
Sign up to save your podcasts
Or


Daily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 17 stories across 5 topic areas, including: Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered; FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys; Russia uses Cellebrite to break into human rights activistβs phone, even after cancellation of contract.
The Hacker News Β· Jun 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Operation Endgame's simultaneous takedown of two malware-as-a-service platforms β dismantling 200+ C2 servers and recovering 27 million credentials β sets a new precedent for coordinated public-private disruption operations and signals continued pressure on the ransomware supply chain.
π Read full article
The Hacker News Β· Jun 26 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Russian intelligence has evolved its Signal phishing campaign to harvest Backup Recovery Keys, giving persistent, account-level access to historical encrypted messages β a critical threat for any executive or security team member using Signal for sensitive communications.
π Read full article
CyberScoop Β· Jun 25 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Citizen Lab's confirmation that Russian authorities used Cellebrite tools post-contract-termination exposes a critical gap in vendor end-of-life controls for dual-use surveillance technology β CISOs should reassess assumptions that commercial vendor off-boarding stops state adversary tool use.
π Read full article
Dark Reading Β· Jun 25 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A 50%+ rise in ransomware attacks targeting European organizations, with third-party suppliers as the primary entry point, is directly relevant to any CISO operating in or with supply chains connected to EU markets β especially given NIS2 enforcement and DORA compliance obligations.
π Read full article
The Hacker News Β· Jun 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A researcher-built fake skill that bypassed all tested AI agent security scanners and reached 26,000 agents β including corporate accounts β demonstrates that AI agent marketplaces are a nascent but materially uncontrolled attack surface that most enterprise security programs have not yet addressed.
π Read full article
Infosecurity Magazine Β· Jun 25 Β· Relevance: ββββββββββ 6/10
Why it matters to CISOs: A 20-percentage-point collapse in organizational reliance on AI-only vulnerability scanning is a direct signal to CISOs evaluating AI security tooling ROI β the market is course-correcting toward human-AI hybrid models, with implications for vendor selection and board-level AI security narratives.
π Read full article
Krebs on Security Β· Jun 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The guilty pleas from two core Scattered Spider members β responsible for the 2024 Transport for London attack β mark a landmark legal accountability moment for a group that has targeted enterprise social engineering at scale; CISOs should note the conviction validates that SIM-swap and vishing TTPs now carry serious criminal consequences.
π Read full article
Cybersecurity Dive Β· Jun 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The Klue breach is a textbook third-party OAuth token risk: a four-year-old credential from a forgotten pilot was used to pivot into Salesforce environments at Huntress, HackerOne, Jamf, Recorded Future, Tanium, and LastPass β directly hitting the security vendor ecosystem CISOs rely on.
π Read full article
Dark Reading Β· Jun 23 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: FortiBleed's scope is expanding β attackers have weaponized 430,000 compromised FortiGate firewalls as active credential sniffers, making this an ongoing network intelligence operation, not just a patch-and-move-on event; any enterprise running FortiGate should assume traffic visibility is compromised until forensically cleared.
π Read full article
BleepingComputer Β· Jun 26 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The Polymarket incident β a malicious script injected via a breached third-party vendor reaching the platform's frontend β is a vivid reminder that software supply chain integrity controls must extend to every vendor with write access to production assets, not just direct code contributors.
π Read full article
TechCrunch Security Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A confirmed breach at Tata Electronics β a primary manufacturer in Apple and Tesla supply chains β raises fourth-party risk concerns for any enterprise whose technology procurement flows through these vendors, and reinforces that supply chain cyber risk extends well beyond software into physical hardware manufacturing.
π Read full article
The Hacker News Β· Jun 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The executive order creates hard regulatory deadlines (key establishment by 2030, digital signatures by 2031) that will cascade into federal contractor requirements and vendor certification demands, forcing CISOs at companies with government exposure to accelerate PQC roadmaps now.
π Read full article
CyberScoop Β· Jun 25 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: FCC's new mandatory cybersecurity requirements for emergency alert distributors and undersea cable operators represent a shift from voluntary guidance to enforceable standards for critical communications infrastructure β relevant for CISOs at telecom, ISP, and media organizations.
π Read full article
The Record (Recorded Future) Β· Jun 25 Β· Relevance: ββββββββββ 6/10
Why it matters to CISOs: After months of CISA operating without a Senate-confirmed director, confirmation that a nominee is imminent β alongside plans to hire 600 staff β signals a potential reset in federal cyber leadership that will affect agency relationships, information sharing, and regulatory posture for enterprise CISOs.
π Read full article
The Hacker News Β· Jun 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: CVE-2026-20230 in Cisco Unified Communications Manager is unauthenticated and remotely exploitable (CVSS 8.6), now actively attacked with a public PoC β CISA's Sunday patch deadline for federal agencies makes this an emergency patching event for any enterprise running UCM infrastructure.
π Read full article
The Hacker News Β· Jun 25 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Mandiant's finding that this Cisco SD-WAN zero-day was exploited two months before public disclosure β at a communications service provider β suggests a sophisticated threat actor with pre-patch intelligence, underscoring that KEV patching timelines alone are insufficient when adversaries have zero-day access.
π Read full article
The Hacker News Β· Jun 24 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The Cordyceps CI/CD workflow pattern affects repositories at Microsoft, Google, Apache, and hundreds of other major organizations β CISOs overseeing software development must audit pull_request_target usage in GitHub Actions workflows immediately, as this is an exploitable class vulnerability not a one-off.
π Read full article
Jordan: If I had to pick one word for this week, it's supply chain. Not as a buzzword β as an actual, live, multi-front crisis. A four-year-old OAuth token from a forgotten pilot program let attackers pivot through Salesforce integrations at Huntress, HackerOne, Jamf, Recorded Future, Tanium, and LastPass. Half the security vendor ecosystem got hit because nobody revoked a credential from 2022. Meanwhile, four hundred and thirty thousand FortiGate firewalls are actively sniffing credentials, Cisco has two critical vulns under active exploitation, and a fake AI agent skill waltzed past every marketplace scanner to reach twenty-six thousand agents. If your security model depends on trusting your vendors, your tools, and your infrastructure β and whose doesn't β this was the week that trust got stress-tested hard.
Alex: Welcome to the Cleartext Week in Review. I'm Alex Chen, alongside Jordan Reeves. If you couldn't keep up this week, here's what mattered and what it means. We're going to cover four themes today. First, the supply chain reckoning β from the Klue breach to FortiBleed to Tata Electronics, third-party risk went from theoretical to visceral this week. Second, the geopolitical landscape β a major botnet takedown, Russian intelligence evolving its Signal targeting, and uncomfortable questions about surveillance tool controls. Third, governance and deadlines β a post-quantum executive order with hard dates, new FCC rules, and movement on CISA leadership. And fourth, the emerging AI attack surface and what the market is telling us about trust in AI security tooling. Let's get into it.
Jordan: So let's start with supply chain, because this week was a masterclass in how third-party risk actually materializes. The Klue breach is the one I want CISOs to sit with. An attacker used a credential from a 2022 pilot integration β a pilot that apparently ended, but the OAuth token was never revoked. Four years later, that token opened the door to Salesforce environments at companies whose entire business is security. Huntress. HackerOne. Recorded Future. LastPass, which really cannot catch a break. And then a second threat group piled on with a ransom demand.
Alex: What makes this one sting is the victim list. These aren't companies that lack security maturity. These are security companies. And the lesson isn't that they're incompetent β it's that the problem is structural. Every enterprise has hundreds of SaaS integrations, many from pilots and POCs that went nowhere. The OAuth tokens persist. The Salesforce connections persist. Nobody owns the lifecycle. If your identity governance program doesn't cover third-party OAuth grants with the same rigor as employee accounts, you have this exact exposure right now.
Jordan: And then layer FortiBleed on top. This isn't a new vulnerability β it's the ongoing exploitation campaign where attackers deployed a Golang-based credential sniffer across roughly four hundred and thirty thousand compromised FortiGate firewalls. A hundred and ten million credentials harvested. These aren't firewalls that got popped and patched. They're firewalls that are actively operating as intelligence collection platforms for attackers. If you're running FortiGate and you patched but didn't do forensic validation, you should assume your traffic has been visible to someone else.
Alex: I want to connect that to the Tata Electronics breach. Tata is a primary manufacturer for Apple and Tesla. The details are thin β we don't know the full scope of what was exfiltrated β but the signal matters. Supply chain cyber risk isn't just about software and SaaS anymore. It extends into physical hardware manufacturing. If your iPhones or your fleet vehicles run through a compromised manufacturing partner, that's a fourth-party risk that almost no enterprise risk framework adequately captures.
Jordan: And the Polymarket incident rounds this out nicely. Three million dollars stolen from customers because attackers breached a third-party vendor that had write access to Polymarket's production frontend and injected a malicious script. The vendor wasn't a code contributor. They were just some vendor with access. This is the same pattern over and over β the blast radius of your security is defined by whoever has write access to your production environment, and most organizations don't have a complete inventory of who that is.
Alex: So the through-line for CISOs: this week, conduct an OAuth and API token audit across your SaaS estate. Prioritize tokens from integrations older than twelve months. Revisit your vendor access governance to include every party with write access to production, not just your direct engineering team. And if you're running FortiGate, treat this as an active compromise investigation, not a patching exercise.
Jordan: Let's shift to the geopolitical picture. Operation Endgame was the big coordinated action this week β Europol, Microsoft, Bitdefender, ESET, and Bitsight jointly took down the Amadey and StealC malware-as-a-service infrastructure. Two hundred-plus command-and-control servers. Twenty-seven million stolen credentials recovered. This is the second phase of Endgame; the first hit botnets like Smokeloader last year. What's significant is the targeting β they went after the assembly line, not just the finished product. These are the platforms ransomware operators use upstream.
Alex: And the timing matters. Black Kite's data showed ransomware attacks against European organizations jumped more than fifty percent in the past year, with third-party suppliers as the primary entry vector. So you've got law enforcement hitting the supply side of ransomware at exactly the moment the demand side is surging in Europe. For CISOs with European operations or EU supply chains, this is a dual pressure β regulatory enforcement under NIS2 and DORA is tightening, while the threat environment is intensifying. The takedowns help, but they're disruptions, not eliminations.
Jordan: On the intelligence side, the FBI and CISA updated their advisory on Russian Signal phishing. The original campaign used linked device tricks β essentially getting a target to scan a QR code that linked the attacker's device to the target's Signal account. Now they've added recovery key theft. If an attacker gets your Signal Backup Recovery Key, they can restore your full message history, read everything, and effectively own the account permanently. The key doesn't expire. It doesn't rotate. One phishing success gives them persistent access.
Alex: This is directly relevant to executive communications. A lot of CISOs and their leadership teams moved to Signal precisely because it's encrypted. But encryption doesn't help if the attacker has your recovery key. If your executives use Signal for sensitive discussions β and many do β you need to issue guidance this week: do not share recovery keys under any circumstances, enable registration lock, and frankly, consider whether Signal's backup model is appropriate for your threat environment.
Jordan: And then there's the Cellebrite story, which is more of a slow burn but important. Citizen Lab confirmed that Russian authorities used Cellebrite phone-cracking tools to access a political opponent's iPhone β after Cellebrite claimed to have terminated its contract with Russia. The tool kept working. The implication for CISOs is broader than Russia: when you off-board a surveillance or forensics vendor, can you actually verify they no longer have capability? The answer, apparently, is often no. Dual-use technology export controls have limited real-world enforcement.
Alex: Let's move to governance, because this week had some consequential regulatory developments. The big one: Executive Order 14409 sets hard deadlines for federal post-quantum cryptography migration. Key establishment algorithms must be in place by December 31, 2030. Digital signatures by December 31, 2031. National security systems are on a separate classified timeline.
Jordan: And for anyone thinking this only matters to federal agencies β it doesn't. These deadlines will cascade into FedRAMP requirements, federal contractor certifications, and vendor qualification criteria. If you sell to the government or you're in the government supply chain, your PQC roadmap just got a hard deadline. 2030 sounds far away until you realize cryptographic migrations in large enterprises take three to five years. The planning window is now.
Alex: The FCC also finalized mandatory cybersecurity rules for emergency alert system distributors and undersea cable operators. This is a shift from voluntary guidance to enforceable requirements β and it's worth noting that these emergency alert systems were successfully hacked back in 2013. It took over a decade to move from incident to enforceable regulation. CISOs in telecom, ISP, and media sectors should review the final rule text.
Jordan: And a quick note on CISA β DHS Secretary Mullin confirmed the president has met with a likely director nominee, with plans to hire six hundred staff once confirmed. After months of the agency operating without Senate-confirmed leadership, this matters for the information sharing relationships and regulatory posture that CISOs depend on. Watch this space.
Alex: On the vulnerability front, two Cisco stories deserve attention together. CVE-2026-20230 in Unified Communications Manager β unauthenticated, remote, CVSS 8.6, actively exploited after a public proof of concept β CISA set a Sunday patch deadline for federal agencies. And CVE-2026-20245 in Catalyst SD-WAN Manager, which Mandiant confirmed was exploited as a zero-day at a communications service provider at least two months before public disclosure. That's root-level access on network infrastructure, pre-patch.
Jordan: The SD-WAN zero-day is the more concerning of the two. Two months of pre-disclosure exploitation at a comms provider suggests a sophisticated actor with access to vulnerability intelligence before the public β whether through independent discovery or something else. This is a reminder that patching on disclosure is necessary but not sufficient. If your threat model includes nation-state actors, you need detection capabilities that don't depend on knowing the specific CVE.
Alex: And quickly on the Cordyceps CI/CD vulnerability β Novee Security found an exploitable pattern in GitHub Actions workflows affecting three hundred-plus repositories at Microsoft, Google, Apache, and others. GitHub pushed a fix on June 18th, but if your engineering teams use pull_request_target triggers, audit those workflows now. This is a class vulnerability, not a single bug.
Jordan: Last theme β AI attack surface. The AIR research firm built a fake AI agent skill, pushed it through a marketplace and an Instagram ad, and it reached twenty-six thousand agents including corporate accounts. Every marketplace security scanner marked it safe. The payload was deliberately benign, but the research proves the full attack chain works at scale. AI agent marketplaces are an uncontrolled attack surface, and most security programs haven't even started thinking about them.
Alex: And on the flip side, Cobalt's study found that only nine percent of organizations now rely solely on AI for vulnerability scanning β down twenty percentage points. The market is course-correcting away from fully autonomous AI security tooling toward human-AI hybrid models. If you're evaluating AI security products or presenting AI security strategy to your board, the narrative has shifted. Pure automation is losing credibility. Human oversight is back in favor.
Jordan: So stepping back β what defined this week? I'd say it was a week where the complexity of modern enterprise dependencies became painfully visible. Supply chain risk isn't one thing β it's forgotten OAuth tokens, compromised firewalls acting as sensors, third-party vendors with production write access, hardware manufacturers in geopolitical crosshairs. It's all of it, simultaneously.
Alex: Agreed. And what I'd add is that this week showed a widening gap between the speed of threat evolution and the speed of institutional response. Russian intelligence is iterating on Signal phishing faster than most security teams update their awareness training. Attackers exploited a Cisco zero-day two months before anyone knew about it. A fake AI skill bypassed every scanner. The defense community is getting better at takedowns and regulation, but the cycle time mismatch is the fundamental challenge. Going into next week, I'd prioritize three things: OAuth and API token hygiene across your SaaS estate, forensic validation of any FortiGate infrastructure, and executive guidance on Signal backup key security. Those are the actions that map to this week's actual threat surface.
Jordan: And if you're in a regulated industry with government exposure, start socializing those post-quantum deadlines internally. 2030 comes fast.
Alex: That's your week in review. The daily show returns Monday. Show notes and links to all stories covered today are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. Have a good weekend.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-27.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.
By CleartextDaily cybersecurity briefing for CISOs and security leaders.
π§ Listen to this episode
Today's episode covers 17 stories across 5 topic areas, including: Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered; FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys; Russia uses Cellebrite to break into human rights activistβs phone, even after cancellation of contract.
The Hacker News Β· Jun 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Operation Endgame's simultaneous takedown of two malware-as-a-service platforms β dismantling 200+ C2 servers and recovering 27 million credentials β sets a new precedent for coordinated public-private disruption operations and signals continued pressure on the ransomware supply chain.
π Read full article
The Hacker News Β· Jun 26 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Russian intelligence has evolved its Signal phishing campaign to harvest Backup Recovery Keys, giving persistent, account-level access to historical encrypted messages β a critical threat for any executive or security team member using Signal for sensitive communications.
π Read full article
CyberScoop Β· Jun 25 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: Citizen Lab's confirmation that Russian authorities used Cellebrite tools post-contract-termination exposes a critical gap in vendor end-of-life controls for dual-use surveillance technology β CISOs should reassess assumptions that commercial vendor off-boarding stops state adversary tool use.
π Read full article
Dark Reading Β· Jun 25 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A 50%+ rise in ransomware attacks targeting European organizations, with third-party suppliers as the primary entry point, is directly relevant to any CISO operating in or with supply chains connected to EU markets β especially given NIS2 enforcement and DORA compliance obligations.
π Read full article
The Hacker News Β· Jun 23 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A researcher-built fake skill that bypassed all tested AI agent security scanners and reached 26,000 agents β including corporate accounts β demonstrates that AI agent marketplaces are a nascent but materially uncontrolled attack surface that most enterprise security programs have not yet addressed.
π Read full article
Infosecurity Magazine Β· Jun 25 Β· Relevance: ββββββββββ 6/10
Why it matters to CISOs: A 20-percentage-point collapse in organizational reliance on AI-only vulnerability scanning is a direct signal to CISOs evaluating AI security tooling ROI β the market is course-correcting toward human-AI hybrid models, with implications for vendor selection and board-level AI security narratives.
π Read full article
Krebs on Security Β· Jun 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The guilty pleas from two core Scattered Spider members β responsible for the 2024 Transport for London attack β mark a landmark legal accountability moment for a group that has targeted enterprise social engineering at scale; CISOs should note the conviction validates that SIM-swap and vishing TTPs now carry serious criminal consequences.
π Read full article
Cybersecurity Dive Β· Jun 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The Klue breach is a textbook third-party OAuth token risk: a four-year-old credential from a forgotten pilot was used to pivot into Salesforce environments at Huntress, HackerOne, Jamf, Recorded Future, Tanium, and LastPass β directly hitting the security vendor ecosystem CISOs rely on.
π Read full article
Dark Reading Β· Jun 23 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: FortiBleed's scope is expanding β attackers have weaponized 430,000 compromised FortiGate firewalls as active credential sniffers, making this an ongoing network intelligence operation, not just a patch-and-move-on event; any enterprise running FortiGate should assume traffic visibility is compromised until forensically cleared.
π Read full article
BleepingComputer Β· Jun 26 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The Polymarket incident β a malicious script injected via a breached third-party vendor reaching the platform's frontend β is a vivid reminder that software supply chain integrity controls must extend to every vendor with write access to production assets, not just direct code contributors.
π Read full article
TechCrunch Security Β· Jun 22 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: A confirmed breach at Tata Electronics β a primary manufacturer in Apple and Tesla supply chains β raises fourth-party risk concerns for any enterprise whose technology procurement flows through these vendors, and reinforces that supply chain cyber risk extends well beyond software into physical hardware manufacturing.
π Read full article
The Hacker News Β· Jun 23 Β· Relevance: ββββββββββ 9/10
Why it matters to CISOs: The executive order creates hard regulatory deadlines (key establishment by 2030, digital signatures by 2031) that will cascade into federal contractor requirements and vendor certification demands, forcing CISOs at companies with government exposure to accelerate PQC roadmaps now.
π Read full article
CyberScoop Β· Jun 25 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: FCC's new mandatory cybersecurity requirements for emergency alert distributors and undersea cable operators represent a shift from voluntary guidance to enforceable standards for critical communications infrastructure β relevant for CISOs at telecom, ISP, and media organizations.
π Read full article
The Record (Recorded Future) Β· Jun 25 Β· Relevance: ββββββββββ 6/10
Why it matters to CISOs: After months of CISA operating without a Senate-confirmed director, confirmation that a nominee is imminent β alongside plans to hire 600 staff β signals a potential reset in federal cyber leadership that will affect agency relationships, information sharing, and regulatory posture for enterprise CISOs.
π Read full article
The Hacker News Β· Jun 24 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: CVE-2026-20230 in Cisco Unified Communications Manager is unauthenticated and remotely exploitable (CVSS 8.6), now actively attacked with a public PoC β CISA's Sunday patch deadline for federal agencies makes this an emergency patching event for any enterprise running UCM infrastructure.
π Read full article
The Hacker News Β· Jun 25 Β· Relevance: ββββββββββ 8/10
Why it matters to CISOs: Mandiant's finding that this Cisco SD-WAN zero-day was exploited two months before public disclosure β at a communications service provider β suggests a sophisticated threat actor with pre-patch intelligence, underscoring that KEV patching timelines alone are insufficient when adversaries have zero-day access.
π Read full article
The Hacker News Β· Jun 24 Β· Relevance: ββββββββββ 7/10
Why it matters to CISOs: The Cordyceps CI/CD workflow pattern affects repositories at Microsoft, Google, Apache, and hundreds of other major organizations β CISOs overseeing software development must audit pull_request_target usage in GitHub Actions workflows immediately, as this is an exploitable class vulnerability not a one-off.
π Read full article
Jordan: If I had to pick one word for this week, it's supply chain. Not as a buzzword β as an actual, live, multi-front crisis. A four-year-old OAuth token from a forgotten pilot program let attackers pivot through Salesforce integrations at Huntress, HackerOne, Jamf, Recorded Future, Tanium, and LastPass. Half the security vendor ecosystem got hit because nobody revoked a credential from 2022. Meanwhile, four hundred and thirty thousand FortiGate firewalls are actively sniffing credentials, Cisco has two critical vulns under active exploitation, and a fake AI agent skill waltzed past every marketplace scanner to reach twenty-six thousand agents. If your security model depends on trusting your vendors, your tools, and your infrastructure β and whose doesn't β this was the week that trust got stress-tested hard.
Alex: Welcome to the Cleartext Week in Review. I'm Alex Chen, alongside Jordan Reeves. If you couldn't keep up this week, here's what mattered and what it means. We're going to cover four themes today. First, the supply chain reckoning β from the Klue breach to FortiBleed to Tata Electronics, third-party risk went from theoretical to visceral this week. Second, the geopolitical landscape β a major botnet takedown, Russian intelligence evolving its Signal targeting, and uncomfortable questions about surveillance tool controls. Third, governance and deadlines β a post-quantum executive order with hard dates, new FCC rules, and movement on CISA leadership. And fourth, the emerging AI attack surface and what the market is telling us about trust in AI security tooling. Let's get into it.
Jordan: So let's start with supply chain, because this week was a masterclass in how third-party risk actually materializes. The Klue breach is the one I want CISOs to sit with. An attacker used a credential from a 2022 pilot integration β a pilot that apparently ended, but the OAuth token was never revoked. Four years later, that token opened the door to Salesforce environments at companies whose entire business is security. Huntress. HackerOne. Recorded Future. LastPass, which really cannot catch a break. And then a second threat group piled on with a ransom demand.
Alex: What makes this one sting is the victim list. These aren't companies that lack security maturity. These are security companies. And the lesson isn't that they're incompetent β it's that the problem is structural. Every enterprise has hundreds of SaaS integrations, many from pilots and POCs that went nowhere. The OAuth tokens persist. The Salesforce connections persist. Nobody owns the lifecycle. If your identity governance program doesn't cover third-party OAuth grants with the same rigor as employee accounts, you have this exact exposure right now.
Jordan: And then layer FortiBleed on top. This isn't a new vulnerability β it's the ongoing exploitation campaign where attackers deployed a Golang-based credential sniffer across roughly four hundred and thirty thousand compromised FortiGate firewalls. A hundred and ten million credentials harvested. These aren't firewalls that got popped and patched. They're firewalls that are actively operating as intelligence collection platforms for attackers. If you're running FortiGate and you patched but didn't do forensic validation, you should assume your traffic has been visible to someone else.
Alex: I want to connect that to the Tata Electronics breach. Tata is a primary manufacturer for Apple and Tesla. The details are thin β we don't know the full scope of what was exfiltrated β but the signal matters. Supply chain cyber risk isn't just about software and SaaS anymore. It extends into physical hardware manufacturing. If your iPhones or your fleet vehicles run through a compromised manufacturing partner, that's a fourth-party risk that almost no enterprise risk framework adequately captures.
Jordan: And the Polymarket incident rounds this out nicely. Three million dollars stolen from customers because attackers breached a third-party vendor that had write access to Polymarket's production frontend and injected a malicious script. The vendor wasn't a code contributor. They were just some vendor with access. This is the same pattern over and over β the blast radius of your security is defined by whoever has write access to your production environment, and most organizations don't have a complete inventory of who that is.
Alex: So the through-line for CISOs: this week, conduct an OAuth and API token audit across your SaaS estate. Prioritize tokens from integrations older than twelve months. Revisit your vendor access governance to include every party with write access to production, not just your direct engineering team. And if you're running FortiGate, treat this as an active compromise investigation, not a patching exercise.
Jordan: Let's shift to the geopolitical picture. Operation Endgame was the big coordinated action this week β Europol, Microsoft, Bitdefender, ESET, and Bitsight jointly took down the Amadey and StealC malware-as-a-service infrastructure. Two hundred-plus command-and-control servers. Twenty-seven million stolen credentials recovered. This is the second phase of Endgame; the first hit botnets like Smokeloader last year. What's significant is the targeting β they went after the assembly line, not just the finished product. These are the platforms ransomware operators use upstream.
Alex: And the timing matters. Black Kite's data showed ransomware attacks against European organizations jumped more than fifty percent in the past year, with third-party suppliers as the primary entry vector. So you've got law enforcement hitting the supply side of ransomware at exactly the moment the demand side is surging in Europe. For CISOs with European operations or EU supply chains, this is a dual pressure β regulatory enforcement under NIS2 and DORA is tightening, while the threat environment is intensifying. The takedowns help, but they're disruptions, not eliminations.
Jordan: On the intelligence side, the FBI and CISA updated their advisory on Russian Signal phishing. The original campaign used linked device tricks β essentially getting a target to scan a QR code that linked the attacker's device to the target's Signal account. Now they've added recovery key theft. If an attacker gets your Signal Backup Recovery Key, they can restore your full message history, read everything, and effectively own the account permanently. The key doesn't expire. It doesn't rotate. One phishing success gives them persistent access.
Alex: This is directly relevant to executive communications. A lot of CISOs and their leadership teams moved to Signal precisely because it's encrypted. But encryption doesn't help if the attacker has your recovery key. If your executives use Signal for sensitive discussions β and many do β you need to issue guidance this week: do not share recovery keys under any circumstances, enable registration lock, and frankly, consider whether Signal's backup model is appropriate for your threat environment.
Jordan: And then there's the Cellebrite story, which is more of a slow burn but important. Citizen Lab confirmed that Russian authorities used Cellebrite phone-cracking tools to access a political opponent's iPhone β after Cellebrite claimed to have terminated its contract with Russia. The tool kept working. The implication for CISOs is broader than Russia: when you off-board a surveillance or forensics vendor, can you actually verify they no longer have capability? The answer, apparently, is often no. Dual-use technology export controls have limited real-world enforcement.
Alex: Let's move to governance, because this week had some consequential regulatory developments. The big one: Executive Order 14409 sets hard deadlines for federal post-quantum cryptography migration. Key establishment algorithms must be in place by December 31, 2030. Digital signatures by December 31, 2031. National security systems are on a separate classified timeline.
Jordan: And for anyone thinking this only matters to federal agencies β it doesn't. These deadlines will cascade into FedRAMP requirements, federal contractor certifications, and vendor qualification criteria. If you sell to the government or you're in the government supply chain, your PQC roadmap just got a hard deadline. 2030 sounds far away until you realize cryptographic migrations in large enterprises take three to five years. The planning window is now.
Alex: The FCC also finalized mandatory cybersecurity rules for emergency alert system distributors and undersea cable operators. This is a shift from voluntary guidance to enforceable requirements β and it's worth noting that these emergency alert systems were successfully hacked back in 2013. It took over a decade to move from incident to enforceable regulation. CISOs in telecom, ISP, and media sectors should review the final rule text.
Jordan: And a quick note on CISA β DHS Secretary Mullin confirmed the president has met with a likely director nominee, with plans to hire six hundred staff once confirmed. After months of the agency operating without Senate-confirmed leadership, this matters for the information sharing relationships and regulatory posture that CISOs depend on. Watch this space.
Alex: On the vulnerability front, two Cisco stories deserve attention together. CVE-2026-20230 in Unified Communications Manager β unauthenticated, remote, CVSS 8.6, actively exploited after a public proof of concept β CISA set a Sunday patch deadline for federal agencies. And CVE-2026-20245 in Catalyst SD-WAN Manager, which Mandiant confirmed was exploited as a zero-day at a communications service provider at least two months before public disclosure. That's root-level access on network infrastructure, pre-patch.
Jordan: The SD-WAN zero-day is the more concerning of the two. Two months of pre-disclosure exploitation at a comms provider suggests a sophisticated actor with access to vulnerability intelligence before the public β whether through independent discovery or something else. This is a reminder that patching on disclosure is necessary but not sufficient. If your threat model includes nation-state actors, you need detection capabilities that don't depend on knowing the specific CVE.
Alex: And quickly on the Cordyceps CI/CD vulnerability β Novee Security found an exploitable pattern in GitHub Actions workflows affecting three hundred-plus repositories at Microsoft, Google, Apache, and others. GitHub pushed a fix on June 18th, but if your engineering teams use pull_request_target triggers, audit those workflows now. This is a class vulnerability, not a single bug.
Jordan: Last theme β AI attack surface. The AIR research firm built a fake AI agent skill, pushed it through a marketplace and an Instagram ad, and it reached twenty-six thousand agents including corporate accounts. Every marketplace security scanner marked it safe. The payload was deliberately benign, but the research proves the full attack chain works at scale. AI agent marketplaces are an uncontrolled attack surface, and most security programs haven't even started thinking about them.
Alex: And on the flip side, Cobalt's study found that only nine percent of organizations now rely solely on AI for vulnerability scanning β down twenty percentage points. The market is course-correcting away from fully autonomous AI security tooling toward human-AI hybrid models. If you're evaluating AI security products or presenting AI security strategy to your board, the narrative has shifted. Pure automation is losing credibility. Human oversight is back in favor.
Jordan: So stepping back β what defined this week? I'd say it was a week where the complexity of modern enterprise dependencies became painfully visible. Supply chain risk isn't one thing β it's forgotten OAuth tokens, compromised firewalls acting as sensors, third-party vendors with production write access, hardware manufacturers in geopolitical crosshairs. It's all of it, simultaneously.
Alex: Agreed. And what I'd add is that this week showed a widening gap between the speed of threat evolution and the speed of institutional response. Russian intelligence is iterating on Signal phishing faster than most security teams update their awareness training. Attackers exploited a Cisco zero-day two months before anyone knew about it. A fake AI skill bypassed every scanner. The defense community is getting better at takedowns and regulation, but the cycle time mismatch is the fundamental challenge. Going into next week, I'd prioritize three things: OAuth and API token hygiene across your SaaS estate, forensic validation of any FortiGate infrastructure, and executive guidance on Signal backup key security. Those are the actions that map to this week's actual threat surface.
Jordan: And if you're in a regulated industry with government exposure, start socializing those post-quantum deadlines internally. 2030 comes fast.
Alex: That's your week in review. The daily show returns Monday. Show notes and links to all stories covered today are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. Have a good weekend.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-27.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.