vulnerability, generate working exploit code, adapt it to a target environment, and do that across thousands of targets simultaneously. The economics of offense just changed. The marginal cost of a sophisticated attack drops toward zero.
Alex: Which brings us directly to the Anthropic restriction story. The U.S. government has imposed export-style restrictions on Anthropic's most advanced models. The cybersecurity industry is pushing back hard, and the argument is straightforward β you're handicapping defenders while attackers have no such constraints. Adversaries aren't waiting for an export license.
Jordan: The policy tension here is real. There are legitimate national security reasons to control frontier model proliferation. But the practical effect for CISOs is that your AI vendor strategy just got geopolitical risk layered on top of it. If you've been building defensive workflows around a specific frontier model β automated threat hunting, code review, incident response augmentation β you need to scenario-plan for access disruption. What happens if the model you depend on gets restricted, versioned down, or pulled from your region?
Alex: This is a procurement and architecture conversation now, not just a policy debate. Dual-vendor strategies for AI, just like you'd have for cloud. And it connects to the smaller models discussion that's gaining traction. There are CISOs making the argument that fine-tuned, domain-specific smaller models running on-premise give you capability without the geopolitical supply chain risk.
Jordan: Agreed. And while we're on AI risk β the BankInfoSecurity piece on AI agent permissions is one of those stories that sounds academic until you realize it describes your environment right now. The research shows that most organizations cannot track what data their AI agents are accessing. The agents inherit user permissions. They operate at machine speed. They don't hesitate, they don't apply judgment, they don't think "maybe I shouldn't open that file." Your IAM framework was designed for humans. It assumes a human is on the other end of that session.
Alex: This is the identity governance gap I've been talking about for six months. Every CISO I know has deployed or is deploying AI agents somewhere in their environment. How many of them have implemented agent-specific access controls? How many can audit what those agents touched last Tuesday? The answer, based on this research, is almost none. You need a dedicated workstream for AI agent identity governance. Treat agents as a distinct principal type. Instrument them. Constrain them. Audit them. If you can't do that today, you need to be honest with your board about what you don't know.
Jordan: Let's pivot to the North Korea story because it puts a point on all of this. Microsoft attributed a supply chain attack on the Mastra AI framework to Sapphire Sleet. For anyone unfamiliar, Mastra is an open-source AI agent framework that a lot of development teams use to build AI-powered applications. Sapphire Sleet compromised the supply chain β meaning anyone pulling Mastra dependencies could have been pulling poisoned code.
Alex: This is the convergence story. Nation-states are now targeting AI development toolchains specifically. Not just traditional software supply chains β AI supply chains. The libraries, the frameworks, the model registries, the training pipelines. If your engineering teams are building AI capabilities, which they are, their development dependencies are now a tier-one attack surface.
Jordan: And Sapphire Sleet is not a smash-and-grab crew. They do financial theft and espionage. They're strategic. Compromising an AI framework gives you access to every organization that uses it. It's a force multiplier. CISOs need to be having explicit conversations with their engineering leadership about AI dependency management. Software composition analysis tools need to cover AI-specific supply chains. If they don't today, that's a gap.
Alex: Moving to the Klue breach, and this one stings because it hit our own industry. Huntress, HackerOne, Jamf, Recorded Future, Tanium β these are security companies. Klue is a competitive intelligence platform. The attackers compromised Klue, obtained OAuth tokens through a Salesforce integration, and used those tokens to pivot into downstream customer environments.
Jordan: OAuth token abuse through SaaS integrations. It's not new, but the scale and the victim list here make it a case study. Every one of those security vendors had a trust relationship with Klue. That trust relationship was a lateral movement path. The attackers didn't need to breach Huntress directly. They breezed through the integration.
Alex: The lesson for every CISO: your SaaS integration map is your blast radius map. When did you last audit every OAuth grant, every API token, every third-party integration touching your Salesforce instance, your identity provider, your CRM? Most organizations can't even enumerate them. That's the problem. You can't revoke what you can't see.
Jordan: Let's talk about the GentleKiller framework. ESET published details on a purpose-built EDR-killing tool distributed by the Gentlemen ransomware gang to their affiliates as a service. This is EDR bypass as a commodity.
Alex: This is the natural evolution. We've seen EDR killers before β Terminator, AuKill, various BYOVD techniques. The difference here is the productization. It's packaged, maintained, and distributed to affiliates who may not have the sophistication to build it themselves. It raises the floor for every ransomware operator in that ecosystem.
Jordan: If your defensive strategy terminates at the EDR agent, you have a single point of failure that now has a purpose-built tool designed to remove it. Defense in depth isn't a platitude here β it's operational necessity. Application allowlisting, network segmentation, behavioral analytics that don't depend on the endpoint agent being alive.
Alex: The Brazil emergency alert story is worth flagging because it's a template. Attackers compromised the national Civil Defense Alert system and pushed at least a dozen false emergency warnings to citizens. Floods, landslides β the kind of alerts people act on immediately.
Jordan: This is a trust destruction operation. The damage isn't in the false alerts themselves β it's that next time there's a real flood warning, people hesitate. If you're a CISO supporting government infrastructure, critical infrastructure, or any organization that operates public-facing alert or notification systems, this is your threat scenario. Authenticate your broadcast channels. Verify the integrity of your alerting pipeline end to end.
Alex: The Canada story is a legal precedent worth tracking. CSIS β Canada's intelligence service β obtained a judicial warrant to remotely access and remediate privately owned devices that were part of foreign-run botnets. Home routers, IoT devices, servers β on Canadian soil, belonging to private parties.
Jordan: First time they've used threat reduction warrant powers this way. The ruling was made public June 15th. This matters because it establishes that a government intelligence agency can, with judicial authorization, reach into your infrastructure and alter it to neutralize a threat. Whether you view that as a necessary national defense measure or a sovereignty concern depends on your perspective. But CISOs need to understand the legal landscape is shifting. Governments are asserting authority to act on private networks.
Alex: If your devices are compromised and you haven't remediated them, someone else might. That's the new reality.
Jordan: Last item β CISA issued an urgent advisory on Fortinet credential compromise. The FortiBleed campaign has been running for months, targeting western organizations. Thousands of credentials confirmed compromised. This is active, ongoing exploitation.
Alex: If you have internet-facing Fortinet infrastructure, this is a stop-what-you're-doing item. Verify device hardening against CISA's advisory. Rotate credentials. Check for indicators of compromise. Assume breach if you haven't patched and hardened. This isn't theoretical β thousands of organizations are already compromised.
Jordan: The theme this week, Alex β it's compression. Time compression on AI threats. Trust compression across SaaS supply chains. Capability compression as commodity tools close the gap between sophisticated and unsophisticated attackers.
Alex: That's exactly right. The planning assumptions from twelve months ago are obsolete. The Five Eyes warning isn't about 2028. The Mastra supply chain attack isn't about future AI risks. The GentleKiller framework isn't about theoretical EDR bypass. All of it is happening now, and the organizations that are still in annual planning cycles for these threats are operating on a timeline that no longer exists.
Jordan: Watch this week for follow-on analysis from the Five Eyes advisory β particularly any technical annexes that drop. Watch for Klue breach notifications propagating through vendor risk management channels. And if you're running Fortinet, you know what to do.
Alex: That's our show for Monday, June 22nd. Show notes, links to every story we covered, and additional context are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. See you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-22.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 9 stories across 5 topic areas, including: Intel agencies: Frontier AI models will reshape cybersecurity faster than expected; Microsoft Attributes Mastra AI Supply Chain Attack to North Korea; Suspected cyberattack triggers false emergency alerts across parts of Brazil.
CyberScoop Β· Jun 22 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A Five Eyes joint warning signals that AI-enabled offensive capabilities are arriving on a compressed timeline, requiring CISOs to accelerate defensive AI investments and threat model updates now rather than in multi-year planning cycles.
π Read full article
Infosecurity Magazine Β· Jun 22 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: North Korean state actor Sapphire Sleet targeting a widely-used AI framework signals that AI development toolchains are now high-priority nation-state targets, forcing CISOs to extend supply chain security controls to AI/ML infrastructure.
π Read full article
The Record (Recorded Future) Β· Jun 22 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: The compromise of Brazil's national emergency alert infrastructure to broadcast false warnings demonstrates that critical public-warning systems are viable targets for disruption operations, a template CISOs supporting government or critical infrastructure clients must account for.
π Read full article
BankInfoSecurity Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: U.S. government restrictions on Anthropic's most advanced models directly affect enterprise security teams evaluating or deploying frontier AI for defensive use cases, forcing strategic reconsideration of AI vendor selection and deployment architectures.
π Read full article
BankInfoSecurity Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: New CISO research quantifying organizations' inability to track AI agent data access confirms that identity and access management frameworks designed for human actors create dangerous blind spots when AI agents inherit enterprise permissions at machine speed.
π Read full article
TechCrunch Security Β· Jun 22 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: A breach at market research platform Klue propagated through OAuth/Salesforce integrations to compromise data at multiple major security vendors, illustrating how SaaS supply chain trust relationships create systemic third-party risk even within the security industry itself.
π Read full article
Infosecurity Magazine Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The Gentlemen ransomware gang distributing a purpose-built EDR-killer framework to affiliates as a service raises the baseline capability of ransomware operators and directly challenges EDR as a last line of defense in enterprise environments.
π Read full article
The Hacker News Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Canada's CSIS obtaining judicial authority to remotely remediate privately-owned infected devices sets a legal precedent for government-mandated active cyber defense on enterprise infrastructure, with significant implications for corporate network sovereignty and incident response obligations.
π Read full article
Cybersecurity Dive Β· Jun 22 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: A months-long campaign (FortiBleed) actively harvesting Fortinet credentials at scale across western enterprises requires immediate verification of device hardening posture and credential rotation for any internet-facing Fortinet infrastructure.
π Read full article
Jordan: Five Eyes just told every CISO on the planet that AI-enabled offensive capabilities aren't a planning-cycle problem β they're a this-quarter problem. Meanwhile, North Korea is poisoning AI development frameworks, Brazil's emergency alert system got hijacked, and a breach at a market research platform cascaded through OAuth tokens into Huntress, HackerOne, Recorded Future, and half a dozen other security vendors. It's Monday, June 22nd. Let's get into it.
Alex: Welcome to Cleartext. I'm Alex Chen, alongside Jordan Reeves. We've got a dense show today. We're going to spend real time on that Five Eyes warning because it changes planning assumptions. We'll connect it to the Anthropic export restrictions and the AI permissions blind spot that's widening across enterprises. Then we'll hit the North Korea supply chain attack on Mastra, the Klue breach that embarrassed our own industry, a new EDR-killer framework going affiliate, a Canadian legal precedent for government-mandated remediation on private infrastructure, and a Fortinet credential harvesting campaign that CISA wants you acting on right now. Jordan, take us into the Five Eyes piece.
Jordan: So all five agencies β NSA, GCHQ, CSE, ASD, GCSB β put their names on a joint assessment that frontier AI models capable of meaningfully augmenting offensive cyber operations are months away, not years. That's the headline. But the real story is the subtext. Intelligence agencies issue joint warnings when they want to create political cover for accelerated spending and policy. This is a signal to governments and to the private sector that the threat model is compressing.
Alex: And the timing matters. This validates what researchers at Anthropic, DeepMind, and several academic labs have been publishing over the last twelve months. But there's a difference between a research paper and a Five Eyes joint advisory. The advisory is what your board will read. It's what your general counsel will forward you. If you haven't updated your threat models to account for AI-augmented reconnaissance, AI-generated exploit chains, and AI-assisted social engineering operating at scale, you're behind. Not behind the curve β behind the threat.
Jordan: I want to be specific about what "months away" means operationally. We're not talking about AGI writing zero-days from scratch. We're talking about models that can take a known vulnerability, generate working exploit code, adapt it to a target environment, and do that across thousands of targets simultaneously. The economics of offense just changed. The marginal cost of a sophisticated attack drops toward zero.
Alex: Which brings us directly to the Anthropic restriction story. The U.S. government has imposed export-style restrictions on Anthropic's most advanced models. The cybersecurity industry is pushing back hard, and the argument is straightforward β you're handicapping defenders while attackers have no such constraints. Adversaries aren't waiting for an export license.
Jordan: The policy tension here is real. There are legitimate national security reasons to control frontier model proliferation. But the practical effect for CISOs is that your AI vendor strategy just got geopolitical risk layered on top of it. If you've been building defensive workflows around a specific frontier model β automated threat hunting, code review, incident response augmentation β you need to scenario-plan for access disruption. What happens if the model you depend on gets restricted, versioned down, or pulled from your region?
Alex: This is a procurement and architecture conversation now, not just a policy debate. Dual-vendor strategies for AI, just like you'd have for cloud. And it connects to the smaller models discussion that's gaining traction. There are CISOs making the argument that fine-tuned, domain-specific smaller models running on-premise give you capability without the geopolitical supply chain risk.
Jordan: Agreed. And while we're on AI risk β the BankInfoSecurity piece on AI agent permissions is one of those stories that sounds academic until you realize it describes your environment right now. The research shows that most organizations cannot track what data their AI agents are accessing. The agents inherit user permissions. They operate at machine speed. They don't hesitate, they don't apply judgment, they don't think "maybe I shouldn't open that file." Your IAM framework was designed for humans. It assumes a human is on the other end of that session.
Alex: This is the identity governance gap I've been talking about for six months. Every CISO I know has deployed or is deploying AI agents somewhere in their environment. How many of them have implemented agent-specific access controls? How many can audit what those agents touched last Tuesday? The answer, based on this research, is almost none. You need a dedicated workstream for AI agent identity governance. Treat agents as a distinct principal type. Instrument them. Constrain them. Audit them. If you can't do that today, you need to be honest with your board about what you don't know.
Jordan: Let's pivot to the North Korea story because it puts a point on all of this. Microsoft attributed a supply chain attack on the Mastra AI framework to Sapphire Sleet. For anyone unfamiliar, Mastra is an open-source AI agent framework that a lot of development teams use to build AI-powered applications. Sapphire Sleet compromised the supply chain β meaning anyone pulling Mastra dependencies could have been pulling poisoned code.
Alex: This is the convergence story. Nation-states are now targeting AI development toolchains specifically. Not just traditional software supply chains β AI supply chains. The libraries, the frameworks, the model registries, the training pipelines. If your engineering teams are building AI capabilities, which they are, their development dependencies are now a tier-one attack surface.
Jordan: And Sapphire Sleet is not a smash-and-grab crew. They do financial theft and espionage. They're strategic. Compromising an AI framework gives you access to every organization that uses it. It's a force multiplier. CISOs need to be having explicit conversations with their engineering leadership about AI dependency management. Software composition analysis tools need to cover AI-specific supply chains. If they don't today, that's a gap.
Alex: Moving to the Klue breach, and this one stings because it hit our own industry. Huntress, HackerOne, Jamf, Recorded Future, Tanium β these are security companies. Klue is a competitive intelligence platform. The attackers compromised Klue, obtained OAuth tokens through a Salesforce integration, and used those tokens to pivot into downstream customer environments.
Jordan: OAuth token abuse through SaaS integrations. It's not new, but the scale and the victim list here make it a case study. Every one of those security vendors had a trust relationship with Klue. That trust relationship was a lateral movement path. The attackers didn't need to breach Huntress directly. They breezed through the integration.
Alex: The lesson for every CISO: your SaaS integration map is your blast radius map. When did you last audit every OAuth grant, every API token, every third-party integration touching your Salesforce instance, your identity provider, your CRM? Most organizations can't even enumerate them. That's the problem. You can't revoke what you can't see.
Jordan: Let's talk about the GentleKiller framework. ESET published details on a purpose-built EDR-killing tool distributed by the Gentlemen ransomware gang to their affiliates as a service. This is EDR bypass as a commodity.
Alex: This is the natural evolution. We've seen EDR killers before β Terminator, AuKill, various BYOVD techniques. The difference here is the productization. It's packaged, maintained, and distributed to affiliates who may not have the sophistication to build it themselves. It raises the floor for every ransomware operator in that ecosystem.
Jordan: If your defensive strategy terminates at the EDR agent, you have a single point of failure that now has a purpose-built tool designed to remove it. Defense in depth isn't a platitude here β it's operational necessity. Application allowlisting, network segmentation, behavioral analytics that don't depend on the endpoint agent being alive.
Alex: The Brazil emergency alert story is worth flagging because it's a template. Attackers compromised the national Civil Defense Alert system and pushed at least a dozen false emergency warnings to citizens. Floods, landslides β the kind of alerts people act on immediately.
Jordan: This is a trust destruction operation. The damage isn't in the false alerts themselves β it's that next time there's a real flood warning, people hesitate. If you're a CISO supporting government infrastructure, critical infrastructure, or any organization that operates public-facing alert or notification systems, this is your threat scenario. Authenticate your broadcast channels. Verify the integrity of your alerting pipeline end to end.
Alex: The Canada story is a legal precedent worth tracking. CSIS β Canada's intelligence service β obtained a judicial warrant to remotely access and remediate privately owned devices that were part of foreign-run botnets. Home routers, IoT devices, servers β on Canadian soil, belonging to private parties.
Jordan: First time they've used threat reduction warrant powers this way. The ruling was made public June 15th. This matters because it establishes that a government intelligence agency can, with judicial authorization, reach into your infrastructure and alter it to neutralize a threat. Whether you view that as a necessary national defense measure or a sovereignty concern depends on your perspective. But CISOs need to understand the legal landscape is shifting. Governments are asserting authority to act on private networks.
Alex: If your devices are compromised and you haven't remediated them, someone else might. That's the new reality.
Jordan: Last item β CISA issued an urgent advisory on Fortinet credential compromise. The FortiBleed campaign has been running for months, targeting western organizations. Thousands of credentials confirmed compromised. This is active, ongoing exploitation.
Alex: If you have internet-facing Fortinet infrastructure, this is a stop-what-you're-doing item. Verify device hardening against CISA's advisory. Rotate credentials. Check for indicators of compromise. Assume breach if you haven't patched and hardened. This isn't theoretical β thousands of organizations are already compromised.
Jordan: The theme this week, Alex β it's compression. Time compression on AI threats. Trust compression across SaaS supply chains. Capability compression as commodity tools close the gap between sophisticated and unsophisticated attackers.
Alex: That's exactly right. The planning assumptions from twelve months ago are obsolete. The Five Eyes warning isn't about 2028. The Mastra supply chain attack isn't about future AI risks. The GentleKiller framework isn't about theoretical EDR bypass. All of it is happening now, and the organizations that are still in annual planning cycles for these threats are operating on a timeline that no longer exists.
Jordan: Watch this week for follow-on analysis from the Five Eyes advisory β particularly any technical annexes that drop. Watch for Klue breach notifications propagating through vendor risk management channels. And if you're running Fortinet, you know what to do.
Alex: That's our show for Monday, June 22nd. Show notes, links to every story we covered, and additional context are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. See you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-22.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.