Cleartext

Cleartext – June 26, 2026


Listen Later

Cleartext – June 26, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 5 topic areas, including: Risky Bulletin: Operation Endgame dismantles Amadey and StealerC; Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks; China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor.

Stories Covered
🌍 Geopolitical
Risky Bulletin: Operation Endgame dismantles Amadey and StealerC

Risky Business News Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

Why it matters to CISOs: Law enforcement's takedown of two major malware-as-a-service operations (Amadey and StealerC) directly reduces active threat infrastructure targeting enterprises; the Australia 'digital dynamite on critical networks' finding warrants attention for critical infrastructure operators.

  • Operation Endgame expanded to dismantle Amadey botnet and StealerC credential-theft malware operations
  • Australia discovered what officials described as 'digital dynamite' embedded on critical infrastructure networks
  • Japan's military found infected USB drives in use, highlighting insider/supply chain risk in allied defense ecosystems
  • πŸ“– Read full article

    Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

    The Hacker News Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

    Why it matters to CISOs: Google Threat Intelligence's attribution of a new .NET backdoor to Turlaβ€”actively deployed against government and military targetsβ€”signals continued Russian APT capability development that enterprises with government contracts or NATO-adjacent supply chains must track.

    • Turla (Russian FSB-linked APT) has deployed a new .NET backdoor called STOCKSTAY against Ukrainian government and military organizations
    • The backdoor is described as 'continually developed,' indicating active, maintained capability
    • Targeting extends beyond Ukraine to entities with Italian foreign policy interests, broadening the geographic risk profile
    • πŸ“– Read full article

      China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor

      Infosecurity Magazine Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

      Why it matters to CISOs: A China-nexus threat group deploying a custom backdoor against Southeast Asian critical infrastructure reinforces the persistent CNI targeting trend and raises third-party risk concerns for multinationals operating in the region.

      • China-linked threat actor deployed a previously undocumented custom backdoor named TinyRCT against critical infrastructure in Southeast Asia
      • Custom tooling suggests a sophisticated, well-resourced actor willing to invest in operational security
      • Pattern is consistent with broader Chinese APT campaigns against CNI ahead of potential geopolitical flashpoints
      • πŸ“– Read full article

        πŸ“‘ Macro Trends
        Ransomware gangs find Europe’s weakest link in third-party suppliers

        Help Net Security Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

        Why it matters to CISOs: With ransomware attacks against European organizations accelerating and third-party suppliers emerging as the primary attack vector, CISOs with EU operations or supply chains must reassess vendor risk programs against the backdrop of converging NIS2 and DORA obligations.

        • Black Kite analyzed 2,066 ransomware incidents across 31 European countries between January 2025 and April 2026
        • Third-party suppliers have become a primary ransomware entry point, overtaking direct enterprise targeting in frequency
        • Three converging forces identified: accelerating ransomware volume, supply chain as primary attack path, and tightening EU regulations (NIS2, DORA)
        • πŸ“– Read full article

          πŸ”“ Data Breach
          Breach Roundup: How Hackers Exploited a Cisco SD-WAN Flaw

          BankInfoSecurity Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

          Why it matters to CISOs: This roundup consolidates several active incidentsβ€”Cisco SD-WAN exploitation, Ubiquiti zero-days, INC ransomware activity, and cross-cloud bucket hijacking researchβ€”providing a concise threat picture for security operations briefings.

          • Mandiant detailed active exploitation of a Cisco SD-WAN flaw, corroborating pre-disclosure exploitation findings
          • Three Ubiquiti vulnerabilities are under active exploitation, affecting networking infrastructure commonly used in enterprise branch offices
          • INC ransomware group leak and cross-cloud bucket hijacking research represent emerging TTPs requiring defensive review
          • πŸ“– Read full article

            βš–οΈ Governance & Policy
            FCC passes new cybersecurity rules for emergency systems, undersea cables

            CyberScoop Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

            Why it matters to CISOs: New FCC rules overhauling national emergency alert systems and imposing federal security review requirements on undersea cable providers create direct compliance obligations for telecoms, ISPs, and the enterprises that depend on them for resilient connectivity.

            • FCC adopted rules to overhaul national emergency alert infrastructure to protect against hijacking
            • New federal security review requirements apply to undersea cable providers with national security implications
            • Rules affect telecommunications carriers and potentially large enterprises with private cable landing rights
            • πŸ“– Read full article

              DHS chief says president has met with likely CISA nominee; agency plans to hire 600

              The Record (Recorded Future) Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

              Why it matters to CISOs: CISA's planned 600-person hiring surge and imminent director appointment will shape the agency's operational posture, affecting how enterprises receive threat intelligence, respond to KEV advisories, and engage on sector-specific guidance.

              • DHS Secretary Mullin confirmed the president has met with a likely CISA director nominee, though no formal announcement has been made
              • Once a director is confirmed, CISA plans to hire approximately 600 additional staff
              • Testimony was delivered at a House hearing, signaling congressional pressure to restore CISA leadership capacity
              • πŸ“– Read full article

                As cyber risk evolves, the insurance industry tightens guardrails

                Cybersecurity Dive Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                Why it matters to CISOs: Stricter cyber insurance underwriting standards are increasingly tied to measurable security controls, making insurance renewals a de facto security audit that CISOs must prepare for with documented resilience evidence.

                • Cyber insurance underwriters are tightening requirements, linking claims eligibility to adherence to strict security control standards
                • C-suite concern about resilience is rising but insurers are responding with more prescriptive policy conditions
                • Claims frequency and severity trends are driving premium and exclusion adjustments that will affect enterprise security budgeting
                • πŸ“– Read full article

                  Critical open-source projects get a new security framework

                  Help Net Security Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                  Why it matters to CISOs: The Linux Foundation's Akrites initiative establishes an industry-backed common framework for open-source vulnerability remediation and disclosure, directly affecting how enterprises receive and act on CVE information for the OSS components in their software supply chains.

                  • The Linux Foundation launched Akrites, bringing together tech companies, financial institutions, security vendors, and AI companies to support OSS vulnerability remediation
                  • The initiative is explicitly motivated by AI shortening the time between flaw discovery and exploitation
                  • Akrites aims to establish a common disclosure and remediation process for widely used open-source software, potentially standardizing enterprise response obligations
                  • πŸ“– Read full article

                    🚨 Critical Vulnerability
                    Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

                    Infosecurity Magazine Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                    Why it matters to CISOs: A high-severity Cisco Catalyst SD-WAN Manager flaw being actively exploited as far back as Marchβ€”three months before public disclosureβ€”illustrates the zero-day dwell-time problem for enterprises running widely deployed SD-WAN infrastructure.

                    • A high-severity flaw in Cisco Catalyst SD-WAN Manager was exploited by threat actors as early as March 2026, roughly three months before its June disclosure
                    • Google (Mandiant) detailed the exploitation activity, suggesting nation-state or sophisticated criminal actor involvement
                    • The pre-patch exploitation window means organizations that patched promptly may still have experienced undetected compromise requiring retrospective investigation
                    • πŸ“– Read full article

                      Further Reading
                      • 🌍 Risky Bulletin: Operation Endgame dismantles Amadey and StealerC β€” Risky Business News
                      • 🌍 Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks β€” The Hacker News
                      • 🌍 China-Linked Hackers Strike Asian Critical Infrastructure with TinyRCT Backdoor β€” Infosecurity Magazine
                      • πŸ“‘ Ransomware gangs find Europe’s weakest link in third-party suppliers β€” Help Net Security
                      • πŸ”“ Breach Roundup: How Hackers Exploited a Cisco SD-WAN Flaw β€” BankInfoSecurity
                      • βš–οΈ FCC passes new cybersecurity rules for emergency systems, undersea cables β€” CyberScoop
                      • βš–οΈ DHS chief says president has met with likely CISA nominee; agency plans to hire 600 β€” The Record (Recorded Future)
                      • βš–οΈ As cyber risk evolves, the insurance industry tightens guardrails β€” Cybersecurity Dive
                      • βš–οΈ Critical open-source projects get a new security framework β€” Help Net Security
                      • 🚨 Cisco Vulnerability Exploited Months Before Disclosure, Google Warns β€” Infosecurity Magazine
                      • Full Transcript
                        Click to expand full episode transcript

                        Alex: Welcome to Cleartext. It's Friday, June 26th, 2026. I'm Alex Chen.

                        Jordan: And I'm Jordan Reeves. Let's get into it.

                        Alex: Jordan, you wanted to lead with the Cisco SD-WAN story today and I think that's the right call.

                        Jordan: Yeah. So Google's Mandiant team published details on a high-severity flaw in Cisco Catalyst SD-WAN Manager that was being actively exploited as far back as March. The vulnerability wasn't publicly disclosed until June. That's a three-month dwell time where attackers had free rein on one of the most widely deployed SD-WAN platforms in the enterprise. And the sophistication of the exploitation activity suggests this wasn't script kiddies. We're talking nation-state or top-tier criminal operators.

                        Alex: And this is the part that should land hard for anyone listening. If you patched the day Cisco disclosed, you were already three months late. The real action item here is retrospective investigation. You need to go back and look for indicators of compromise in your SD-WAN infrastructure from March forward. Patching closed the door, but someone may have already been inside.

                        Jordan: Exactly. And this ties into the broader breach roundup from BankInfoSecurity this week. Mandiant's SD-WAN findings were part of a cluster that also includes three Ubiquiti vulnerabilities under active exploitation, INC ransomware activity, and some interesting research on cross-cloud bucket hijacking. For security operations teams, this is a dense week. The Ubiquiti flaws hit networking gear that's common in branch offices, so if you're running distributed infrastructure, check your exposure.

                        Alex: Good segue, because dense is the word for the threat landscape this week. Let's talk about the state-sponsored activity, because there's a lot of it and it paints a coherent picture.

                        Jordan: Three distinct stories, three different nation-state actors, all dropped on the same day. First, Google Threat Intelligence published a detailed write-up on Turla, the Russian FSB-linked group, deploying a new .NET backdoor called STOCKSTAY. Primary targets are Ukrainian government and military, which is expected. What's less expected is the targeting of entities with ties to Italian foreign policy, which broadens the geographic risk profile significantly.

                        Alex: And for CISOs at organizations with government contracts or NATO-adjacent supply chains, this is directly relevant. Turla doesn't limit itself to Ukrainian targets. They follow the intelligence priorities of the Russian state, and right now those priorities include fracturing Western European consensus. If your organization touches defense, diplomacy, or energy policy in Europe, you're in the aperture.

                        Jordan: Second story. China-linked actors deploying a custom backdoor called TinyRCT against critical infrastructure in Southeast Asia. The custom tooling is the important detail here. When a threat group invests in bespoke malware rather than repurposing commodity tools, it tells you two things: they're well-resourced, and they care about operational security. They don't want to be detected and they don't want the capability burned.

                        Alex: And for multinationals with operations in the region, this is a third-party risk story as much as a direct targeting story. Your Southeast Asian suppliers, your joint ventures, your regional data centers, they're all potential vectors. The pattern of Chinese APT activity against critical national infrastructure ahead of geopolitical flashpoints is well established at this point. We saw it before the Taiwan Strait tensions, we're seeing it again now.

                        Jordan: And the third piece is the most visceral. Australia's intelligence services found what they described publicly as "digital dynamite" embedded on critical infrastructure networks. That's not analyst hyperbole; that's the Australian government using that language deliberately. At the same time, Japan's military discovered infected USB drives in active use within their defense ecosystem. These are allied nations in the Five Eyes and Quad frameworks finding pre-positioned threats in their most sensitive environments.

                        Alex: Let me connect these three threads for the board-level audience. We are watching real-time preparation of the cyber battlespace by multiple state actors simultaneously. Russia maintaining persistent access in Europe through Turla. China pre-positioning in Southeast Asian infrastructure. And allied nations discovering embedded threats they didn't know were there. If you're a CISO at a critical infrastructure operator, this is the week you update your board on nation-state risk and make sure your threat model reflects the current geopolitical reality, not the one from 18 months ago.

                        Jordan: Now let's talk about some good news, which doesn't happen often on this show. Operation Endgame expanded this week. Europol and partner agencies dismantled the Amadey botnet and the StealerC credential-theft malware operation. These were major malware-as-a-service platforms. Amadey was a loader botnet used to distribute secondary payloads, and StealerC was exactly what the name suggests: a credential harvesting operation at scale.

                        Alex: This is the kind of law enforcement action that actually moves the needle. These aren't symbolic arrests; these are infrastructure takedowns that force threat actors to rebuild. It doesn't eliminate the threat, but it creates friction. It raises the cost of doing business for cybercriminals. And if your organization was seeing Amadey or StealerC indicators in your environment, you should be tracking whether those command-and-control channels have gone dark and using that window to clean up any residual compromise.

                        Jordan: Agreed. Credit where it's due. The sustained international coordination on Endgame has been impressive.

                        Alex: Let's shift to the supply chain and regulatory picture in Europe, because there's a report from Black Kite that quantifies something we've been talking about for months. They analyzed over 2,000 ransomware incidents across 31 European countries between January 2025 and April 2026, and the headline finding is that third-party suppliers have overtaken direct enterprise targeting as the primary ransomware entry point.

                        Jordan: That's not a surprise to anyone who's been paying attention, but having the data is useful. It validates the investment thesis for vendor risk programs.

                        Alex: It does, and it makes the NIS2 and DORA compliance conversation much more concrete. Those regulations explicitly address supply chain security obligations. If your third-party risk program is still based on annual questionnaires and SOC 2 reports, you're not meeting the spirit of what European regulators are building toward. The Black Kite data gives you ammunition to go to your board and say: the regulatory pressure and the threat data are aligned. We need to invest in continuous vendor monitoring.

                        Jordan: And speaking of regulatory movement, two governance stories worth flagging. The FCC adopted new rules this week overhauling security requirements for national emergency alert systems and imposing federal security review for undersea cable providers. If you're in telecom or if your business continuity depends on submarine cable connectivity, which it does for most global enterprises, these rules affect your risk posture.

                        Alex: The emergency alert system piece is particularly interesting. The FCC is explicitly addressing the hijacking risk for national alert infrastructure. This is the kind of systemic risk that most CISOs don't think about until it's too late. And the undersea cable rules reflect the reality that those cables are strategic assets, not just commercial infrastructure.

                        Jordan: Second governance item: DHS Secretary Mullin confirmed that the president has met with a likely CISA director nominee, and once confirmed, the agency plans to hire 600 additional staff. No formal announcement yet, but the signal is clear. CISA is going to ramp back up.

                        Alex: This matters for how enterprises receive threat intelligence, how KEV advisories get prioritized, and how sector-specific guidance evolves. A fully staffed CISA with permanent leadership is good for everyone. Watch this space.

                        Jordan: Two more quick hits. Cyber insurance underwriters are tightening the screws again. Claims eligibility is increasingly tied to adherence to specific security controls, not just having a policy. Renewals are becoming de facto security audits. CISOs need documented evidence of resilience, not just assertions.

                        Alex: I've been saying this for two years. Your insurance renewal prep should look like your audit prep. Have your MFA coverage data, your backup testing results, your incident response tabletop records ready. Insurers are getting sophisticated about what they ask for, and exclusions are getting more specific.

                        Jordan: And finally, the Linux Foundation launched Akrites, an industry-backed framework for coordinating open-source vulnerability remediation and disclosure. The explicit motivation is that AI is shortening the window between flaw discovery and exploitation, so the open-source ecosystem needs a faster, more standardized response process.

                        Alex: This is a software supply chain story. If your application stack depends on open-source components, and it does, then how those communities handle vulnerability disclosure directly affects your patching timelines. Akrites is trying to industrialize that process, and major tech companies and financial institutions are backing it. Worth tracking how it evolves.

                        Jordan: So Alex, stepping back and looking at the week, what's the thread?

                        Alex: The thread is convergence. The threat actors are converging on supply chains and pre-positioned access. The regulators are converging on accountability, whether that's NIS2, DORA, or the FCC. And the insurance market is converging on verifiable controls. For CISOs, this means the gap between what you tell your board and what you can actually demonstrate is getting smaller. Assertions without evidence are going to get you in trouble, whether it's with your insurer, your regulator, or the threat actor who's already in your supplier's network.

                        Jordan: I'd add one thing. The Cisco SD-WAN story is the canary. Three months of pre-disclosure exploitation on widely deployed infrastructure. If your detection capabilities aren't good enough to catch that kind of activity independently of vendor disclosure, that's the gap you need to close. Don't wait for the CVE. Assume someone already found it.

                        Alex: That's a great note to end on. That's Cleartext for Friday, June 26th, 2026. Show notes and links to every story we covered today are at cleartext.fm.

                        Jordan: Have a good weekend. Stay sharp.

                        Alex: We'll see you Monday.

                        Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-26.

                        Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                        ...more
                        View all episodesView all episodes
                        Download on the App Store

                        CleartextBy Cleartext