Cleartext

Cleartext – June 25, 2026


Listen Later

Cleartext – June 25, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: In a first, a court takedown goes after two cybercrime tools at once; Srsly Risky Biz: Open weight models make the Mythos debate moot; Europe Evolves Into Ransomware's Favorite Region.

Stories Covered
🌍 Geopolitical
In a first, a court takedown goes after two cybercrime tools at once

CyberScoop · Jun 24 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The simultaneous court-authorized disruption of Amadey and StealC—two tools frequently used together as an initial-access-to-infostealer pipeline feeding ransomware—represents a new legal strategy with real near-term impact on credential theft volumes targeting enterprise environments. CISOs should monitor for reduced infostealer activity but not stand down defenses.

  • Microsoft, Europol, and partners disrupted 200+ command-and-control servers for Amadey and StealC in a single coordinated action—the first dual-tool simultaneous court takedown
  • Operation Endgame action recovered 27 million stolen credentials and targeted the full cybercriminal 'assembly line' used to launch ransomware and fraud
  • More than 300 servers were seized or disrupted globally, with Bitdefender, Bitsight, ESET, and Microsoft participating alongside law enforcement
  • 📖 Read full article

    Srsly Risky Biz: Open weight models make the Mythos debate moot

    Risky Business News · Jun 25 · Relevance: ███████░░░ 7/10

    Why it matters to CISOs: Five Eyes agencies formally acknowledging that AI-enabled offensive cyber capabilities can no longer be contained by export controls is a strategic inflection point—CISOs should factor the democratization of AI-assisted attacks into threat modeling and board-level risk narratives.

    • Five Eyes cybersecurity agencies issued a formal warning about AI-enabled cyber threats, acknowledging that offensive AI capabilities are now accessible regardless of frontier model export controls
    • Open-weight models make it impossible to limit advanced AI cyber tools to benign actors, fundamentally changing the threat landscape
    • Operation Endgame is cited as a successful model for continuous disruption of cybercriminal ecosystems, though criminal enterprises demonstrate resilience and recovery
    • 📖 Read full article

      📡 Macro Trends
      Europe Evolves Into Ransomware's Favorite Region

      Dark Reading · Jun 25 · Relevance: ████████░░ 8/10

      Why it matters to CISOs: A 50%+ surge in ransomware targeting EU organizations over the past year, combined with rising supply chain attack vectors, directly affects CISOs with European operations, subsidiaries, or third-party suppliers—particularly given NIS2 mandatory incident reporting timelines now in force.

      • Black Kite analysis shows ransomware attacks targeting Europe increased by over 50% in the last year
      • Supply chain attacks are increasing as a primary vector for ransomware delivery in the European theater
      • After a global lull, ransomware gangs are refocusing on EU organizations and their supplier ecosystems
      • 📖 Read full article

        New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

        The Hacker News · Jun 25 · Relevance: ███████░░░ 7/10

        Why it matters to CISOs: Gaslight represents a first-in-class threat tactic where malware actively sabotages AI-assisted malware analysis tools used by SOC teams—CISOs integrating AI into incident response and triage workflows must account for adversarial prompt injection as a technique to blind their detection pipelines.

        • Gaslight is a Rust-based macOS implant and infostealer that embeds prompt injection payloads designed to cause AI analysis tools to abort or refuse malware examination
        • The malware is assessed with high confidence to be an operational tool, not a proof-of-concept, targeting security analysts using AI-assisted investigation platforms
        • This represents a new adversarial technique specifically designed to undermine AI-augmented SOC workflows and slow incident response
        • 📖 Read full article

          More Malicious OpenClaw Skills Threaten AI Supply Chain

          Dark Reading · Jun 24 · Relevance: ███████░░░ 7/10

          Why it matters to CISOs: Malicious packages containing infostealers reaching the ClawHub AI skills marketplace—bypassing security checks—signals that AI agent supply chain risk is materializing in the same pattern as npm/PyPI attacks, requiring CISOs to extend software composition analysis to AI skill and plugin ecosystems.

          • Five malicious packages were removed from OpenClaw's ClawHub skills marketplace after bypassing security verification checks
          • Malicious packages contained infostealers and other threats capable of compromising enterprise environments using AI agents
          • The incident demonstrates that AI skills/plugin marketplaces are now an active supply chain attack vector analogous to open-source package repositories
          • 📖 Read full article

            🔓 Data Breach
            Indian auto giant Bajaj Auto hit by ransomware incident

            The Record (Recorded Future) · Jun 24 · Relevance: ███████░░░ 7/10

            Why it matters to CISOs: A ransomware attack on one of India's largest automotive manufacturers—disclosed via regulatory filing—underscores the continued targeting of major industrial conglomerates and the regulatory disclosure obligations CISOs must manage under SEBI and equivalent frameworks.

            • Bajaj Auto, a major Indian automotive manufacturer, disclosed a ransomware incident in a regulatory filing
            • The company became aware of the incident on Tuesday morning and took precautionary containment measures
            • No ransomware group has yet claimed responsibility; scope of data exfiltration remains unclear
            • 📖 Read full article

              ⚖️ Governance & Policy
              White House’s state infrastructure cybersecurity initiative stalled

              Cybersecurity Dive · Jun 24 · Relevance: ███████░░░ 7/10

              Why it matters to CISOs: The stalling of the federal-state critical infrastructure cybersecurity pilot program signals continued fragmentation in US national cyber defense coordination—CISOs in regulated critical infrastructure sectors should not count on federal-state partnership initiatives materializing for near-term planning purposes.

              • The Trump administration's initiative to help states implement innovative cybersecurity defenses for critical infrastructure has stalled, with most states still waiting to participate
              • ONCD-led program has not progressed to actionable pilot deployments despite White House stated intent
              • The gap leaves state-level critical infrastructure operators without the federal coordination support originally envisioned
              • 📖 Read full article

                🚨 Critical Vulnerability
                Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

                The Hacker News · Jun 25 · Relevance: █████████░ 9/10

                Why it matters to CISOs: A zero-day exploited two months before disclosure against a communications service provider—granting root access on Cisco SD-WAN infrastructure—demands immediate patching and threat hunting across any organization running Catalyst SD-WAN. Mandiant attribution and the communications sector targeting suggest sophisticated, likely nation-state-adjacent actors.

                • CVE-2026-20245 (CVSS 7.8) was exploited in the wild at least two months before public disclosure, classified as a zero-day by Mandiant/Google
                • Attackers gained root access on Cisco Catalyst SD-WAN devices at a communications service provider, potentially enabling traffic interception
                • Exploitation allows authenticated local attackers to execute arbitrary commands with elevated privileges, creating rogue root accounts
                • 📖 Read full article

                  Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

                  The Hacker News · Jun 24 · Relevance: ████████░░ 8/10

                  Why it matters to CISOs: A newly identified CI/CD workflow weakness class enables full attacker control of repositories at major organizations including Microsoft, Google, and Apache—CISOs running GitHub-based pipelines must audit for this pattern immediately given the software supply chain risk and potential for silent backdooring of build artifacts.

                  • The 'Cordyceps' vulnerability class affects 300+ GitHub repositories across dozens of major organizations including Microsoft, Google, and Apache
                  • Exploitation allows attackers to hijack CI/CD workflows and compromise open-source supply chains with full repository control
                  • Discovered by Novee Security; organizations with public-facing GitHub Actions workflows using pull request triggers are at highest risk
                  • 📖 Read full article

                    Further Reading
                    • 🌍 In a first, a court takedown goes after two cybercrime tools at onceCyberScoop
                    • 🌍 Srsly Risky Biz: Open weight models make the Mythos debate mootRisky Business News
                    • 📡 Europe Evolves Into Ransomware's Favorite RegionDark Reading
                    • 📡 New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted AnalysisThe Hacker News
                    • 📡 More Malicious OpenClaw Skills Threaten AI Supply ChainDark Reading
                    • 🔓 Indian auto giant Bajaj Auto hit by ransomware incidentThe Record (Recorded Future)
                    • ⚖️ White House’s state infrastructure cybersecurity initiative stalledCybersecurity Dive
                    • 🚨 Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root AccessThe Hacker News
                    • 🚨 Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain AttacksThe Hacker News
                    • Full Transcript
                      Click to expand full episode transcript

                      Alex: Welcome to Cleartext. It's Thursday, June 25th, 2026. I'm Alex Chen.

                      Jordan: And I'm Jordan Reeves. Let's get into it.

                      Alex: We've got a packed show today. Microsoft and Europol just executed something genuinely new in cybercrime disruption. Five Eyes agencies are waving a flag on AI-enabled offense. Europe is becoming ransomware's favorite hunting ground. We've got a Cisco SD-WAN zero-day that's been exploited for two months before anyone knew about it. And a fascinating piece of malware that's literally gaslighting your SOC's AI tools. Let's start big.

                      Jordan: So the Microsoft-Europol action. On the surface, another takedown, another press release. But this one is structurally different and CISOs should pay attention to why. For the first time, a court-authorized operation targeted two distinct cybercrime tools simultaneously—Amadey and StealC—because they function as an assembly line. Amadey gets initial access, StealC harvests credentials, and that pipeline feeds directly into ransomware operations. Microsoft and partners took down over 200 command-and-control servers. More than 300 servers seized or disrupted globally. And they recovered 27 million stolen credentials.

                      Alex: The strategic shift here is the legal innovation. Previous takedowns targeted individual botnets or individual malware families. This is the first time the legal framework was constructed to go after two tools as a connected criminal workflow. That matters because it reflects how cybercrime actually operates—as a supply chain, not as isolated tools. The court order recognized that reality.

                      Jordan: Exactly. And this is part of the broader Operation Endgame framework, which Europol has been running. The participating organizations—Bitdefender, Bitsight, ESET, Microsoft—are essentially operating as a standing coalition. Now, will Amadey and StealC operators rebuild? Almost certainly. But the disruption has a real cost function. Rebuilding C2 infrastructure takes time and money, and during that window, the infostealer pipeline feeding ransomware operators is degraded.

                      Alex: For CISOs, the practical takeaway is this: you may see a near-term reduction in credential theft volume from these specific tools. Do not mistake a temporary lull for a trend. Your infostealer defenses, your credential monitoring, your dark web exposure assessments—none of that changes. But do track the disruption as a data point when you're briefing your board on the threat landscape.

                      Jordan: Which brings us directly to the Five Eyes AI warning, because these two stories are connected. The Five Eyes cybersecurity agencies—US, UK, Canada, Australia, New Zealand—issued a formal acknowledgment that AI-enabled offensive cyber capabilities can no longer be contained through export controls or model restrictions. The genie is out of the bottle. Their words, essentially.

                      Alex: This is a strategic inflection point and I want CISOs to understand why. For the last two years, there's been a policy debate about whether restricting access to frontier AI models could limit offensive cyber capability. The Five Eyes agencies just formally conceded that argument is over. Open-weight models have made it moot. Any moderately sophisticated threat actor can fine-tune an open model for vulnerability discovery, phishing generation, or exploit development. The Mythos debate—whether AI meaningfully changes offensive capability—is settled in the affirmative.

                      Jordan: And the practical implication is that the asymmetry defenders have relied on—that offensive AI tooling requires significant resources—is collapsing. CISOs need to update their threat models. When you're doing your annual risk assessment, when you're presenting to the board, the assumption should now be that your adversaries have AI-augmented capabilities regardless of who they are. That's not speculation anymore. That's the assessed position of Five Eyes intelligence agencies.

                      Alex: The Five Eyes statement also references Operation Endgame as the model for how you deal with this—continuous disruption rather than containment. Which tells you something about where national cyber strategy is heading: accept that the tools are proliferated, focus on disrupting the operators.

                      Jordan: Let's shift to Europe, because the targeting data is stark. Black Kite's analysis shows ransomware attacks targeting European organizations increased by over 50 percent in the last year. And the primary vector driving that increase is supply chain attacks.

                      Alex: This is directly relevant to any CISO with European operations, European subsidiaries, or European third-party suppliers. And given how interconnected global supply chains are, that's most of you. The 50 percent increase isn't evenly distributed—it's concentrated in manufacturing, healthcare, and critical infrastructure. And the supply chain vector means your third-party risk management program is your front line.

                      Jordan: What's driving the shift is partly opportunity and partly regulatory asymmetry. European organizations are implementing NIS2, which creates mandatory incident reporting timelines. Ransomware operators know this. They know that a ticking disclosure clock creates leverage. If you have to report within 24 hours and you haven't figured out what happened yet, the pressure to pay increases.

                      Alex: And NIS2's supply chain provisions mean that if your supplier gets hit, you may have reporting obligations even if your own systems are untouched. CISOs need to be mapping their European supplier exposure and ensuring their third-party risk programs account for this threat concentration.

                      Jordan: Now let's talk about a vulnerability that demands immediate attention. CVE-2026-20245, Cisco Catalyst SD-WAN. CVSS 7.8. Mandiant confirmed this was exploited as a zero-day at least two months before public disclosure. The target was a communications service provider. The attackers gained root access and created rogue root accounts on SD-WAN infrastructure.

                      Alex: Let me be direct. If you're running Cisco Catalyst SD-WAN, this is a patch-now situation. The fact that it was exploited against a communications service provider—where SD-WAN infrastructure handles traffic routing—suggests the objective was traffic interception. Mandiant hasn't publicly attributed it, but the targeting profile and sophistication point to nation-state-adjacent actors.

                      Jordan: The exploitation requires authenticated local access, which means there's a precursor access event. So your threat hunting shouldn't stop at patching. You need to look for unauthorized accounts, unexpected privilege escalations, and any signs of lateral movement toward your SD-WAN management plane over the past 60 to 90 days.

                      Alex: Next up, and this one is genuinely novel. A macOS malware called Gaslight—Rust-based infostealer—that embeds prompt injection payloads specifically designed to make AI analysis tools refuse to examine it. This is not a proof of concept. Mandiant assesses with high confidence this is operational malware.

                      Jordan: This is the adversarial AI story that actually matters. Not AI generating malware—we've been talking about that for two years. This is malware that attacks the AI tools your SOC analysts are using. If your incident response workflow includes AI-assisted triage, AI-assisted malware analysis, AI-assisted reverse engineering, Gaslight is designed to make those tools say "I can't analyze this" or produce incorrect results. It's poisoning your analysis pipeline.

                      Alex: The strategic implication for CISOs is clear. If you've integrated AI tooling into your security operations—and most of you have or are in the process—you need adversarial testing of those tools. Can your AI analysis pipeline be tricked by embedded prompt injection? If you don't know the answer, you have a gap. AI in the SOC is a force multiplier, but it's also a new attack surface.

                      Jordan: And relatedly, the AI supply chain story. Five malicious packages were removed from OpenClaw's ClawHub skills marketplace after bypassing security verification. These packages contained infostealers. This is the npm and PyPI problem replicated in the AI agent ecosystem. If your organization is deploying AI agents that pull skills or plugins from marketplaces, you now have a software composition analysis problem that most AppSec programs aren't covering.

                      Alex: Extend your SCA tooling and your procurement review processes to AI skill and plugin ecosystems. If your AI agents can install capabilities from a marketplace, that marketplace is part of your supply chain. Treat it accordingly.

                      Jordan: Quick hit on Bajaj Auto. One of India's largest automotive manufacturers disclosed a ransomware incident via regulatory filing. No group has claimed it yet. The significance here isn't the specific incident—it's the pattern. Major industrial conglomerates in emerging markets are increasingly targets, and the disclosure came through securities regulation, not voluntary disclosure. SEBI's requirements forced transparency. Same dynamic we see with the SEC rules here.

                      Alex: And the White House state infrastructure cybersecurity initiative has stalled. The ONCD-led program to help states implement cybersecurity defenses for critical infrastructure hasn't progressed to actionable pilots. Most states are still waiting to participate. If you're a CISO in a regulated critical infrastructure sector, do not plan around federal-state coordination support materializing in the near term. Build your resilience independently.

                      Jordan: Last item. The Cordyceps vulnerability class. Novee Security identified a pattern in GitHub Actions CI/CD workflows that affects over 300 repositories across Microsoft, Google, Apache, and other major organizations. Exploitation allows full attacker control of repositories and silent backdooring of build artifacts.

                      Alex: If you're running GitHub-based CI/CD pipelines with pull request triggers on public repositories, audit immediately. This is a software supply chain risk that could allow an attacker to inject code into your build process without touching your source code directly. The Cordyceps pattern is a workflow configuration weakness, not a GitHub platform vulnerability, which means it's on you to fix.

                      Jordan: So stepping back—what's the theme this week?

                      Alex: It's the weaponization of trust in systems. The AI tools you trust for analysis can be manipulated. The AI marketplaces you trust for capabilities can deliver malware. The CI/CD pipelines you trust to build your software can be hijacked. The supply chains you trust in Europe are being targeted at 50 percent higher rates. Every layer of trust in the technology stack is being tested.

                      Jordan: And the response from the defender ecosystem is evolving. The dual-tool takedown, the Five Eyes acknowledging AI proliferation, these are signs that the strategic framework is shifting from prevention to continuous disruption. CISOs need to internalize that. You're not building a wall. You're managing an ongoing contest.

                      Alex: Exactly right. That's our show for Thursday, June 25th. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow.

                      Jordan: Stay sharp.

                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-25.

                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                      ...more
                      View all episodesView all episodes
                      Download on the App Store

                      CleartextBy Cleartext