Cleartext – June 20, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 17 stories across 5 topic areas, including: Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails; Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns; Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites.
Stories Covered
🌍 Geopolitical
Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
The Hacker News · Jun 15 · Relevance: █████████░ 9/10
Why it matters to CISOs: UNC6508 spent over a year undetected inside North American medical, academic, and defense research networks by weaponizing the victims' own Google Workspace mail-forwarding rules — a living-off-the-land technique that bypasses most SIEM detection. Any organization running REDCap or sharing research data with defense agencies should treat this as a direct threat model.
China-linked group UNC6508 lurked undetected since 2023 in medical, academic, and military research networksEntry was via backdoored REDCap servers; exfiltration used victims' own Google Workspace forwarding rules to silently copy emailsGoogle's Threat Intelligence Group discovered and disrupted the campaign; targeted sectors include defense contractorsHostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns
The Record (Recorded Future) · Jun 17 · Relevance: ████████░░ 8/10
Why it matters to CISOs: NCSC CEO Richard Horne's explicit warning that nation-states are pre-positioning inside critical infrastructure for future kinetic conflict is a board-level strategic signal, not just a tactical advisory. CISOs in energy, water, transport, and defense supply chains should use this framing to elevate resilience investment conversations.
75% of consequential cyberattacks on UK critical infrastructure are attributed to nation-state actors, per NCSC CEO Richard HorneHorne warned adversaries are 'prepositioning' inside networks to enable future kinetic conflict targetingUK's NCSC is urging business leaders and authorities to fundamentally rethink critical infrastructure protectionOperation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
The Hacker News · Jun 19 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The takedown of Evil Corp's SocGholish infrastructure — 106 servers and nearly 15,000 compromised WordPress sites — is a significant disruption to a major initial-access broker used by ransomware affiliates. CISOs should use this moment to audit web supplier estates and verify no SocGholish indicators persist in their environments.
International law enforcement from Netherlands, Canada, Germany, and U.S. disrupted SocGholish botnet linked to Russia's Evil Corp106 servers taken down and 14,971 infected WordPress sites remediatedSocGholish served as a primary initial-access vector for multiple ransomware operationsCalifornia water utility probes breach claim by Iran-linked actor
Cybersecurity Dive · Jun 17 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Iran-linked group Handala claiming an attack on one of the largest U.S. water utilities underscores the active targeting of civilian critical infrastructure by state-sponsored actors — a risk CISOs at utilities and their OT/ICS vendors must plan for explicitly in incident response tabletops.
Iran-linked threat group Handala claimed responsibility for breaching a major California water utilityThe utility confirmed it is investigating the breach claimAttack follows a broader pattern of Iranian actors targeting U.S. water and energy infrastructure🔓 Data Breach
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
The Hacker News · Jun 19 · Relevance: █████████░ 9/10
Why it matters to CISOs: The Klue incident is the third Salesforce-connected app compromised this year via OAuth token abuse, demonstrating that third-party SaaS integrations are now a primary attack vector against CRM data. CISOs should audit every OAuth app connected to Salesforce and other critical platforms immediately.
Threat actor group 'Icarus' stole OAuth tokens from Klue, enabling access to customer Salesforce environmentsSalesforce disabled the Klue Battlecards integration entirely; affected organizations include cybersecurity vendor HuntressThis is the third integrated app compromised to steal Salesforce data in a pattern of supply-chain OAuth attacksTexas govt data breach exposes over 3 million driver’s licenses
BleepingComputer · Jun 19 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A breach at a third-party license vendor exposing 3 million government-issued IDs — including passports — illustrates the persistent risk of state and local government's dependence on under-secured SaaS vendors for identity-critical data. CISOs supporting government contracts or housing similar identity data should review vendor risk posture.
Texas Parks and Wildlife Department disclosed a breach at its license system vendor exposing personal data for over 3 million individualsStolen data includes driver's licenses and passport informationBreach originated at a third-party vendor, not TPWD's own systemsNovo Nordisk Breach Exposes Software Development Pipeline Risk
Dark Reading · Jun 18 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Novo Nordisk's breach via a leaked GitHub token reframes secrets management from a developer tooling issue into an identity governance problem that belongs in the CISO's purview. With supply-chain attacks accelerating — including the Mastra npm compromise and TeamPCP campaigns this week — secure-by-design CI/CD pipelines are now a board-reportable risk.
A leaked GitHub token gave attackers access to Novo Nordisk's software development pipelineAnalysis frames the root cause as treating secrets management as a tooling problem rather than an identity problemIncident is part of a broader week of supply-chain attacks including 145 compromised Mastra npm packages⚖️ Governance & Policy
‘Dangerous’ AI Models Are Coming No Matter What
Wired Security · Jun 16 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The U.S. government's export controls on Anthropic's Fable 5 and Mythos 5 — opposed by dozens of CISOs in an open letter — raises a foundational strategic question: whether restricting defensive AI tools slows defenders more than attackers. Security leaders need a position on this for both vendor and regulatory engagement.
Trump administration placed export controls on Anthropic's Claude Fable 5 and Mythos 5 cybersecurity-focused AI modelsDozens of CISOs and security researchers signed an open letter calling the ban 'dangerous' to defendersExperts argue AI models with advanced hacking capabilities will proliferate regardless, disadvantaging defenders who face restrictionsSecurity Community Slams US Ban on Exporting Mythos, Fable
Dark Reading · Jun 16 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The organized pushback from the security community — including an open letter from senior practitioners — signals that AI export controls are becoming a significant policy battleground that will shape which defensive tools CISOs can deploy for global teams. This is a regulatory risk to track for multinational security programs.
An open letter signed by dozens of security experts called on the government to reverse restrictions on Mythos 5 and Fable 5Critics argue restrictions impair blue-team use of AI for vulnerability discovery and secure code reviewCongressional members expressed unease, with some calling for more information before supporting the orderAI Inherits People's Permissions but Not Judgment
BankInfoSecurity · Jun 20 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: New CISO research confirming that most enterprises cannot track what AI agents are accessing — despite those agents operating with full user-level permissions — is an identity governance gap that existing IAM and PAM programs were not designed to close. This is the foundational control problem underlying the AutoJack and SearchLeak disclosures this week.
AI agents inherit user permissions but apply no human judgment, creating machine-speed risk from existing data access gapsCISO research shows most organizations lack visibility into what AI systems are accessingControls built for humans — pauses, filtering, contextual judgment — do not apply to AI agentsMost CISOs Report Pressure to Bury Bad Security News
Dark Reading · Jun 15 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: With SEC disclosure rules now in force and DOJ prosecuting CISOs for concealment, the finding that most CISOs feel organizational pressure to suppress bad security news is a direct personal and legal liability signal. CISOs need explicit board-level mandates protecting their ability to disclose accurately and on time.
A majority of surveyed CISOs report experiencing pressure from executive leadership to delay or downplay security incident disclosuresBusiness objectives and priorities were cited as the primary driver of suppression pressureThe dynamic creates direct legal exposure for CISOs under SEC and DOJ enforcement frameworks🚀 Startup Ecosystem
Accenture to buy Dragos, runZero, and NetRise in $4.2 billion cybersecurity deal
Help Net Security · Jun 19 · Relevance: █████████░ 9/10
Why it matters to CISOs: This is the largest OT/ICS security acquisition in the industry's history; it consolidates three complementary asset-visibility and threat-detection platforms under a global consulting giant at a moment when critical infrastructure attacks are surging. CISOs at industrial organizations should expect significant product roadmap and support changes at Dragos, runZero, and NetRise.
Accenture is acquiring a majority stake in Dragos and full ownership of runZero and NetRise for $4.18 billionThe deal is framed as Accenture's first major push into OT security software amid AI-driven critical infrastructure threatsThe combined platform will cover power grids, pipelines, manufacturing, and data center environmentsAccenture shells out $4.18B on three companies in big industrial cybersecurity push
CyberScoop · Jun 18 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Accenture's simultaneous acquisition of Dragos, runZero, and NetRise consolidates the leading OT asset discovery, firmware analysis, and threat detection platforms into a single managed-services wrapper — a move that could reshape how enterprise CISOs procure and operate OT security programs.
Deal valued at approximately $4.18 billion, Accenture's first major OT security software pushDragos platform will expand to cover the full extended OT environment; runZero and NetRise add network discovery and firmware risk capabilitiesTiming coincides with intensifying AI-driven threats to critical infrastructure globally🚨 Critical Vulnerability
CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices
The Hacker News · Jun 19 · Relevance: █████████░ 9/10
Why it matters to CISOs: Russian-speaking threat actors have compromised nearly 87,000 FortiGate devices in an active campaign dubbed FortiBleed; any enterprise running Fortinet perimeter gear must treat this as an emergency patching and credential-reset event. CISA's formal warning combined with active FortiSandbox exploitation this same week signals a coordinated targeting of Fortinet's entire product line.
86,644 FortiGate devices confirmed compromised in campaign attributed to Russian-speaking actorsCISA issued an emergency advisory urging immediate remediation stepsFortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) also under active exploitation the same weekUnauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)
Help Net Security · Jun 19 · Relevance: █████████░ 9/10
Why it matters to CISOs: Splunk is a crown-jewel security operations platform; unauthenticated RCE in it means attackers can potentially pivot from the SIEM into every integrated environment. CISA's order to patch by June 21 leaves federal CISOs almost no runway and sets the urgency bar for enterprise security teams.
CVE-2026-20253 is a critical unauthenticated RCE in Splunk Enterprise confirmed exploited in the wildCISA added it to the KEV catalog and ordered federal agencies to patch by June 21, 2026Full system compromise is possible; organizations must also review systems for indicators of compromiseOne-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
The Hacker News · Jun 15 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The SearchLeak exploit chain demonstrates that enterprise AI assistants like Copilot introduce novel exfiltration paths that bypass traditional email security and URL filtering — CISOs running M365 Copilot Enterprise Search must validate that Varonis's disclosed CVEs are fully patched and review Copilot's data access scope.
Varonis chained three bugs (CVE-2026-42824) into 'SearchLeak,' a one-click exfiltration path from Microsoft 365 Copilot Enterprise SearchA victim clicking a crafted microsoft.com URL triggered Copilot to search mailboxes and exfiltrate data via Bing SSRF — no plugins or second click requiredTraditional anti-phishing and URL filtering tools were ineffective because the link pointed to a legitimate Microsoft domainAutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution
The Hacker News · Jun 19 · Relevance: ████████░░ 8/10
Why it matters to CISOs: AutoJack is the first publicly documented exploit chain turning an AI browsing agent into a remote code execution vector via a malicious web page — with no credentials or user interaction required after initial page load. CISOs deploying agentic AI for business process automation must treat agent sandboxing and privilege isolation as a critical control.
Microsoft researchers documented 'AutoJack,' where a malicious web page's JavaScript hijacks an AI browsing agent to reach a privileged local service and spawn processes on the hostAttack requires no credentials, no sign-in, and no further user interaction once the agent loads the attacker's pageHighlights the absence of trust boundaries in enterprise AI systems that accept external inputFurther Reading
🌍 Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails — The Hacker News🌍 Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns — The Record (Recorded Future)🌍 Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites — The Hacker News🌍 California water utility probes breach claim by Iran-linked actor — Cybersecurity Dive🔓 Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data — The Hacker News🔓 Texas govt data breach exposes over 3 million driver’s licenses — BleepingComputer🔓 Novo Nordisk Breach Exposes Software Development Pipeline Risk — Dark Reading⚖️ ‘Dangerous’ AI Models Are Coming No Matter What — Wired Security⚖️ Security Community Slams US Ban on Exporting Mythos, Fable — Dark Reading⚖️ AI Inherits People's Permissions but Not Judgment — BankInfoSecurity⚖️ Most CISOs Report Pressure to Bury Bad Security News — Dark Reading🚀 Accenture to buy Dragos, runZero, and NetRise in $4.2 billion cybersecurity deal — Help Net Security🚀 Accenture shells out $4.18B on three companies in big industrial cybersecurity push — CyberScoop🚨 CISA Warns Fortinet Customers as FortiBleed Hits 86,644 FortiGate Devices — The Hacker News🚨 Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) — Help Net Security🚨 One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes — The Hacker News🚨 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution — The Hacker NewsFull Transcript
Click to expand full episode transcript
Alex: Welcome back to Cleartext. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. This is your Saturday Week in Review for the week ending June 20th, 2026.
Jordan: If I had to distill this entire week into a single sentence, it would be this: the things you trust most are the things being used against you. Your Google Workspace rules, your Salesforce OAuth tokens, your Splunk SIEM, your AI copilot, your Fortinet perimeter. Every one of those became an attack surface this week. Not because they're broken, but because adversaries have figured out that living inside your trusted infrastructure is more effective than trying to break through it.
Alex: That's exactly the thread. So if you couldn't keep up this week, here's what mattered and what it means. We're going to cover four themes. First, the nation-state infrastructure story, which is no longer theoretical. Second, the trust chain collapse, where your own tools and integrations became the attack path. Third, AI as both a weapon and a policy battleground. And fourth, a massive acquisition that's going to reshape OT security procurement for years. Let's get into it.
Jordan: So let's start with the geopolitical picture because this was a week where three distinct stories painted a very coherent, very uncomfortable picture. Google's Threat Intelligence Group disclosed that a China-linked group, UNC6508, had been sitting inside North American medical, academic, and defense research networks since 2023. Over a year undetected. And the tradecraft here is what matters. They got in through backdoored REDCap servers, which is a research data platform that's everywhere in clinical and academic environments. But the exfiltration method was almost elegant in its simplicity. They rewrote the victims' own Google Workspace mail forwarding rules to silently copy messages out.
Alex: And this is the part that should make every CISO uncomfortable. This isn't some exotic zero-day chain. This is a configuration change in a productivity suite that most security teams aren't monitoring with the granularity required to catch it. How many of your organizations are auditing Google Workspace mail routing rules as part of your threat detection program? I'd bet the number is vanishingly small. And if you're in a sector that touches defense research, clinical trials, anything with dual-use implications, this is your threat model right now.
Jordan: The same day that story was developing, NCSC CEO Richard Horne gave a speech at RUSI that was remarkably blunt for a sitting intelligence chief. He said, and I'm paraphrasing only slightly, that kinetic targeting in any future conflict will be based on intelligence gathered today, and that nation-state adversaries are actively prepositioning inside British critical infrastructure. Seventy-five percent of consequential attacks on UK critical infrastructure are now attributed to nation-states. Three-quarters.
Alex: And he wasn't being abstract. He was directly telling business leaders to fundamentally rethink how they protect critical infrastructure. This is the kind of language that should show up in your next board presentation verbatim. When the head of the UK's national cyber center is saying that adversaries are already inside positioning for future conflict, that reframes your resilience investment from cybersecurity spending to national security preparedness. Those are different budget conversations.
Jordan: And then to round out the picture, we had an Iran-linked group called Handala claiming a breach at a major California water utility. The utility confirmed it's investigating. This follows the pattern we've been tracking for two years now: Iranian actors targeting U.S. water and energy infrastructure. These aren't espionage operations. These are capability demonstrations. They're proving they can reach civilian infrastructure, and they want us to know it.
Alex: The bright spot in this theme was Operation Endgame. Dutch, Canadian, German, and U.S. law enforcement took down 106 servers tied to Evil Corp's SocGholish botnet and remediated nearly fifteen thousand compromised WordPress sites. SocGholish was a major initial access broker feeding ransomware affiliates, so this is meaningful disruption. But I want to be clear about what this is and isn't. This is a temporary setback for one operation. The infrastructure will reconstitute. The value here is the intelligence gathered and the signal it sends that law enforcement is willing to invest in sustained disruption campaigns.
Jordan: Agreed. And CISOs should use this moment practically. Audit your web supply chain for SocGholish indicators. Check your WordPress-based vendor estates. The fifteen thousand compromised sites that were cleaned up had been serving malicious redirects, and some of them were probably in your users' browsing paths.
Alex: Let's move to what I'm calling the trust chain collapse, because this was the week it became undeniable that third-party integrations and your own security tools are the primary attack surface. The Klue incident is Exhibit A. A threat actor group called Icarus stole OAuth tokens from Klue, a competitive intelligence platform, and used those tokens to access customer Salesforce environments. Salesforce killed the integration entirely. And here's the number that should alarm you: this is the third Salesforce-connected app compromised via OAuth token abuse this year. Third.
Jordan: The pattern is clear and it's not going away. Your Salesforce instance doesn't get breached directly. It gets breached through the twenty, thirty, fifty OAuth-connected apps that have persistent access to your CRM data. And most security teams have no inventory of those connections, let alone monitoring on what they're accessing. If you haven't done a full OAuth app audit on Salesforce, ServiceNow, and your other critical SaaS platforms, this is the week you start.
Alex: The Texas Parks and Wildlife breach follows the same pattern at the government level. Three million driver's licenses and passport records exposed, not through the state agency's own systems, but through a third-party licensing vendor. The vendor was the weak link. And this is the challenge for any CISO supporting government contracts or holding identity-critical data: your security posture is only as strong as your least mature vendor.
Jordan: And then Novo Nordisk got breached via a leaked GitHub token that gave attackers access to their development pipeline. Dark Reading's framing was exactly right: this is an identity governance problem, not a developer tooling problem. Secrets management has been treated as something the engineering team handles with their own tools, and it needs to be pulled into the CISO's identity governance program. The same week, we saw a hundred forty-five compromised Mastra npm packages. The supply chain is under coordinated pressure.
Alex: Now let's talk about the vulnerabilities that hit this week, because two of them are genuinely hair-on-fire. FortiBleed. Russian-speaking actors have compromised eighty-six thousand six hundred forty-four FortiGate devices in an active campaign. CISA issued an emergency advisory. And in the same week, three FortiSandbox CVEs came under active exploitation. This looks like coordinated targeting of Fortinet's entire product line. If you're running Fortinet on your perimeter, this is an emergency patching and credential reset event. Full stop.
Jordan: And then there's CVE-2026-20253. Unauthenticated remote code execution in Splunk Enterprise, confirmed exploited in the wild. I want to let that sink in. Splunk. Your SIEM. The thing that's supposed to be watching everything. It has an unauthenticated RCE that attackers are actively exploiting. CISA ordered federal agencies to patch by June 21st, which is tomorrow. That's almost no runway. If you're running Splunk Enterprise, assume you're in scope and act accordingly.
Alex: This connects directly to Jordan's opening point. When your security monitoring platform itself becomes the attack vector, the trust assumptions underlying your entire detection architecture need to be reexamined.
Jordan: Which brings us to AI, and this was a big week on multiple fronts. Let's start with the attacks. Microsoft researchers documented AutoJack, which is the first publicly documented exploit chain that turns an AI browsing agent into a remote code execution vector. A malicious web page's JavaScript hijacks the AI agent, reaches a privileged local service, and spawns a process on the host. No credentials required. No further user interaction after the page loads. If you're deploying agentic AI for business process automation, this is the attack you need to model against.
Alex: And Varonis disclosed SearchLeak, a one-click exfiltration chain against Microsoft 365 Copilot Enterprise Search. A victim clicks what looks like a legitimate microsoft.com URL, Copilot searches their mailbox, and data gets exfiltrated via a Bing server-side request forgery. Traditional anti-phishing tools couldn't catch it because the domain was legitimate. These two disclosures, combined with the BankInfoSecurity research showing most enterprises can't even track what their AI agents are accessing, paint a very clear picture: we are deploying AI with human-level permissions and zero human-level judgment, and our existing IAM and PAM controls were never designed for this.
Jordan: On the policy front, the Trump administration placed export controls on Anthropic's Claude Fable 5 and Mythos 5, which are cybersecurity-focused AI models. Dozens of CISOs and security researchers signed an open letter calling this dangerous to defenders. The argument is straightforward: offensive AI capabilities will proliferate regardless, and restricting the models that defenders use for vulnerability discovery and secure code review just creates asymmetry that favors attackers. If you run a multinational security program, this is a regulatory risk you need to be tracking because it will determine which AI tools your global teams can deploy.
Alex: And for the market-moving story of the week. Accenture announced a four-point-eighteen-billion-dollar deal to acquire a majority stake in Dragos and full ownership of runZero and NetRise. This is the largest OT security acquisition in the industry's history, and it's happening at exactly the moment when critical infrastructure attacks are surging. If you're a Dragos, runZero, or NetRise customer, expect product roadmap changes, support model changes, and likely a push toward Accenture's managed services wrapper. Start planning for that conversation now.
Jordan: The timing is not coincidental. Accenture is reading the same threat landscape we just walked through. Nation-states prepositioning in critical infrastructure, Iranian actors hitting water utilities, coordinated campaigns against network perimeter devices. OT security just became a four-billion-dollar bet by one of the world's largest consulting firms.
Alex: So stepping back, what defined this week? I think it's the collapse of implicit trust. Every story we covered, from Google Workspace forwarding rules to Salesforce OAuth tokens to Splunk and Fortinet to AI agents acting with user permissions, the common thread is that attackers are exploiting the trust we place in our own tools and integrations. The perimeter isn't just the firewall anymore. It's every API connection, every OAuth token, every AI agent, every configuration rule in every SaaS platform.
Jordan: And the uncomfortable corollary is that your detection architecture was built on the assumption that your own tools are trustworthy. When the SIEM has an unauthenticated RCE, when the AI copilot is an exfiltration path, when the firewall vendor's entire product line is under coordinated attack, you need to rethink what you're trusting and why. Going into next week, I'd prioritize three things: audit every OAuth integration on your critical SaaS platforms, verify your Fortinet and Splunk patching status as of today, and start the conversation with your board about what the NCSC's prepositioning warning means for your resilience investment.
Alex: Well said. The daily show returns Monday. All the stories we referenced today, with links and context, are at cleartext.fm. Thanks for spending part of your weekend with us.
Jordan: Stay sharp. See you Monday.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-20.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.