Cleartext

Cleartext – June 30, 2026


Listen Later

Cleartext – June 30, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 5 topic areas, including: US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp; Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks; The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure..

Stories Covered
🌍 Geopolitical
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp

The Record (Recorded Future) Β· Jun 29 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

Why it matters to CISOs: Russia-linked APT groups UNC5792 and UNC4221 are actively targeting government officials via secure messaging platforms, representing a significant threat to executive communications security and mobile device policies at any organization with government ties or sensitive communications requirements.

  • U.S. State Department is offering $10 million for information on UNC5792 and UNC4221, groups linked to Russian intelligence and military services
  • The campaign has been ongoing since at least March and involves social engineering to compromise Signal and WhatsApp accounts
  • The targeting of secure messaging apps signals a strategic shift in how nation-state actors pursue high-value communications interception
  • πŸ“– Read full article

    Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

    The Hacker News Β· Jun 29 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

    Why it matters to CISOs: China-aligned Mustang Panda's use of legitimate SaaS platforms like Zoho WorkDrive as C2 infrastructure demonstrates an evolving evasion technique that defeats network-based controls and highlights the risk of trusted cloud services being weaponized against enterprise and government targets.

    • Mustang Panda is conducting active espionage campaigns against Indian government networks, including machines used by senior administrative staff
    • The group is using Zoho WorkDrive as a command-and-control channel, allowing malicious traffic to blend with legitimate SaaS communications
    • New malware families are being deployed, indicating ongoing capability development by the threat actor
    • πŸ“– Read full article

      πŸ“‘ Macro Trends
      The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure.

      VentureBeat Security Β· Jun 29 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

      Why it matters to CISOs: The 'agentjacking' attack classβ€”where attackers inject malicious instructions into observability and ticketing tools to hijack AI coding agentsβ€”exposes enterprises adopting agentic AI development workflows to a systemic new threat that bypasses EDR, WAF, IAM, and firewall controls entirely.

      • Tenet Security demonstrated that a single crafted Sentry error event sent through a public credential can hijack Claude Code, Cursor, and Codex to execute attacker instructions with developer privileges
      • The attack achieved an 85% success rate in controlled testing across 100-plus targets; Sentry acknowledged the flaw is 'technically not defensible'
      • The Cloud Security Alliance classified agentjacking as a systemic MCP vulnerability class, affecting Datadog, PagerDuty, Jira, and similar DevOps toolchain integrations
      • πŸ“– Read full article

        πŸ”“ Data Breach
        Hackers now exploit critical Oracle E-Business flaw in attacks

        BleepingComputer Β· Jun 29 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

        Why it matters to CISOs: Active exploitation of a CVSS 9.8 authentication and privilege management flaw in Oracle E-Business Suite's Payments module threatens financial data integrity and ERP system availability at enterprises running one of the most widely deployed back-office platforms globally.

        • CVE-2026-46817 (CVSS 9.8) in Oracle E-Business Suite Payments module is being actively exploited in the wild
        • The flaw allows privilege management bypass and authentication exploitation, enabling full instance takeover
        • Oracle E-Business Suite is used by thousands of large enterprises globally for financial, HR, and supply chain operations
        • πŸ“– Read full article

          Nissan discloses employee data breach linked to Oracle zero-day attacks

          BleepingComputer Β· Jun 29 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

          Why it matters to CISOs: Nissan's disclosure of an employee data breach via Oracle PeopleSoft zero-day exploitation by ShinyHunters reinforces the urgent need for CISOs to assess PeopleSoft exposure and patch status, especially as the same attack vector has now hit multiple major organizations.

          • Nissan disclosed a breach affecting current and former employees tied to Oracle PeopleSoft zero-day exploitation
          • The ShinyHunters extortion group is attributed to the attack, which also targeted NAIC in a separate but related incident
          • The breach follows a pattern of Oracle PeopleSoft exploitation hitting multiple large organizations, suggesting a coordinated campaign
          • πŸ“– Read full article

            Insurance giant Aflac discloses data breach after subsidiary hack

            BleepingComputer Β· Jun 30 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

            Why it matters to CISOs: Aflac's breach via a Japan subsidiary underscores the persistent risk of subsidiary and international entity security gaps creating enterprise-wide exposure, particularly for personal and financial data subject to cross-border regulatory obligations.

            • Aflac disclosed attackers breached its Japan subsidiary and stole personal and bank account information
            • The incident highlights subsidiary security as a major attack vector for large multinational enterprises
            • Financial data exposure in Japan triggers obligations under Japan's Act on the Protection of Personal Information (APPI) in addition to any U.S. reporting requirements
            • πŸ“– Read full article

              βš–οΈ Governance & Policy
              Justices rule that cellphone location histories are protected by the Fourth Amendment

              The Record (Recorded Future) Β· Jun 29 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

              Why it matters to CISOs: The Supreme Court's Chatrie ruling requiring warrants for geofence location data materially changes how enterprises must respond to law enforcement data requests and may affect data retention policies for any systems that collect or process location information at scale.

              • The U.S. Supreme Court ruled that police must obtain a warrant before requesting geofence data involving individual cellphones
              • The ruling extends Fourth Amendment protections to location history data held by third parties, reversing prior third-party doctrine application
              • Dissenting justices described the ruling as having 'seismic' implications for the Fourth Amendment, signaling broad downstream legal and compliance consequences
              • πŸ“– Read full article

                Warner bill would create federally vetted list for secure, trustworthy AI agents

                CyberScoop Β· Jun 29 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                Why it matters to CISOs: Senator Warner's draft AI Agent Act would require FTC-vetted certification for AI agent software vendors, creating a potential new compliance layer for enterprises procuring or deploying AI agents and putting AI vendor due diligence directly on security and procurement teams.

                • The bill would empower the FTC to create a registry certifying AI agent software sellers on privacy and cybersecurity protections
                • Organizations purchasing non-registered AI agents could face regulatory exposure under the proposed framework
                • The bill signals growing congressional intent to regulate AI agent deployments at the enterprise level, likely influencing future procurement standards
                • πŸ“– Read full article

                  🚨 Critical Vulnerability
                  CISA: Windows BlueHammer flaw now exploited by ransomware gangs

                  BleepingComputer Β· Jun 30 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                  Why it matters to CISOs: CISA confirmation of active ransomware exploitation of a Windows Defender privilege escalation vulnerability means every enterprise Windows environment is at risk; immediate patch validation and threat hunting are warranted given the ransomware delivery vector.

                  • CISA has confirmed ransomware gangs are now actively exploiting the BlueHammer Microsoft Defender privilege escalation vulnerability
                  • The flaw was previously used in zero-day attacks before ransomware operators adopted it, indicating rapid weaponization
                  • Windows Defender is deployed across virtually all enterprise Windows environments, giving this flaw near-universal exposure
                  • πŸ“– Read full article

                    Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer

                    The Hacker News Β· Jun 30 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                    Why it matters to CISOs: A CVSS 10.0 authentication bypass in SimpleHelp RMMβ€”widely used by MSPs managing enterprise environmentsβ€”is being actively exploited to deliver a cross-platform stealer targeting cloud, AI, and DevOps credentials, creating supply chain exposure for any enterprise relying on managed service providers.

                    • CVE-2026-48558 is a CVSS 10.0 authentication bypass in SimpleHelp RMM actively exploited to drop Djinn Stealer and TaskWeaver malware
                    • Djinn Stealer targets credentials for cloud platforms, source control, package registries, AI development tools, browsers, SSH, and cryptocurrency wallets across Windows, macOS, and Linux
                    • Organizations using MSPs that run SimpleHelp are at indirect risk even if they do not directly operate the software themselves
                    • πŸ“– Read full article

                      Further Reading
                      • 🌍 US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp β€” The Record (Recorded Future)
                      • 🌍 Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks β€” The Hacker News
                      • πŸ“‘ The attack that hijacked Claude Code came through Sentry. Datadog, PagerDuty, and Jira have the same exposure. β€” VentureBeat Security
                      • πŸ”“ Hackers now exploit critical Oracle E-Business flaw in attacks β€” BleepingComputer
                      • πŸ”“ Nissan discloses employee data breach linked to Oracle zero-day attacks β€” BleepingComputer
                      • πŸ”“ Insurance giant Aflac discloses data breach after subsidiary hack β€” BleepingComputer
                      • βš–οΈ Justices rule that cellphone location histories are protected by the Fourth Amendment β€” The Record (Recorded Future)
                      • βš–οΈ Warner bill would create federally vetted list for secure, trustworthy AI agents β€” CyberScoop
                      • 🚨 CISA: Windows BlueHammer flaw now exploited by ransomware gangs β€” BleepingComputer
                      • 🚨 Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer β€” The Hacker News
                      • Full Transcript
                        Click to expand full episode transcript

                        Alex: Welcome to Cleartext for Tuesday, June 30th, 2026. I'm Alex Chen.

                        Jordan: And I'm Jordan Reeves.

                        Jordan: So here's where we're starting today. Sentry, the error monitoring tool that lives in basically every modern dev shop, was used to hijack AI coding agents. Claude Code, Cursor, Codex. A single crafted error event, sent through a public credential, and the agent executes attacker instructions with full developer privileges. Eighty-five percent success rate in testing. EDR didn't catch it. WAF didn't catch it. IAM didn't catch it. Sentry's own response was, and I'm quoting here, "technically not defensible." That's the phrase that should keep you up tonight.

                        Alex: That is a hell of a way to start the show. We're going to dig into that one. We've also got active ransomware exploitation of a Windows Defender flaw that CISA just flagged, a ten-million-dollar bounty on Russian hackers targeting Signal and WhatsApp, Oracle E-Business Suite under active attack, Nissan disclosing a breach tied to Oracle PeopleSoft zero-days, Mustang Panda weaponizing Zoho WorkDrive against India, a Supreme Court ruling that's going to change how you handle law enforcement data requests, and a Senate bill that wants to create a federal registry for AI agents. It's a packed day. Let's get into it.

                        Alex: Jordan, let's start with the agentjacking story because this feels like a category-defining moment for anyone deploying agentic AI in their development pipeline.

                        Jordan: It is. And the reason I led with it is that this isn't a theoretical attack. Tenet Security demonstrated it. The Cloud Security Alliance has already classified agentjacking as a systemic MCP vulnerability class. The attack surface here is every integration point between an AI coding agent and the tools it consumes data from. Sentry, Datadog, PagerDuty, Jira. These are all tools that feed context into agentic workflows. An attacker poisons that context, and the agent treats it as legitimate instruction. There's no malware signature to detect. There's no anomalous network traffic. The agent is doing exactly what it's designed to do, just with instructions from the wrong person.

                        Alex: And this is the part that boards need to understand. We've spent decades building security architectures around the assumption that humans read the input and make decisions. AI agents don't have that filter. They ingest and execute. So every data source that feeds an agent is now a trust boundary, and most organizations haven't mapped those boundaries, let alone defended them.

                        Jordan: Right. And the fix isn't simple. You can't just patch Sentry. The problem is architectural. If your AI agent trusts data from any external system without verification, you have this exposure. Period. The practical step right now is inventory. Know which AI agents are running in your environment, what data sources they consume, and what privileges they hold. If you can't answer those three questions, you have an unmanaged risk.

                        Alex: And I'd add, if you're in a board conversation about AI productivity gains, this is the counter-narrative you need to present. The productivity comes with a new threat surface that existing controls don't address. Budget accordingly.

                        Jordan: Let's pivot to the geopolitical block because we've got two stories that rhyme in important ways. First, the State Department posting a ten-million-dollar reward for information on UNC5792 and UNC4221, two Russian groups that have been compromising government officials' Signal and WhatsApp accounts through social engineering.

                        Alex: The CISO takeaway here isn't just about government targets. If your executives communicate sensitive business information over Signal or WhatsApp, and let's be honest, they all do, you need to treat those platforms as part of your attack surface. The fact that nation-state actors are specifically targeting secure messaging apps tells you something. These apps are where the high-value conversations happen, and adversaries know it.

                        Jordan: And the attack vector is social engineering, not cryptographic compromise. They're not breaking Signal's encryption. They're tricking people into linking devices or approving access. So your technical controls on the app itself are irrelevant. This is about user awareness and, frankly, about whether your mobile device policy even acknowledges that these apps exist in your environment.

                        Alex: Most don't. And that's the gap. You've got executives using personal devices running consumer messaging apps for board-level discussions, M&A conversations, regulatory strategy. None of it's in your MDM. None of it's in your DLP. And now you've got Russian intelligence services actively targeting that exact blind spot.

                        Jordan: The second geopolitical story is Mustang Panda, China-aligned, running espionage campaigns against Indian government networks and using Zoho WorkDrive as their command-and-control channel. This is the living-off-trusted-services play. Malicious traffic blends perfectly with legitimate SaaS communications.

                        Alex: This is a trend that's been building for two years, and it's now fully mature. When your C2 traffic looks like a file sync to Zoho or OneDrive or Google Drive, your network-based detection is effectively blind. The implication for CISOs is that you need behavioral analytics at the endpoint level, not just network monitoring. And you need to seriously evaluate which SaaS platforms are allowed to communicate with sensitive segments of your environment.

                        Jordan: They're also deploying new malware families, which tells you Mustang Panda is investing in capability development. This isn't a one-off campaign. It's an ongoing program with resources behind it. If your organization operates in South or Southeast Asia or has supply chain exposure there, this is directly relevant.

                        Alex: Now let's talk Oracle, because we essentially have two Oracle stories that together paint a pretty alarming picture. First, CVE-2026-46817, a CVSS 9.8 in Oracle E-Business Suite's Payments module, actively exploited in the wild. Authentication bypass, privilege management bypass, full instance takeover potential.

                        Jordan: If you run Oracle EBS, and thousands of large enterprises do, this is a drop-everything-and-patch situation. The Payments module means financial data integrity is directly at risk. And the CVSS score isn't theoretical. This is being exploited now, in production, against real targets.

                        Alex: And then we have Nissan disclosing a breach of employee data tied to Oracle PeopleSoft zero-day exploitation, attributed to ShinyHunters. This is the same attack vector that hit NAIC. It looks coordinated, a campaign targeting PeopleSoft instances across multiple large organizations.

                        Jordan: ShinyHunters is an extortion group. So expect the data to surface on leak sites if ransom demands aren't met. For CISOs running PeopleSoft, the question isn't whether you're a target. It's whether you've already been compromised and don't know it yet. Patch, then threat-hunt. In that order.

                        Alex: On the breach front, we also have Aflac disclosing that attackers compromised its Japan subsidiary and stole personal and bank account information. This is the perennial subsidiary risk story. Your security posture is only as strong as your weakest international entity.

                        Jordan: And Japan's APPI has teeth. Cross-border data breach obligations are real. If you're a multinational, your subsidiary governance model is either a security program or it's a liability. There's no middle ground anymore.

                        Alex: Let's hit the two vulnerability stories. Jordan, BlueHammer first.

                        Jordan: CISA confirmed Monday that ransomware gangs are actively exploiting a Windows Defender privilege escalation vulnerability they're calling BlueHammer. This was a zero-day before ransomware operators picked it up, and now it's in active ransomware campaigns. Windows Defender is on virtually every enterprise Windows endpoint. This is near-universal exposure. Validate your patches. If you're behind on the June cycle, this one alone justifies emergency remediation.

                        Alex: And SimpleHelp?

                        Jordan: CVE-2026-48558. CVSS 10. Authentication bypass in SimpleHelp's remote monitoring and management platform. Actively exploited to drop a cross-platform stealer called Djinn that targets cloud credentials, source control tokens, AI development tool keys, SSH keys, the whole crown jewels inventory. Here's the wrinkle: SimpleHelp is widely used by managed service providers. So even if you don't run it yourself, your MSP might. And that makes this a supply chain problem. Ask your MSPs today whether they use SimpleHelp and whether they've patched.

                        Alex: Good. Two governance stories to close out the segments. The Supreme Court ruled in Chatrie that police need a warrant to request geofence location data from third parties. This reverses the prior third-party doctrine application for location data.

                        Jordan: The dissent called it "seismic," and they're not wrong. For CISOs, the practical impact is on how you handle law enforcement data requests. If your systems collect or process location data at scale, and many enterprise apps do, your legal and compliance teams need to update their response playbooks. You may also want to revisit data retention policies for location information. Less data retained means less data to argue about in court.

                        Alex: And finally, Senator Warner's draft AI Agent Act, which would empower the FTC to create a registry certifying AI agent software vendors on privacy and cybersecurity protections. If you're procuring or deploying AI agents, this bill signals where the regulatory wind is blowing.

                        Jordan: It's a draft. It hasn't passed. But the direction is clear. Congress wants a compliance layer around AI agent procurement. If your organization is buying AI agent capabilities today, start documenting your vendor due diligence now. When the regulation lands, and some version of it will, you don't want to be scrambling.

                        Alex: Let's zoom out for the outlook. Jordan, what's the thread you're pulling on this week?

                        Jordan: Trust boundaries. Every major story today is fundamentally about trust boundaries being violated or redefined. AI agents trusting poisoned data from observability tools. Secure messaging apps being compromised through social engineering. Legitimate SaaS platforms being weaponized as C2 channels. Subsidiaries creating enterprise-wide exposure. MSP tools becoming supply chain attack vectors. The common theme is that the things we implicitly trust, our tools, our vendors, our subsidiaries, our communication platforms, are exactly what adversaries are targeting. The 2026 CISO challenge is making trust explicit and verifiable rather than assumed.

                        Alex: I'd add the governance dimension. Between the Supreme Court ruling and the Warner bill, we're seeing the legal and regulatory framework trying to catch up with these same trust questions. Who can access what data under what conditions? Who's accountable when an AI agent acts on bad input? These aren't abstract policy debates anymore. They're operational questions that land on the CISO's desk. If you're not already embedded in your organization's legal and policy conversations about AI and data governance, you're behind.

                        Jordan: And I'll leave listeners with one tactical takeaway: this week, map your AI agent integrations. Every tool that feeds data to an AI agent in your environment is a potential injection point. If you don't have that inventory, building it is your highest-leverage activity this week.

                        Alex: That's Cleartext for Tuesday, June 30th, 2026. Show notes and links to every story we covered today are at cleartext.fm. I'm Alex Chen.

                        Jordan: I'm Jordan Reeves. We'll see you tomorrow.

                        Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-30.

                        Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                        ...more
                        View all episodesView all episodes
                        Download on the App Store

                        CleartextBy Cleartext