Cleartext

Cleartext Week in Review – July 18, 2026


Listen Later

Cleartext – July 18, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 18 stories across 5 topic areas, including: Leading members of Scattered Spider sentenced in UK to 66 months in jail; Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime; The US government warns that Russia state hackers are coming after your router.

Stories Covered
🌍 Geopolitical
Leading members of Scattered Spider sentenced in UK to 66 months in jail

CyberScoop Β· Jul 17 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

Why it matters to CISOs: The first significant prison sentences for Scattered Spider members send a deterrence signal to English-speaking cybercrime collectives and validate the UK-US law enforcement coordination model, which CISOs can reference when advocating for incident reporting and law enforcement engagement.

  • Thalha Jubair (20) and Owen Flowers (18) sentenced to 66 months each at Woolwich Crown Court for the 2024 TfL hack
  • The TfL attack rendered 148 systems inoperable and forced all 27,000 employees to reset passwords in person, costing Β£29M
  • NCA credited the sentences with disrupting broader Scattered Spider operations; US previously linked Jubair to 120+ attacks
  • πŸ“– Read full article

    Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime

    CyberScoop Β· Jul 16 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

    Why it matters to CISOs: The unsealed indictment of Media Land and ML.Cloudβ€”core infrastructure providers for ransomware and cybercrime groupsβ€”disrupts a critical tier of the criminal supply chain and may degrade the reliability of attack infrastructure targeting enterprise environments.

    • Three Russian nationals charged for operating bulletproof hosting services supporting attacks across 21 US states with $62M+ in victim losses
    • Media Land and ML.Cloud provided resilient hosting specifically designed to evade law enforcement takedowns
    • Indictment was originally sealed in 2024 and unsealed this week, signaling a coordinated DOJ enforcement action
    • πŸ“– Read full article

      The US government warns that Russia state hackers are coming after your router

      Ars Technica Security Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

      Why it matters to CISOs: CISA's advisory on Russian APT targeting of consumer and SOHO routers as residential proxy infrastructure directly threatens enterprise perimeter defenses and VPN access controls, requiring immediate review of network edge policies and remote access assumptions.

      • CISA warns that Russian state-linked hackers are compromising residential and SOHO routers to build proxy infrastructure for further attacks
      • The technique allows adversaries to blend malicious traffic with legitimate residential IP ranges, defeating geo-blocking and IP reputation controls
      • The UK and EU jointly imposed sanctions on Russian individuals and entities for related cyberattack and disinformation campaigns
      • πŸ“– Read full article

        Now, even Russia's most elite hackers are using Clickfix to infect devices

        Ars Technica Security Β· Jul 16 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

        Why it matters to CISOs: The adoption of ClickFix social engineering by Russian nation-state APTsβ€”previously a financially-motivated criminal toolβ€”signals a blurring of TTPs between espionage and crime groups that requires enterprise security awareness programs to evolve accordingly.

        • Russian nation-state threat actors, previously focused on sophisticated technical exploits, are now leveraging ClickFix browser-based social engineering for initial access
        • ClickFix tricks users into manually executing malicious commands by posing as CAPTCHA or browser error fixes
        • The technique's adoption by elite APTs suggests it offers a reliable, low-cost initial access vector that bypasses many email and endpoint controls
        • πŸ“– Read full article

          Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says

          TechCrunch Security Β· Jul 14 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

          Why it matters to CISOs: Iran's exploitation of SS7/telecom protocol vulnerabilities to physically locate and target US military personnel represents a direct convergence of cyber and kinetic operations, with serious implications for mobile device security policies in high-risk operational environments.

          • Iranian government exploited well-known cellular network protocol vulnerabilities (SS7-class flaws) to geolocate US military personnel in the Middle East
          • The intelligence gathered was used in the lead-up to and during active military engagements
          • The incident demonstrates that telecom infrastructure weaknesses pose life-safety risks beyond traditional data breach scenarios
          • πŸ“– Read full article

            πŸ“‘ Macro Trends
            Identity Attacks Overtake Exploits as Top Ransomware Cause

            Dark Reading Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

            Why it matters to CISOs: With credential-based attacks now the leading ransomware entry vector and MFA failing in 97% of those cases, CISOs must fundamentally reassess their identity security posture beyond checkbox MFA deployment toward phishing-resistant authentication and continuous access verification.

            • Identity-based attacks (phishing, brute force, credential theft) have surpassed software exploits as the top ransomware initial access vector
            • MFA was deployed in 97% of credential-based ransomware attacks yet failed to prevent compromise in all measured cases
            • Sophos incident data underpins the findings, representing real-world enterprise breach analysis
            • πŸ“– Read full article

              OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

              The Hacker News Β· Jul 14 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

              Why it matters to CISOs: A novel OAuth spoofing technique allows adversaries to silently enumerate and validate stolen Entra ID credentials without generating sign-in events, rendering SIEM-based detection blind to a critical credential validation step in cloud account takeover chains.

              • At least two threat actor groups are actively weaponizing OAuth Client ID spoofing against Microsoft Entra ID environments
              • The technique validates stolen credentials without generating a successful sign-in log event, bypassing standard SIEM and UEBA detections
              • Organizations are advised to audit OAuth application registrations and review non-standard authentication telemetry sources immediately
              • πŸ“– Read full article

                Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim

                Infosecurity Magazine Β· Jul 16 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                Why it matters to CISOs: Research demonstrating that GPT-5.5 can autonomously execute a full attack chain from a single prompt is a board-level AI risk crystallization moment, requiring CISOs to accelerate AI acceptable-use policies and red-team AI-assisted threat scenarios.

                • Researchers demonstrated GPT-5.5 executing a complete cyber-attack chainβ€”reconnaissance through exploitationβ€”from a single natural-language prompt
                • The finding coincides with SANS Institute data showing a major AI governance gap between frontline security teams and senior leadership
                • Iran-linked and other state-nexus actors have already been documented using ChatGPT and similar tools for malware development and phishing at scale
                • πŸ“– Read full article

                  Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools

                  VentureBeat Security Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                  Why it matters to CISOs: Slopsquatting exploits AI coding assistant hallucinations to inject malicious packages into developer workflows from day one, representing a new supply chain attack vector that existing SCA and dependency-scanning tools are not designed to detect.

                  • AI coding assistants hallucinate nonexistent package names that attackers pre-register with malicious code, creating 'slopsquatting' supply chain attacks
                  • Unlike typosquatting, slopsquatting packages are installed by trusting developers following AI-generated instructions rather than human typing errors
                  • The attack vector is compounding as enterprise AI coding tool adoption accelerates without corresponding security guardrails
                  • πŸ“– Read full article

                    πŸ”“ Data Breach
                    Coca-Cola says Fairlife ransomware attack halts US dairy production

                    BleepingComputer Β· Jul 16 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                    Why it matters to CISOs: A ransomware attack disrupting physical production at a $1B+ subsidiary and triggering an SEC 8-K filing illustrates the direct OT/IT convergence risk and the regulatory disclosure obligations CISOs must now manage within hours of a confirmed incident.

                    • Ransomware at Coca-Cola's Fairlife unit halted all US dairy production operations; Canadian operations unaffected
                    • Coca-Cola filed an SEC Form 8-K disclosing the incident, underscoring mandatory public-company disclosure timelines
                    • The attack follows Fairlife surpassing $1B in retail sales, making it a high-value target with significant supply-chain impact
                    • πŸ“– Read full article

                      Abbott probes two cyber incidents amid extortion claims

                      BleepingComputer Β· Jul 17 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                      Why it matters to CISOs: Abbott's simultaneous exposure on two frontsβ€”a legacy system inherited from a $21B acquisition and an active extortion claim on a customer portalβ€”highlights M&A cyber due diligence failures and the compounding risk of integrating acquired IT estates.

                      • Unauthorized access confirmed to legacy Exact Sciences systems inside Abbott's Cancer Diagnostics business, acquired for $21B
                      • A separate extortion claim alleges breach of Abbott's LabCentral portal with data theft
                      • Abbott has not disclosed what categories of data were accessed in either incident
                      • πŸ“– Read full article

                        Ernst & Young discloses data breach after support system hack

                        BleepingComputer Β· Jul 17 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                        Why it matters to CISOs: A breach via a third-party IT support ticketing system at one of the Big Four audit firms underscores supply-chain and vendor access risk, particularly relevant to any enterprise that shares sensitive data through outsourced IT support channels.

                        • EY is notifying customers after attackers compromised a third-party support ticket system used by its IT personnel
                        • The breach originates in the vendor/support tier, not EY's core internal systems
                        • Incident adds to a pattern of professional services firms being targeted via peripheral third-party tooling
                        • πŸ“– Read full article

                          βš–οΈ Governance & Policy
                          White House details β€˜Gold Eagle’ clearinghouse for AI cyber threats

                          CyberScoop Β· Jul 14 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                          Why it matters to CISOs: The White House's Gold Eagle program creates a new federal coordination layer for AI-discovered vulnerabilities, potentially accelerating mandatory patch timelines and changing how enterprises receive and act on government threat intelligence.

                          • White House launched Gold Eagle to coordinate discovery, prioritization, and patching of AI-found vulnerabilities
                          • The clearinghouse has already begun receiving vulnerability intelligence and issuing prioritization guidance
                          • Implementation details remain unclear, raising questions about how private-sector enterprises will interface with the program
                          • πŸ“– Read full article

                            23andMe to pay $18 million in new genetics data breach settlement

                            BleepingComputer Β· Jul 16 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                            Why it matters to CISOs: The 43-state AG coalition settlement against 23andMe establishes a precedent for coordinated state enforcement against breaches of sensitive biometric and health data, and the mandated security controls will inform expectations for any enterprise handling similar data categories.

                            • 23andMe agreed to pay $18M to settle claims from 43 attorneys general over its 2023 genetic data breach
                            • Settlement includes mandatory enhanced data protection requirements beyond the financial penalty
                            • The multi-state AG action reflects an increasingly aggressive state-level enforcement posture on consumer health and genetic data privacy
                            • πŸ“– Read full article

                              Lessons Learned from CISA’s Recent GitHub Leak

                              Krebs on Security Β· Jul 13 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                              Why it matters to CISOs: CISA's postmortem on a contractor exposing AWS GovCloud keys in a public GitHub repo for six monthsβ€”discovered by a journalist, not internal controlsβ€”provides a directly transferable case study for hardening secrets management and contractor oversight programs.

                              • A CISA contractor published dozens of internal credentials including AWS GovCloud keys to a public GitHub repository
                              • The exposure persisted for nearly six months before KrebsOnSecurity notified CISA, not internal detection systems
                              • CISA's postmortem identified gaps in contractor oversight, secrets scanning, and initial incident response that apply broadly to enterprise programs
                              • πŸ“– Read full article

                                🚨 Critical Vulnerability
                                Microsoft Patches a Record 570 Security Flaws

                                Krebs on Security Β· Jul 14 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ 10/10

                                Why it matters to CISOs: AI-assisted vulnerability discovery has tripled Microsoft's patch volume in a single month, fundamentally breaking traditional patch triage workflows and demanding immediate reprioritization of remediation programs enterprise-wide.

                                • Microsoft patched 570+ CVEs in July Patch Tuesday, nearly triple June's prior record, with AI discovery credited for the surge
                                • Two zero-days are under active exploitation; more than 60 vulnerabilities are rated critical
                                • The volume increase signals a structural shift: AI will continue accelerating CVE discovery, making current patch cadences unsustainable
                                • πŸ“– Read full article

                                  Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

                                  The Hacker News Β· Jul 15 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                                  Why it matters to CISOs: Chained SonicWall SMA zero-days with a CVSS 10.0 SSRF flaw are being actively exploited by ransomware actors weeks before vendor disclosure, making any enterprise running SMA 1000 appliances an immediate priority for emergency patching or isolation.

                                  • CVE-2026-15409 carries a CVSS score of 10.0 and allows unauthenticated remote code execution via SSRF
                                  • Inc ransomware group is actively chaining the two flaws to achieve root-level access on SMA appliances
                                  • Exploitation began approximately three weeks before SonicWall disclosed and patched the vulnerabilities
                                  • πŸ“– Read full article

                                    CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

                                    The Hacker News Β· Jul 17 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                                    Why it matters to CISOs: A CVSS 9.8 SharePoint deserialization zero-day is under active exploitation with a patch not available until August, leaving FCEB agencies and enterprises with a mandatory emergency deadline and no vendor fix to deploy.

                                    • CVE-2026-58644 is a critical SharePoint RCE deserialization flaw with CVSS 9.8, added to CISA KEV
                                    • Federal agencies have until July 19 to remediate; a full patch will not be available until August
                                    • Researchers report additional SharePoint flaws are being chained together in active attacks
                                    • πŸ“– Read full article

                                      Further Reading
                                      • 🌍 Leading members of Scattered Spider sentenced in UK to 66 months in jail β€” CyberScoop
                                      • 🌍 Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime β€” CyberScoop
                                      • 🌍 The US government warns that Russia state hackers are coming after your router β€” Ars Technica Security
                                      • 🌍 Now, even Russia's most elite hackers are using Clickfix to infect devices β€” Ars Technica Security
                                      • 🌍 Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says β€” TechCrunch Security
                                      • πŸ“‘ Identity Attacks Overtake Exploits as Top Ransomware Cause β€” Dark Reading
                                      • πŸ“‘ OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials β€” The Hacker News
                                      • πŸ“‘ Single Prompt Enables ChatGPT to Execute Full Cyber-Attack Chain, Researchers Claim β€” Infosecurity Magazine
                                      • πŸ“‘ Forget typosquatting; slopsquatting is the software supply chain threat created by AI coding tools β€” VentureBeat Security
                                      • πŸ”“ Coca-Cola says Fairlife ransomware attack halts US dairy production β€” BleepingComputer
                                      • πŸ”“ Abbott probes two cyber incidents amid extortion claims β€” BleepingComputer
                                      • πŸ”“ Ernst & Young discloses data breach after support system hack β€” BleepingComputer
                                      • βš–οΈ White House details β€˜Gold Eagle’ clearinghouse for AI cyber threats β€” CyberScoop
                                      • βš–οΈ 23andMe to pay $18 million in new genetics data breach settlement β€” BleepingComputer
                                      • βš–οΈ Lessons Learned from CISA’s Recent GitHub Leak β€” Krebs on Security
                                      • 🚨 Microsoft Patches a Record 570 Security Flaws β€” Krebs on Security
                                      • 🚨 Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands β€” The Hacker News
                                      • 🚨 CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV β€” The Hacker News
                                      • Full Transcript
                                        Click to expand full episode transcript

                                        Jordan: Five hundred and seventy patches in a single Patch Tuesday. That's the number that defined this week. Not because it's a record β€” though it is β€” but because of what's behind it. AI is now discovering vulnerabilities faster than any enterprise on Earth can remediate them. And that's not a one-month anomaly. That's the new normal. Welcome to the week that broke your patch cadence.

                                        Alex: Welcome to Cleartext. I'm Alex Chen, alongside Jordan Reeves. This is your Saturday Week in Review for the week ending July 18th, 2026. If you couldn't keep up this week, here's what mattered and what it means. We've got four big themes to walk through. First, the vulnerability avalanche β€” Microsoft's record patch dump, actively exploited zero-days in SonicWall and SharePoint, and what the Gold Eagle program signals about where this is all heading. Second, identity is officially the front door for ransomware, and the tools we thought were protecting it aren't. Third, law enforcement had a genuinely consequential week, from Scattered Spider sentencing to bulletproof hosting takedowns. And fourth, the geopolitical landscape got darker β€” Russian APTs borrowing criminal playbooks, Iran exploiting telecom protocols to locate soldiers, and AI lowering the bar for offensive operations. Let's get into it.

                                        Jordan: So let's start with the vulnerability story because it touches everything else. Microsoft patched 570-plus CVEs on Tuesday. To put that in perspective, last month was already a record, and this nearly tripled it. Two zero-days under active exploitation. More than 60 rated critical. And Microsoft explicitly credited AI-assisted discovery for the surge. This isn't a blip. This is the leading edge of a structural shift in how vulnerabilities enter the ecosystem.

                                        Alex: And here's the business problem. Every CISO I know has a patch cadence built around historical volume assumptions. You staff your vulnerability management team, you allocate maintenance windows, you negotiate downtime with business units β€” all based on a rough expectation of what's coming each month. When the number triples overnight, those assumptions collapse. You can't triple your patching capacity in a week. So now you're making harder triage decisions with less margin for error.

                                        Jordan: Which brings us to Gold Eagle. The White House announced this clearinghouse specifically designed to coordinate AI-discovered vulnerabilities β€” prioritize them, route them, accelerate patches. It's already receiving intelligence. But the implementation details are thin. How does a private-sector CISO actually interface with this? What are the SLAs? Does prioritization guidance from Gold Eagle create a de facto compliance obligation? These are open questions, and they matter.

                                        Alex: They matter a lot, because we also got two other critical vulnerabilities this week that illustrate the operational pain. SonicWall SMA 1000 β€” two chained zero-days, one rated CVSS 10.0, actively exploited by the Inc ransomware group. Exploitation started three weeks before SonicWall even disclosed. If you're running SMA appliances, you were already compromised before you knew you were vulnerable.

                                        Jordan: And then SharePoint. CVE-2026-58644, CVSS 9.8, deserialization RCE, added to CISA's Known Exploited Vulnerabilities catalog with a federal remediation deadline of July 19th β€” which is tomorrow. The full patch doesn't arrive until August. So CISA is telling federal agencies to fix something that doesn't have a complete fix yet. That means you're looking at workarounds, network segmentation, compensating controls. It's ugly.

                                        Alex: The through-line here is inescapable. AI is accelerating vulnerability discovery. Vendors are shipping larger patch loads. Exploitation timelines are compressing. And remediation capacity hasn't scaled to match. This is a board-level resource conversation. If your vulnerability management program was adequately funded six months ago, it probably isn't now.

                                        Jordan: Let's pivot to identity, because the data that dropped this week was damning. Sophos published incident response analysis showing identity-based attacks β€” phishing, brute force, credential theft β€” have officially overtaken software exploits as the number one ransomware initial access vector. That's a definitive shift.

                                        Alex: And the statistic that should keep every CISO up tonight: MFA was deployed in 97 percent of those credential-based ransomware cases. It failed in every single one. Ninety-seven percent deployment. Zero percent prevention. That is a fundamental indictment of how most organizations have implemented multi-factor authentication. We've been treating MFA as a checkbox. Push notifications, SMS codes, app-based approvals β€” the adversary has adapted to all of them.

                                        Jordan: The OAuth spoofing research on Entra ID makes this even worse. At least two threat actor groups are using a technique that validates stolen credentials against Microsoft Entra without generating a sign-in event. Your SIEM doesn't see it. Your UEBA doesn't flag it. The adversary confirms your credentials are valid, and your security operations center has no idea it happened. They then move to the next stage of the attack with a verified credential set and you're still looking at a clean dashboard.

                                        Alex: So what do you do? The answer is phishing-resistant MFA β€” FIDO2, hardware keys, certificate-based authentication. And continuous access verification. Not just authentication at the gate, but ongoing validation of session integrity. This is expensive. It's operationally complex. And it's now clearly necessary. If you're going to your board this quarter, this is the conversation to have. The identity perimeter is where ransomware lives now, and our current defenses aren't working.

                                        Jordan: Let's talk about law enforcement, because this was actually a good week on that front. Two Scattered Spider leaders β€” Thalha Jubair and Owen Flowers, both barely out of their teens β€” sentenced to 66 months each at Woolwich Crown Court for the Transport for London hack. That attack took down 148 systems, forced 27,000 employees to do in-person password resets, cost 29 million pounds. The NCA credited these sentences with disrupting broader Scattered Spider operations. US authorities had previously linked Jubair to 120-plus attacks.

                                        Alex: This matters for CISOs beyond the headlines. First, it validates the UK-US law enforcement coordination model. When your legal and executive teams push back on engaging law enforcement during an incident, you now have a concrete example of that cooperation producing real consequences. Second, the deterrence signal to English-speaking cybercrime collectives is meaningful. These aren't untouchable operators in jurisdictions beyond reach. These are kids in the UK getting real prison time.

                                        Jordan: On the infrastructure side, DOJ unsealed the indictment of three Russian nationals running Media Land and ML.Cloud β€” bulletproof hosting providers that supported attacks across 21 US states, over 62 million dollars in victim losses. This targets a critical tier of the criminal supply chain. You take down the hosting layer, you degrade the reliability of attack infrastructure for every group that depended on it.

                                        Alex: Now, will these operators be extradited from Russia? Almost certainly not. But the indictment has operational value. It constrains their movement, their financial access, their ability to operate openly. And it puts other infrastructure providers on notice.

                                        Jordan: Now let's get into the geopolitical picture because this week was dense. CISA issued an advisory on Russian state-linked hackers compromising residential and SOHO routers to build proxy infrastructure. This is the residential proxy problem at scale. They're blending malicious traffic with legitimate residential IP ranges, which defeats geo-blocking, IP reputation scoring, and a lot of the heuristic models your SOC relies on.

                                        Alex: If your remote access controls assume that a connection from a US residential IP is probably a legitimate employee, that assumption is now directly challenged. This requires rethinking how you validate remote sessions β€” device posture, behavioral analysis, not just network origin.

                                        Jordan: Then we saw Russian APTs adopting ClickFix, a social engineering technique that was previously exclusive to financially motivated criminals. It tricks users into manually executing malicious commands by posing as a CAPTCHA or browser error fix. The fact that nation-state espionage groups are now borrowing from the criminal playbook tells you two things: the technique works, and the line between espionage and crime TTPs is effectively gone.

                                        Alex: Which means your security awareness training needs to evolve. If you're still training employees on email phishing and suspicious attachments, you're fighting the last war. Browser-based social engineering, fake CAPTCHAs, clipboard hijacking β€” these are the current vectors.

                                        Jordan: The Iran story is in a different category entirely. Iranian government actors exploited SS7-class vulnerabilities in mobile networks to geolocate US military personnel in the Middle East. This intelligence was used in the lead-up to and during active military engagements. This is cyber enabling kinetic operations. People were physically targeted based on telecom exploitation.

                                        Alex: For defense industrial base CISOs and anyone in critical infrastructure adjacent to national security, this is a wake-up call on mobile device policies. SS7 vulnerabilities have been known for over a decade. They remain largely unpatched because telecom infrastructure modernization is slow and expensive. Your employees' phones are leaking location data to capable adversaries.

                                        Jordan: Two more stories to hit quickly on the AI threat evolution. Researchers demonstrated GPT-5.5 executing a full cyber attack chain β€” recon through exploitation β€” from a single natural language prompt. And slopsquatting emerged as a real supply chain threat: AI coding assistants hallucinate package names, attackers register those names with malicious code, and developers install them trusting the AI's recommendation.

                                        Alex: On the GPT-5.5 research β€” this is a board-level AI risk moment. The SANS Institute simultaneously flagged a major governance gap between frontline security teams and senior leadership on AI risk. If your board still thinks AI risk is theoretical, this research makes it concrete. On slopsquatting, your software composition analysis tools weren't designed for this. You need to add validation steps for any AI-recommended dependencies. It's a process change, not a tool change.

                                        Jordan: Quickly on breaches β€” three significant ones. Coca-Cola's Fairlife subsidiary hit by ransomware, all US dairy production halted, SEC 8-K filed. Abbott Labs dealing with two simultaneous incidents β€” one in legacy systems inherited from a 21 billion dollar acquisition, one an extortion claim on a customer portal. And EY breached through a third-party support ticketing system.

                                        Alex: The Fairlife incident is the textbook OT-IT convergence case. A billion-dollar subsidiary with physical production halted by ransomware, mandatory SEC disclosure within hours. The Abbott situation is the M&A cyber debt story β€” you acquire a company, you inherit its security posture, and legacy systems become your liability. And EY reminds us that Big Four firms, with all their resources, remain vulnerable through their vendor and support tiers.

                                        Jordan: Last one β€” 23andMe settled with 43 state attorneys general for 18 million dollars over the 2023 genetic data breach, with mandatory security control enhancements. The multi-state AG enforcement model is now firmly established as the regulatory mechanism for sensitive data breaches.

                                        Alex: Alright, let's step back. Jordan, what defined this week?

                                        Jordan: Acceleration. Everything is moving faster. AI is finding vulnerabilities faster than we can patch them. Adversaries are validating credentials in ways our detection can't see. Nation-states are borrowing criminal techniques because speed and scale matter more than sophistication. The clock speed of this industry just shifted, and most security programs are still operating at last year's tempo.

                                        Alex: I agree. And I'd add convergence. Identity and ransomware converged β€” identity is now the primary entry point. Cyber and kinetic operations converged in the Iran story. AI and vulnerability management converged in that 570-patch Tuesday. The boundaries we've been drawing between these domains are dissolving. For CISOs going into next week, three priorities. One, reassess your patch triage model β€” the old volume assumptions are gone. Two, audit your MFA deployment with brutal honesty. Three, review your M&A cyber due diligence program, because inherited technical debt is becoming one of the most predictable breach vectors we see.

                                        Jordan: And watch that SharePoint zero-day. No full patch until August. If you're running SharePoint on-prem, your weekend just got shorter.

                                        Alex: That's this week. The daily show returns Monday. Show notes and links to every story we covered are at cleartext.fm. Thanks for listening. Stay sharp out there.

                                        Jordan: See you Monday.

                                        Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-18.

                                        Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                                        ...more
                                        View all episodesView all episodes
                                        Download on the App Store

                                        CleartextBy Cleartext