Cleartext logocleartext_
daily briefing

Cleartext – June 24, 2026

Wednesday, June 24, 2026·10:56

Cleartext – June 24, 2026
10:56·6.7 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – June 24, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 6 topic areas, including: Five Eyes agencies sound alarm about AI’s threat to cybersecurity; Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage; Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents.

Stories Covered

🌍 Geopolitical

Five Eyes agencies sound alarm about AI’s threat to cybersecurity

The Record (Recorded Future) · Jun 23 · Relevance: ██████████ 10/10

Why it matters to CISOs: A rare joint advisory from all Five Eyes intelligence agencies declaring that frontier AI will transform offensive cyber operations within months—not years—demands immediate strategic reassessment of defensive posture and AI governance. This is a direct call to action for security leaders to brief boards and accelerate resilience investments.

  • Five Eyes joint advisory states the AI cyberthreat timeline is 'months, not years'
  • Frontier AI models expected to surpass current offensive capabilities imminently
  • Agencies are pressing leaders to treat cyber resilience as a core business risk

📖 Read full article

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Cyber Espionage

Infosecurity Magazine · Jun 24 · Relevance: ████████░░ 8/10

Why it matters to CISOs: MuddyWater's tactic of disguising state-sponsored espionage operations as ransomware attacks using commercially available malware directly complicates enterprise incident response and attribution, meaning organizations may misclassify a nation-state intrusion as a criminal event and respond inadequately.

  • Iran-linked MuddyWater is deploying ransomware personas to obscure state espionage activity
  • The group is using commercially available malware to blend in with criminal threat actors
  • NCC Group research warns this tactic is specifically designed to mislead defenders and incident responders

📖 Read full article

📡 Macro Trends

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

The Hacker News · Jun 23 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A security firm demonstrated that a malicious AI agent skill can bypass all major skill marketplace security scanners and propagate to 26,000 agents including corporate accounts—exposing a critical governance gap in enterprise agentic AI deployments that current security tooling cannot yet detect or prevent.

  • AIR Security built a fake AI agent skill that passed every security scanner tested and reached approximately 26,000 agents
  • The malicious skill spread via a popular skill marketplace and Instagram advertising, including to corporate accounts
  • The demonstration payload was benign but proved the viability of supply chain attacks targeting enterprise AI agent ecosystems

📖 Read full article

🔓 Data Breach

Scope of Salesforce Attacks Expands as Icarus Leaks Data

Dark Reading · Jun 23 · Relevance: █████████░ 9/10

Why it matters to CISOs: The Klue supply chain attack exploiting OAuth tokens to access downstream customers' Salesforce environments—affecting LastPass and numerous other enterprise firms—is a critical reminder that third-party SaaS integrations represent an undermonitored attack vector with wide blast radius. CISOs should urgently audit OAuth token inventories and third-party Salesforce integration permissions.

  • Attackers breached Klue and used stolen OAuth tokens to access customers' Salesforce data
  • LastPass confirmed customer support case data was stolen via the same attack chain
  • Hackers reportedly used a credential from 2022 that was never revoked after a pilot program ended

📖 Read full article

⚖️ Governance & Policy

Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration

The Hacker News · Jun 23 · Relevance: █████████░ 9/10

Why it matters to CISOs: The executive order establishes hard federal deadlines—key establishment by end of 2030, digital signatures by end of 2031—that will cascade into contractor and vendor compliance requirements, making PQC migration planning an urgent board-level obligation for any enterprise with federal contracts or regulated data.

  • EO 14409 mandates federal agencies migrate high-value systems to post-quantum cryptography by December 31, 2030
  • Digital signature systems face a December 31, 2031 deadline
  • National security systems are on a separate track under the order

📖 Read full article

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Krebs on Security · Jun 23 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The day-one guilty pleas from Scattered Spider members in the UK signal growing international law enforcement effectiveness against sophisticated social engineering threat groups, and affirm that the group's attack patterns—which devastated MGM, Caesars, and Transport for London—carry serious criminal consequences that boards and insurers will note.

  • Two Scattered Spider members pleaded guilty on the first day of what was expected to be a six-week trial in the UK
  • The charges relate to the August 2024 cyberattack that crippled Transport for London
  • Scattered Spider is responsible for a string of high-profile corporate breaches using social engineering

📖 Read full article

🚀 Startup Ecosystem

Why Security Firm Varonis Is Eyeing a Sale to Private Equity

BankInfoSecurity · Jun 24 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Potential acquisition of Varonis—a major data security and access governance platform used widely in enterprises—by Blackstone, Thoma Bravo, or Vista Equity could signal product roadmap shifts, pricing changes, and integration strategy pivots that CISOs currently dependent on the platform should monitor closely.

  • Blackstone, Thoma Bravo, and Vista Equity Partners have expressed preliminary interest in acquiring Varonis
  • Varonis is working with advisors to explore strategic options including a potential sale
  • The interest follows stock struggles and unfavorable market comparisons to rival Cyera

📖 Read full article

🚨 Critical Vulnerability

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root

The Hacker News · Jun 24 · Relevance: █████████░ 9/10

Why it matters to CISOs: CVE-2026-20230 is being actively exploited at scale via automated Tor-based sweeps dropping webshells on Cisco Unified Communications Manager—a widely deployed enterprise telephony platform—enabling unauthenticated remote code execution. Organizations running Unified CM must treat this as an emergency patch and isolate exposed systems immediately.

  • CVE-2026-20230 (CVSS 8.6) is an SSRF/improper input validation flaw in Cisco Unified CM and Unified CM SME
  • Honeypots are detecting automated sweeps via Tor dropping webshells using a WebDialer SSRF exploit chain
  • Exploitation achieves remote code execution on the underlying server with no authentication required

📖 Read full article

FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist

Dark Reading · Jun 23 · Relevance: █████████░ 9/10

Why it matters to CISOs: The FortiBleed campaign has evolved beyond initial exploitation: attackers deployed a custom Golang sniffer on compromised FortiGate firewalls to harvest credentials at massive scale, representing an active, ongoing threat to the 430,000 affected devices. CISOs with FortiGate infrastructure must assume credential compromise and force broad password resets across systems exposed to those firewalls.

  • Threat actors engineered a Golang-based network sniffer deployed on 430,000 compromised FortiGate firewalls
  • The sniffer has captured approximately 110 million credentials from victim networks
  • The campaign is ongoing and extends well beyond the initial credential leak disclosed earlier

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Good morning. It's Wednesday, June 24th, 2026. This is Cleartext. I'm Alex Chen.

Jordan: And I'm Jordan Reeves.

Alex: We have a packed show today. The Five Eyes alliance just dropped a joint advisory that should be on every CISO's desk by lunch. We'll unpack the Salesforce supply chain attack that's still expanding, talk about why MuddyWater is dressing up as a ransomware gang, and cover a post-quantum crypto deadline that just got very real. Plus active exploitation of Cisco Unified CM, the FortiBleed campaign getting worse, Scattered Spider guilty pleas, a fake AI agent skill that fooled every scanner on the market, and Varonis potentially going private. Let's get into it.

Jordan: So let's start where we have to start. Yesterday, all five Five Eyes agencies — that's the US, UK, Canada, Australia, and New Zealand — issued a joint advisory on AI and offensive cyber. And the language is unusually blunt. The quote that matters is this: "The timeline is not years, it is months." They're saying frontier AI models are on the verge of surpassing current offensive cyber capabilities and that organizations need to treat this as an imminent shift, not a theoretical one.

Alex: I want to sit with the weight of that for a second. Joint advisories from all five nations are rare. They don't do this for incremental threats. The last time we saw language this urgent across all five was the early warnings about Chinese pre-positioning in critical infrastructure. So when they say months, they mean it. And the audience they're addressing isn't just government agencies — they're explicitly pressing business leaders to treat cyber resilience as a core business risk, which tells you they see private sector readiness as dangerously behind.

Jordan: What's changed is the capability curve. We've been watching AI-augmented offensive tools improve steadily — better phishing, faster vulnerability discovery, automated exploit generation. But the advisory implies something qualitative is about to shift. We're moving from AI as a force multiplier for existing tradecraft to AI as an autonomous offensive capability that changes the economics of attack entirely.

Alex: And for CISOs, this is a board conversation today. Not next quarter. If you're building your fiscal year 2027 budget without factoring in a step-function increase in attacker capability, you're building the wrong budget. This advisory gives you the ammunition to go to your board and say, every major Western intelligence agency is telling us to move now. Use it.

Jordan: And while we're on geopolitics, let's talk about MuddyWater, because this story connects directly. NCC Group published research showing Iran's MuddyWater group is now disguising state-sponsored espionage operations as ransomware attacks. They're deploying commercially available malware, using ransomware personas, specifically to mislead defenders and incident responders.

Alex: This is an attribution problem that creates a response problem. If your IR team classifies an intrusion as criminal ransomware, the playbook is containment, recovery, maybe negotiate, move on. But if it's actually a nation-state intelligence operation, you're dealing with persistent access, data exfiltration objectives, potential re-entry. The remediation scope is completely different. You might think you're clean when you're not even close.

Jordan: Right. And the commercial tooling choice is deliberate. When MuddyWater uses the same off-the-shelf malware that every ransomware affiliate uses, your EDR alerts, your threat intel feeds — they're going to match criminal TTPs, not nation-state signatures. The entire detection and attribution chain gets poisoned. My advice: if you're in a sector Iran cares about — energy, defense, government contractors, Middle East-adjacent businesses — treat every ransomware incident as potentially state-sponsored until you can prove otherwise. That changes your escalation procedures and your forensic depth.

Alex: Now let's shift to what I think is the operational story of the week. The Salesforce supply chain attack through Klue continues to expand. Dark Reading is reporting more victims emerging. Here's the chain: attackers breached Klue, a competitive intelligence platform, and used Klue's OAuth tokens to access downstream customers' Salesforce environments. LastPass has confirmed that customer support case data was stolen through this exact path. And here's the detail that should make every CISO wince — the attackers reportedly used a credential from 2022 that was never revoked after a pilot program ended.

Jordan: A four-year-old credential from a pilot. That's the kind of thing that kills you. And it's not exotic. Every enterprise has these. OAuth tokens granted to vendors during evaluations, pilots, proofs of concept — and nobody goes back to clean them up. This is a governance failure, not a technology failure.

Alex: Absolutely. And the blast radius here illustrates why SaaS-to-SaaS integrations are one of the most undermonitored attack surfaces in enterprise security. Your Salesforce instance might have dozens of third-party OAuth connections, each one a potential lateral path. If you don't have an inventory of every OAuth token and every third-party integration touching your SaaS platforms, you need one this week. Revoke anything that's not actively in use. And for the love of all things sacred, build a deprovisioning workflow for pilots and POCs that actually gets executed.

Jordan: The Klue-to-Salesforce chain is a template. Expect more of this. SaaS supply chain attacks are the new software supply chain attacks.

Alex: Pivoting to governance. President Trump signed Executive Order 14409 on Sunday, setting hard deadlines for federal post-quantum cryptography migration. Key establishment systems must migrate by December 31, 2030. Digital signatures by December 31, 2031. National security systems are on a separate track.

Jordan: Those dates sound far away. They are not far away. If you've ever done a cryptographic migration across a large enterprise, you know this is a multi-year program. Discovery alone — finding every system, every certificate, every key exchange — takes months. And for anyone with federal contracts, this isn't optional. These deadlines will cascade into contractor and vendor requirements just like every other federal mandate does.

Alex: This is the conversation I've been having with boards for two years. Harvest-now-decrypt-later is not a hypothetical threat. Adversaries are collecting encrypted data today with the expectation that quantum decryption will unlock it within this decade. The executive order confirms the US government believes that timeline is credible enough to mandate action. If you're in financial services, healthcare, defense contracting, or any regulated sector, your PQC migration roadmap should be a board-level agenda item. Start with a crypto inventory. You can't migrate what you can't find.

Jordan: Let's hit the vulnerability block. Two active exploitation stories that need your attention. First, CVE-2026-20230 in Cisco Unified Communications Manager. CVSS 8.6. It's an SSRF and input validation flaw that gives unauthenticated remote code execution. Honeypots are already detecting automated sweeps through Tor dropping webshells via a WebDialer SSRF exploit chain. This is not theoretical — it's happening now, at scale.

Alex: If you're running Unified CM or Unified CM SME, this is an emergency patch. If you can't patch immediately, isolate those systems from internet-facing exposure now. Verify that your WebDialer interface is not accessible externally. Check for webshells. This is the kind of vulnerability that gives attackers a foothold deep inside your communications infrastructure.

Jordan: Second, FortiBleed. We covered the initial FortiGate compromise wave, but the campaign has evolved significantly. Attackers deployed a custom Golang-based network sniffer on approximately 430,000 compromised FortiGate firewalls, and they've harvested roughly 110 million credentials from victim networks. This is ongoing.

Alex: Let me say that number again. 110 million credentials. If your organization runs FortiGate firewalls and you haven't already assumed credential compromise, you need to do that now. Force password resets across every system that was behind or transited through those firewalls. Review authentication logs for anomalous access patterns. And coordinate with Fortinet on the latest IOCs and remediation guidance.

Jordan: Moving quickly — Scattered Spider. Two members pleaded guilty on day one of what was expected to be a six-week trial in the UK. Charges relate to the August 2024 attack that crippled Transport for London. This is the group behind MGM, Caesars, and a long list of corporate breaches using social engineering.

Alex: The day-one guilty pleas signal the strength of the evidence and the increasing effectiveness of international law enforcement cooperation. For CISOs, two takeaways. One, your board and your insurers are watching these cases. The attack patterns Scattered Spider used — help desk social engineering, SIM swapping, MFA fatigue — are well documented. If you haven't hardened against them, you're accepting known risk. Two, law enforcement is getting better at this. Attribution has consequences now. That changes the calculus for some threat actors, though certainly not all.

Jordan: Quick hit on the AI agent supply chain story. AIR Security built a fake AI agent skill, pushed it through a popular skill marketplace, advertised it on Instagram, and it reached roughly 26,000 agents, including corporate accounts. Every skill security scanner they tested it against marked it safe.

Alex: This is the agentic AI governance gap in action. Enterprises are deploying AI agents, connecting them to skill marketplaces, and the security tooling simply doesn't exist yet to vet what those skills actually do. The payload here was benign by design — just collected email addresses — but the proof of concept is devastating. If a malicious skill can reach 26,000 agents including corporate ones without triggering a single alert, your agentic AI deployment is an unmonitored attack surface. If you're running enterprise agents, you need a governance framework for skill approval that doesn't rely on marketplace scanners alone.

Jordan: Last story. Varonis is reportedly exploring a sale. Blackstone, Thoma Bravo, and Vista Equity have expressed preliminary interest. This follows stock struggles and unfavorable market comparisons to Cyera.

Alex: If you're a Varonis customer, put this on your watch list. Private equity acquisitions of security vendors historically lead to cost optimization, which can mean changes to product roadmaps, support models, and pricing. No action required today, but start evaluating your dependency and optionality.

Jordan: Alright, zooming out. Alex, what's the thread this week?

Alex: The thread is convergence. AI accelerating offensive capabilities, state actors hiding behind criminal tradecraft, supply chains being exploited through forgotten OAuth tokens and unvetted AI skills. Every one of these stories points to the same conclusion: the attack surface is expanding faster than our ability to monitor it, and the sophistication gap between offense and defense is widening. The Five Eyes advisory isn't just about AI — it's a signal that the entire threat landscape is about to shift. CISOs who are still running 2024 playbooks are going to get caught flat-footed.

Jordan: Agreed. And the common operational failure across half these stories is the same: things we granted access to and forgot about. OAuth tokens from 2022. FortiGate firewalls that weren't patched. AI skills that weren't vetted. The boring hygiene work is still the most consequential work. The difference now is that the adversaries exploiting those gaps are faster, smarter, and increasingly AI-augmented.

Alex: Well said. If you take one thing from today's show, make it this: go audit your third-party integrations and revoke what you don't need. It's the highest-ROI security action you can take this week.

Jordan: That's the show for today.

Alex: Show notes and links to every story we covered are at cleartext.fm. We're back tomorrow. Stay sharp.

Jordan: Thanks for listening.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-24.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.