Cleartext

Cleartext Week in Review – June 27, 2026


Listen Later

Cleartext – June 27, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 17 stories across 5 topic areas, including: Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered; FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys; Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract.

Stories Covered
🌍 Geopolitical
Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered

The Hacker News Β· Jun 24 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

Why it matters to CISOs: Operation Endgame's simultaneous takedown of two malware-as-a-service platforms β€” dismantling 200+ C2 servers and recovering 27 million credentials β€” sets a new precedent for coordinated public-private disruption operations and signals continued pressure on the ransomware supply chain.

  • Europol, Microsoft, Bitdefender, ESET, and Bitsight jointly dismantled Amadey and StealC infrastructure
  • More than 200 command-and-control servers were taken down simultaneously
  • 27 million stolen credentials were recovered in the operation
  • πŸ“– Read full article

    FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys

    The Hacker News Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

    Why it matters to CISOs: Russian intelligence has evolved its Signal phishing campaign to harvest Backup Recovery Keys, giving persistent, account-level access to historical encrypted messages β€” a critical threat for any executive or security team member using Signal for sensitive communications.

    • FBI and CISA updated their March advisory on Russian Signal phishing to include recovery key theft
    • A stolen Backup Recovery Key allows attackers to restore account history and effectively take over the account permanently
    • The campaign is attributed to Russian intelligence services
    • πŸ“– Read full article

      Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract

      CyberScoop Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

      Why it matters to CISOs: Citizen Lab's confirmation that Russian authorities used Cellebrite tools post-contract-termination exposes a critical gap in vendor end-of-life controls for dual-use surveillance technology β€” CISOs should reassess assumptions that commercial vendor off-boarding stops state adversary tool use.

      • Russian authorities used Cellebrite to access the iPhone of political opponent Andrey Pivovarov after Cellebrite claimed to have cut off Russia
      • Citizen Lab confirmed the forensic evidence of the unauthorized device access
      • The case highlights that commercial surveillance tool export controls have limited real-world enforcement
      • πŸ“– Read full article

        πŸ“‘ Macro Trends
        Europe Evolves Into Ransomware's Favorite Region

        Dark Reading Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

        Why it matters to CISOs: A 50%+ rise in ransomware attacks targeting European organizations, with third-party suppliers as the primary entry point, is directly relevant to any CISO operating in or with supply chains connected to EU markets β€” especially given NIS2 enforcement and DORA compliance obligations.

        • Ransomware attacks against European organizations increased more than 50% in the past year per Black Kite analysis of 2,066 incidents
        • Third-party suppliers have become the primary attack entry point for European ransomware campaigns
        • The trend coincides with NIS2 and DORA regulatory enforcement pressure on European organizations
        • πŸ“– Read full article

          Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

          The Hacker News Β· Jun 23 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

          Why it matters to CISOs: A researcher-built fake skill that bypassed all tested AI agent security scanners and reached 26,000 agents β€” including corporate accounts β€” demonstrates that AI agent marketplaces are a nascent but materially uncontrolled attack surface that most enterprise security programs have not yet addressed.

          • AIR security firm built a benign but unauthorized skill that evaded all tested marketplace security scanners
          • The skill reached approximately 26,000 agents, including accounts tied to corporate organizations
          • The payload only harvested email addresses, but the research proves the full attack chain is viable at scale
          • πŸ“– Read full article

            Trust in Automated AI Vulnerability Scanning Collapses to 9%, New Study Finds

            Infosecurity Magazine Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘ 6/10

            Why it matters to CISOs: A 20-percentage-point collapse in organizational reliance on AI-only vulnerability scanning is a direct signal to CISOs evaluating AI security tooling ROI β€” the market is course-correcting toward human-AI hybrid models, with implications for vendor selection and board-level AI security narratives.

            • Only 9% of organizations now rely solely on AI automation for vulnerability testing, down 20 percentage points
            • Cobalt's study reflects broader market disillusionment with fully autonomous AI security tooling
            • The decline aligns with Dark Reading data showing falling confidence in autonomous AI penetration testing
            • πŸ“– Read full article

              πŸ”“ Data Breach
              Scattered Spider Hackers Plead Guilty on Day 1 of Trial

              Krebs on Security Β· Jun 23 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

              Why it matters to CISOs: The guilty pleas from two core Scattered Spider members β€” responsible for the 2024 Transport for London attack β€” mark a landmark legal accountability moment for a group that has targeted enterprise social engineering at scale; CISOs should note the conviction validates that SIM-swap and vishing TTPs now carry serious criminal consequences.

              • Two British men pleaded guilty on day one of what was expected to be a six-week UK trial
              • The pair were key members of Scattered Spider, responsible for the August 2024 TfL cyberattack
              • Scattered Spider has been responsible for numerous high-profile enterprise breaches using social engineering
              • πŸ“– Read full article

                Klue investigating supply chain attack that targeted Salesforce integrations

                Cybersecurity Dive Β· Jun 23 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                Why it matters to CISOs: The Klue breach is a textbook third-party OAuth token risk: a four-year-old credential from a forgotten pilot was used to pivot into Salesforce environments at Huntress, HackerOne, Jamf, Recorded Future, Tanium, and LastPass β€” directly hitting the security vendor ecosystem CISOs rely on.

                • Attackers used a credential stolen from a 2022 pilot that was never revoked to access customer Salesforce data via OAuth tokens
                • Victims include major cybersecurity firms: Huntress, HackerOne, Jamf, Recorded Future, Tanium, and LastPass
                • A second threat group subsequently threatened Klue with ransom after the initial breach
                • πŸ“– Read full article

                  FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

                  Dark Reading Β· Jun 23 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                  Why it matters to CISOs: FortiBleed's scope is expanding β€” attackers have weaponized 430,000 compromised FortiGate firewalls as active credential sniffers, making this an ongoing network intelligence operation, not just a patch-and-move-on event; any enterprise running FortiGate should assume traffic visibility is compromised until forensically cleared.

                  • Threat actors deployed a Golang-based sniffer across approximately 430,000 compromised FortiGate firewalls
                  • 110 million credentials have been identified as harvested in the ongoing campaign
                  • Attackers are conducting persistent traffic sniffing, not just initial credential theft
                  • πŸ“– Read full article

                    Polymarket customers lose $3 million in supply-chain attack

                    BleepingComputer Β· Jun 26 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                    Why it matters to CISOs: The Polymarket incident β€” a malicious script injected via a breached third-party vendor reaching the platform's frontend β€” is a vivid reminder that software supply chain integrity controls must extend to every vendor with write access to production assets, not just direct code contributors.

                    • Attackers injected a malicious script into Polymarket's frontend after breaching a third-party vendor
                    • Customers lost an estimated $3 million in the attack
                    • Polymarket committed to full reimbursement of affected customers
                    • πŸ“– Read full article

                      Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach

                      TechCrunch Security Β· Jun 22 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                      Why it matters to CISOs: A confirmed breach at Tata Electronics β€” a primary manufacturer in Apple and Tesla supply chains β€” raises fourth-party risk concerns for any enterprise whose technology procurement flows through these vendors, and reinforces that supply chain cyber risk extends well beyond software into physical hardware manufacturing.

                      • Tata Electronics confirmed a data breach affecting the major Apple and Tesla supplier
                      • The incident occurs as Tata is expanding its role in global technology supply chains, increasing its risk surface
                      • Details of data types exfiltrated and the breach vector have not been fully disclosed
                      • πŸ“– Read full article

                        βš–οΈ Governance & Policy
                        Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration

                        The Hacker News Β· Jun 23 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 9/10

                        Why it matters to CISOs: The executive order creates hard regulatory deadlines (key establishment by 2030, digital signatures by 2031) that will cascade into federal contractor requirements and vendor certification demands, forcing CISOs at companies with government exposure to accelerate PQC roadmaps now.

                        • EO 14409 mandates federal agencies migrate high-value systems to post-quantum cryptography with key establishment by December 31, 2030
                        • Digital signature migration deadline is set for December 31, 2031
                        • National security systems are on a separate, classified timeline
                        • πŸ“– Read full article

                          FCC passes new cybersecurity rules for emergency systems, undersea cables

                          CyberScoop Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                          Why it matters to CISOs: FCC's new mandatory cybersecurity requirements for emergency alert distributors and undersea cable operators represent a shift from voluntary guidance to enforceable standards for critical communications infrastructure β€” relevant for CISOs at telecom, ISP, and media organizations.

                          • FCC moved from recommending to requiring basic security protocols for emergency alert system distributors
                          • New rules also update federal security review requirements for undersea cable providers
                          • The emergency alert rules come more than a decade after a high-profile 2013 hacking campaign exploited the same systems
                          • πŸ“– Read full article

                            DHS chief says president has met with likely CISA nominee; agency plans to hire 600

                            The Record (Recorded Future) Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘ 6/10

                            Why it matters to CISOs: After months of CISA operating without a Senate-confirmed director, confirmation that a nominee is imminent β€” alongside plans to hire 600 staff β€” signals a potential reset in federal cyber leadership that will affect agency relationships, information sharing, and regulatory posture for enterprise CISOs.

                            • DHS Secretary Markwayne Mullin confirmed the president has met with a likely CISA director nominee
                            • No formal White House announcement has been made yet
                            • Once a director is confirmed, CISA plans to ramp up hiring by 600 positions
                            • πŸ“– Read full article

                              🚨 Critical Vulnerability
                              Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

                              The Hacker News Β· Jun 24 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                              Why it matters to CISOs: CVE-2026-20230 in Cisco Unified Communications Manager is unauthenticated and remotely exploitable (CVSS 8.6), now actively attacked with a public PoC β€” CISA's Sunday patch deadline for federal agencies makes this an emergency patching event for any enterprise running UCM infrastructure.

                              • CVE-2026-20230 is an unauthenticated remote improper input validation flaw in Cisco Unified CM with CVSS 8.6
                              • Active exploitation began after a public proof-of-concept demonstrated a file-write path to root access
                              • CISA set a Sunday June 29 deadline for federal civilian agencies to patch
                              • πŸ“– Read full article

                                Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access

                                The Hacker News Β· Jun 25 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 8/10

                                Why it matters to CISOs: Mandiant's finding that this Cisco SD-WAN zero-day was exploited two months before public disclosure β€” at a communications service provider β€” suggests a sophisticated threat actor with pre-patch intelligence, underscoring that KEV patching timelines alone are insufficient when adversaries have zero-day access.

                                • CVE-2026-20245 (CVSS 7.8) in Cisco Catalyst SD-WAN Manager was exploited as a zero-day at least two months before public disclosure
                                • Mandiant confirmed exploitation at a communications service provider, with attackers achieving root-level access
                                • The attacker identity and whether they gained broad traffic visibility remains undetermined
                                • πŸ“– Read full article

                                  Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

                                  The Hacker News Β· Jun 24 Β· Relevance: β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 7/10

                                  Why it matters to CISOs: The Cordyceps CI/CD workflow pattern affects repositories at Microsoft, Google, Apache, and hundreds of other major organizations β€” CISOs overseeing software development must audit pull_request_target usage in GitHub Actions workflows immediately, as this is an exploitable class vulnerability not a one-off.

                                  • Novee Security identified a new exploitable CI/CD workflow pattern dubbed Cordyceps affecting 300+ GitHub repositories
                                  • The flaw allows attackers to hijack workflows and gain full control of repositories at major organizations including Microsoft and Google
                                  • GitHub has updated actions/checkout to block the underlying pwn request attack pattern effective June 18, 2026
                                  • πŸ“– Read full article

                                    Further Reading
                                    • 🌍 Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered β€” The Hacker News
                                    • 🌍 FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys β€” The Hacker News
                                    • 🌍 Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract β€” CyberScoop
                                    • πŸ“‘ Europe Evolves Into Ransomware's Favorite Region β€” Dark Reading
                                    • πŸ“‘ Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents β€” The Hacker News
                                    • πŸ“‘ Trust in Automated AI Vulnerability Scanning Collapses to 9%, New Study Finds β€” Infosecurity Magazine
                                    • πŸ”“ Scattered Spider Hackers Plead Guilty on Day 1 of Trial β€” Krebs on Security
                                    • πŸ”“ Klue investigating supply chain attack that targeted Salesforce integrations β€” Cybersecurity Dive
                                    • πŸ”“ FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist β€” Dark Reading
                                    • πŸ”“ Polymarket customers lose $3 million in supply-chain attack β€” BleepingComputer
                                    • πŸ”“ Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach β€” TechCrunch Security
                                    • βš–οΈ Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration β€” The Hacker News
                                    • βš–οΈ FCC passes new cybersecurity rules for emergency systems, undersea cables β€” CyberScoop
                                    • βš–οΈ DHS chief says president has met with likely CISA nominee; agency plans to hire 600 β€” The Record (Recorded Future)
                                    • 🚨 Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root β€” The Hacker News
                                    • 🚨 Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access β€” The Hacker News
                                    • 🚨 Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks β€” The Hacker News
                                    • Full Transcript
                                      Click to expand full episode transcript

                                      Jordan: If I had to pick one word for this week, it's supply chain. Not as a buzzword β€” as an actual, live, multi-front crisis. A four-year-old OAuth token from a forgotten pilot program let attackers pivot through Salesforce integrations at Huntress, HackerOne, Jamf, Recorded Future, Tanium, and LastPass. Half the security vendor ecosystem got hit because nobody revoked a credential from 2022. Meanwhile, four hundred and thirty thousand FortiGate firewalls are actively sniffing credentials, Cisco has two critical vulns under active exploitation, and a fake AI agent skill waltzed past every marketplace scanner to reach twenty-six thousand agents. If your security model depends on trusting your vendors, your tools, and your infrastructure β€” and whose doesn't β€” this was the week that trust got stress-tested hard.

                                      Alex: Welcome to the Cleartext Week in Review. I'm Alex Chen, alongside Jordan Reeves. If you couldn't keep up this week, here's what mattered and what it means. We're going to cover four themes today. First, the supply chain reckoning β€” from the Klue breach to FortiBleed to Tata Electronics, third-party risk went from theoretical to visceral this week. Second, the geopolitical landscape β€” a major botnet takedown, Russian intelligence evolving its Signal targeting, and uncomfortable questions about surveillance tool controls. Third, governance and deadlines β€” a post-quantum executive order with hard dates, new FCC rules, and movement on CISA leadership. And fourth, the emerging AI attack surface and what the market is telling us about trust in AI security tooling. Let's get into it.

                                      Jordan: So let's start with supply chain, because this week was a masterclass in how third-party risk actually materializes. The Klue breach is the one I want CISOs to sit with. An attacker used a credential from a 2022 pilot integration β€” a pilot that apparently ended, but the OAuth token was never revoked. Four years later, that token opened the door to Salesforce environments at companies whose entire business is security. Huntress. HackerOne. Recorded Future. LastPass, which really cannot catch a break. And then a second threat group piled on with a ransom demand.

                                      Alex: What makes this one sting is the victim list. These aren't companies that lack security maturity. These are security companies. And the lesson isn't that they're incompetent β€” it's that the problem is structural. Every enterprise has hundreds of SaaS integrations, many from pilots and POCs that went nowhere. The OAuth tokens persist. The Salesforce connections persist. Nobody owns the lifecycle. If your identity governance program doesn't cover third-party OAuth grants with the same rigor as employee accounts, you have this exact exposure right now.

                                      Jordan: And then layer FortiBleed on top. This isn't a new vulnerability β€” it's the ongoing exploitation campaign where attackers deployed a Golang-based credential sniffer across roughly four hundred and thirty thousand compromised FortiGate firewalls. A hundred and ten million credentials harvested. These aren't firewalls that got popped and patched. They're firewalls that are actively operating as intelligence collection platforms for attackers. If you're running FortiGate and you patched but didn't do forensic validation, you should assume your traffic has been visible to someone else.

                                      Alex: I want to connect that to the Tata Electronics breach. Tata is a primary manufacturer for Apple and Tesla. The details are thin β€” we don't know the full scope of what was exfiltrated β€” but the signal matters. Supply chain cyber risk isn't just about software and SaaS anymore. It extends into physical hardware manufacturing. If your iPhones or your fleet vehicles run through a compromised manufacturing partner, that's a fourth-party risk that almost no enterprise risk framework adequately captures.

                                      Jordan: And the Polymarket incident rounds this out nicely. Three million dollars stolen from customers because attackers breached a third-party vendor that had write access to Polymarket's production frontend and injected a malicious script. The vendor wasn't a code contributor. They were just some vendor with access. This is the same pattern over and over β€” the blast radius of your security is defined by whoever has write access to your production environment, and most organizations don't have a complete inventory of who that is.

                                      Alex: So the through-line for CISOs: this week, conduct an OAuth and API token audit across your SaaS estate. Prioritize tokens from integrations older than twelve months. Revisit your vendor access governance to include every party with write access to production, not just your direct engineering team. And if you're running FortiGate, treat this as an active compromise investigation, not a patching exercise.

                                      Jordan: Let's shift to the geopolitical picture. Operation Endgame was the big coordinated action this week β€” Europol, Microsoft, Bitdefender, ESET, and Bitsight jointly took down the Amadey and StealC malware-as-a-service infrastructure. Two hundred-plus command-and-control servers. Twenty-seven million stolen credentials recovered. This is the second phase of Endgame; the first hit botnets like Smokeloader last year. What's significant is the targeting β€” they went after the assembly line, not just the finished product. These are the platforms ransomware operators use upstream.

                                      Alex: And the timing matters. Black Kite's data showed ransomware attacks against European organizations jumped more than fifty percent in the past year, with third-party suppliers as the primary entry vector. So you've got law enforcement hitting the supply side of ransomware at exactly the moment the demand side is surging in Europe. For CISOs with European operations or EU supply chains, this is a dual pressure β€” regulatory enforcement under NIS2 and DORA is tightening, while the threat environment is intensifying. The takedowns help, but they're disruptions, not eliminations.

                                      Jordan: On the intelligence side, the FBI and CISA updated their advisory on Russian Signal phishing. The original campaign used linked device tricks β€” essentially getting a target to scan a QR code that linked the attacker's device to the target's Signal account. Now they've added recovery key theft. If an attacker gets your Signal Backup Recovery Key, they can restore your full message history, read everything, and effectively own the account permanently. The key doesn't expire. It doesn't rotate. One phishing success gives them persistent access.

                                      Alex: This is directly relevant to executive communications. A lot of CISOs and their leadership teams moved to Signal precisely because it's encrypted. But encryption doesn't help if the attacker has your recovery key. If your executives use Signal for sensitive discussions β€” and many do β€” you need to issue guidance this week: do not share recovery keys under any circumstances, enable registration lock, and frankly, consider whether Signal's backup model is appropriate for your threat environment.

                                      Jordan: And then there's the Cellebrite story, which is more of a slow burn but important. Citizen Lab confirmed that Russian authorities used Cellebrite phone-cracking tools to access a political opponent's iPhone β€” after Cellebrite claimed to have terminated its contract with Russia. The tool kept working. The implication for CISOs is broader than Russia: when you off-board a surveillance or forensics vendor, can you actually verify they no longer have capability? The answer, apparently, is often no. Dual-use technology export controls have limited real-world enforcement.

                                      Alex: Let's move to governance, because this week had some consequential regulatory developments. The big one: Executive Order 14409 sets hard deadlines for federal post-quantum cryptography migration. Key establishment algorithms must be in place by December 31, 2030. Digital signatures by December 31, 2031. National security systems are on a separate classified timeline.

                                      Jordan: And for anyone thinking this only matters to federal agencies β€” it doesn't. These deadlines will cascade into FedRAMP requirements, federal contractor certifications, and vendor qualification criteria. If you sell to the government or you're in the government supply chain, your PQC roadmap just got a hard deadline. 2030 sounds far away until you realize cryptographic migrations in large enterprises take three to five years. The planning window is now.

                                      Alex: The FCC also finalized mandatory cybersecurity rules for emergency alert system distributors and undersea cable operators. This is a shift from voluntary guidance to enforceable requirements β€” and it's worth noting that these emergency alert systems were successfully hacked back in 2013. It took over a decade to move from incident to enforceable regulation. CISOs in telecom, ISP, and media sectors should review the final rule text.

                                      Jordan: And a quick note on CISA β€” DHS Secretary Mullin confirmed the president has met with a likely director nominee, with plans to hire six hundred staff once confirmed. After months of the agency operating without Senate-confirmed leadership, this matters for the information sharing relationships and regulatory posture that CISOs depend on. Watch this space.

                                      Alex: On the vulnerability front, two Cisco stories deserve attention together. CVE-2026-20230 in Unified Communications Manager β€” unauthenticated, remote, CVSS 8.6, actively exploited after a public proof of concept β€” CISA set a Sunday patch deadline for federal agencies. And CVE-2026-20245 in Catalyst SD-WAN Manager, which Mandiant confirmed was exploited as a zero-day at a communications service provider at least two months before public disclosure. That's root-level access on network infrastructure, pre-patch.

                                      Jordan: The SD-WAN zero-day is the more concerning of the two. Two months of pre-disclosure exploitation at a comms provider suggests a sophisticated actor with access to vulnerability intelligence before the public β€” whether through independent discovery or something else. This is a reminder that patching on disclosure is necessary but not sufficient. If your threat model includes nation-state actors, you need detection capabilities that don't depend on knowing the specific CVE.

                                      Alex: And quickly on the Cordyceps CI/CD vulnerability β€” Novee Security found an exploitable pattern in GitHub Actions workflows affecting three hundred-plus repositories at Microsoft, Google, Apache, and others. GitHub pushed a fix on June 18th, but if your engineering teams use pull_request_target triggers, audit those workflows now. This is a class vulnerability, not a single bug.

                                      Jordan: Last theme β€” AI attack surface. The AIR research firm built a fake AI agent skill, pushed it through a marketplace and an Instagram ad, and it reached twenty-six thousand agents including corporate accounts. Every marketplace security scanner marked it safe. The payload was deliberately benign, but the research proves the full attack chain works at scale. AI agent marketplaces are an uncontrolled attack surface, and most security programs haven't even started thinking about them.

                                      Alex: And on the flip side, Cobalt's study found that only nine percent of organizations now rely solely on AI for vulnerability scanning β€” down twenty percentage points. The market is course-correcting away from fully autonomous AI security tooling toward human-AI hybrid models. If you're evaluating AI security products or presenting AI security strategy to your board, the narrative has shifted. Pure automation is losing credibility. Human oversight is back in favor.

                                      Jordan: So stepping back β€” what defined this week? I'd say it was a week where the complexity of modern enterprise dependencies became painfully visible. Supply chain risk isn't one thing β€” it's forgotten OAuth tokens, compromised firewalls acting as sensors, third-party vendors with production write access, hardware manufacturers in geopolitical crosshairs. It's all of it, simultaneously.

                                      Alex: Agreed. And what I'd add is that this week showed a widening gap between the speed of threat evolution and the speed of institutional response. Russian intelligence is iterating on Signal phishing faster than most security teams update their awareness training. Attackers exploited a Cisco zero-day two months before anyone knew about it. A fake AI skill bypassed every scanner. The defense community is getting better at takedowns and regulation, but the cycle time mismatch is the fundamental challenge. Going into next week, I'd prioritize three things: OAuth and API token hygiene across your SaaS estate, forensic validation of any FortiGate infrastructure, and executive guidance on Signal backup key security. Those are the actions that map to this week's actual threat surface.

                                      Jordan: And if you're in a regulated industry with government exposure, start socializing those post-quantum deadlines internally. 2030 comes fast.

                                      Alex: That's your week in review. The daily show returns Monday. Show notes and links to all stories covered today are at cleartext.fm. I'm Alex Chen.

                                      Jordan: I'm Jordan Reeves. Have a good weekend.

                                      Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-27.

                                      Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.

                                      ...more
                                      View all episodesView all episodes
                                      Download on the App Store

                                      CleartextBy Cleartext