Cleartext – June 29, 2026
Monday, June 29, 2026·10:04
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – June 29, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 9 stories across 5 topic areas, including: US offers $10 million reward over Russian cyber campaign targeting Signal, WhatsApp; Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover; Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse.
Stories Covered
🌍 Geopolitical
US offers $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
The Record (Recorded Future) · Jun 29 · Relevance: █████████░ 9/10
Why it matters to CISOs: Russian GRU/FSB-linked groups socially engineering access to encrypted messaging platforms used by senior officials signals a direct threat to executive communications channels at enterprises with government exposure. CISOs should immediately audit use of Signal and WhatsApp by board members and senior leadership.
- Groups UNC5792 and UNC4221, linked to Russian intelligence and military services, have been targeting messaging accounts of government officials via social engineering
- US Department of State is offering up to $10 million for information identifying group members, indicating elevated threat priority
- Attack vector targets encrypted messaging backups and account linking features, not the encryption itself
Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover
Infosecurity Magazine · Jun 29 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A destructive ransomware attack attributed to Kremlin-backed actors against a major multinational manufacturer signals escalating Russian cyber operations beyond government targets into critical industrial and corporate sectors. CISOs at large manufacturers and critical infrastructure organizations should elevate threat levels.
- Jaguar Land Rover suffered a destructive cyber attack bearing hallmarks of Russian state-sponsored threat actors
- Novel ransomware and deliberate attribution obfuscation techniques were employed, complicating incident response and attribution
- Strategic timing of the attack aligns with broader patterns of Russian geopolitically motivated destructive operations against Western corporations
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
The Hacker News · Jun 29 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Gamaredon's 35 documented spear-phishing campaigns and expanded malware arsenal—including abuse of legitimate cloud services for C2—represent TTPs that routinely spill over from conflict-zone targets into Western enterprise supply chains and partners.
- Russian APT Gamaredon conducted 35 distinct spear-phishing campaigns against new targets throughout 2025, primarily in the second half of the year
- The group is abusing legitimate cloud services for command-and-control, making detection significantly harder with standard network controls
- ESET documented new malware variants expanding the group's operational capability and target scope
📡 Macro Trends
OpenAI Reveals GPT-5.6 Sol Cybersecurity Model, Restricts Early Access
Infosecurity Magazine · Jun 29 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: The US government's decision to gate access to OpenAI's most capable cybersecurity-focused AI model signals a new era of AI export controls and dual-use AI governance that will shape enterprise security tooling procurement and vendor risk assessments.
- OpenAI is previewing GPT-5.6 Sol—its flagship cybersecurity-oriented model—exclusively to vetted partners at the US government's request before broader release
- The coordinated government rollout suggests regulators view advanced AI cybersecurity capabilities as strategically sensitive dual-use technology
- CISOs evaluating AI-powered security tools should anticipate access restrictions and procurement complexity for top-tier models
Mozilla warns of indirect prompt injection risk in AI coding agents
Help Net Security · Jun 29 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Mozilla's 0DIN proof-of-concept demonstrates that malicious repositories can silently hijack AI coding agents like Claude Code to compromise developer machines without any malicious code—a novel supply chain vector that enterprises deploying AI-assisted development must immediately assess and govern.
- Mozilla's Zero Day Investigative Network demonstrated a proof-of-concept attack where a malicious GitHub repository uses indirect prompt injection to compromise developer machines via AI coding agents
- The attack requires no malicious code in the repository itself, bypassing traditional static analysis and code review controls
- AI coding agents such as Claude Code are affected, and the attack surface grows with every enterprise that adopts AI-assisted software development pipelines
🔓 Data Breach
US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw
Infosecurity Magazine · Jun 29 · Relevance: █████████░ 9/10
Why it matters to CISOs: A zero-day exploit against Oracle PeopleSoft compromising the NAIC—the body that sets standards for the US insurance regulatory framework—has direct implications for financial sector CISOs managing regulatory data and PeopleSoft deployments.
- National Association of Insurance Commissioners (NAIC) confirmed attackers exploited a zero-day in Oracle PeopleSoft to access its IT systems
- NAIC sets regulatory standards for the US federal insurance system, meaning sensitive regulatory and industry data may be exposed
- Zero-day exploitation confirms Oracle enterprise software is under active, targeted attack across multiple products simultaneously
Data breach exposes up to 14.2 million email logins at six ISPs
BleepingComputer · Jun 28 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Exposure of 14.2 million email credentials across six ISPs creates immediate credential stuffing risk for enterprise organizations whose employees use personal ISP email accounts linked to corporate identities or reuse passwords, and warrants proactive dark web monitoring and MFA enforcement review.
- KDDI Corporation disclosed a breach of an email system shared across five other Japanese ISPs, exposing up to 14.2 million email login credentials
- The shared infrastructure model amplified the breach scope significantly beyond a single provider
- Exposed email credentials frequently appear in subsequent credential stuffing campaigns targeting enterprise SSO and VPN portals
⚖️ Governance & Policy
What the post-quantum executive order really demands of CISOs
CyberScoop · Jun 29 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Federal PQC migration deadlines of 2030 and 2031 create a multi-year transformation program that most enterprise security teams have not yet begun, making this an urgent board-level conversation about cryptographic risk and capital planning.
- US executive order mandates post-quantum cryptography migration with hard deadlines in 2030 and 2031
- Most organizations have not yet inventoried cryptographic assets or begun transition planning, leaving an extremely narrow execution window
- CISOs face both compliance obligations and a 'harvest now, decrypt later' threat from adversaries already collecting encrypted data
🚨 Critical Vulnerability
Hackers now exploit critical Oracle E-Business flaw in attacks
BleepingComputer · Jun 29 · Relevance: █████████░ 9/10
Why it matters to CISOs: Oracle E-Business Suite is widely deployed in large enterprise financial operations; active exploitation of CVE-2026-46817 in ERP and financial systems demands immediate patching prioritization and threat hunting in affected environments.
- CVE-2026-46817 is a critical vulnerability in Oracle E-Business Suite financial applications with confirmed active exploitation
- Threat intelligence from Defused confirms attackers have moved from PoC to active attack campaigns
- Oracle EBS is used by thousands of enterprise organizations for finance, HR, and supply chain operations
Further Reading
- 🌍 US offers $10 million reward over Russian cyber campaign targeting Signal, WhatsApp — The Record (Recorded Future)
- 🌍 Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover — Infosecurity Magazine
- 🌍 Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse — The Hacker News
- 📡 OpenAI Reveals GPT-5.6 Sol Cybersecurity Model, Restricts Early Access — Infosecurity Magazine
- 📡 Mozilla warns of indirect prompt injection risk in AI coding agents — Help Net Security
- 🔓 US Federal Insurance Regulator Confirms Data Breach Via Oracle Flaw — Infosecurity Magazine
- 🔓 Data breach exposes up to 14.2 million email logins at six ISPs — BleepingComputer
- ⚖️ What the post-quantum executive order really demands of CISOs — CyberScoop
- 🚨 Hackers now exploit critical Oracle E-Business flaw in attacks — BleepingComputer
Full Transcript
Click to expand full episode transcript
Alex: ...
Jordan: Monday morning, and the US government is putting a ten million dollar bounty on Russian hackers who figured out you don't need to break encryption if you can just social engineer your way into someone's Signal account. That's where we start today.
Alex: Welcome to Cleartext. It's Monday, June 29th. I'm Alex Chen, alongside Jordan Reeves. We've got a packed show. Russian cyber operations are escalating on multiple fronts, from encrypted messaging platforms to destructive attacks on major manufacturers. We'll cover a federal insurance regulator breached through an Oracle zero-day, Oracle again under active exploitation in E-Business Suite, Mozilla raising red flags about AI coding agents as a novel supply chain vector, the government gating access to OpenAI's new cybersecurity model, and why your post-quantum migration clock is ticking louder than you think. Let's get into it.
Jordan: So let's start with this State Department bounty. Ten million dollars for information on two groups, UNC5792 and UNC4221, both linked to Russian intelligence services. What they're doing is targeting Signal and WhatsApp accounts of government officials, but here's what matters for our audience: they're not breaking the encryption. They're exploiting account linking features and backup mechanisms through social engineering. They're going after the human layer and the platform design choices that sit around the cryptography.
Alex: And this is directly relevant if you're a CISO at any organization where senior leadership or board members use encrypted messaging for sensitive business communications. Which is basically every large enterprise at this point. The assumption that Signal or WhatsApp equals secure is dangerously incomplete. The encryption is sound. The account management, the backup configurations, the device linking workflows, those are the attack surface. If you haven't audited how your executives are using these platforms, how their accounts are configured, whether they've linked devices they've forgotten about, this is your prompt to do it this week.
Jordan: The ten million dollar bounty tells you where the US government ranks this threat. That's not a routine number. That's reserved for operations they consider strategically significant. And it tracks with what we're seeing more broadly from Russian cyber operations right now, which is a clear escalation across multiple vectors simultaneously.
Alex: Which brings us directly to the Jaguar Land Rover attack. A destructive cyberattack attributed to Kremlin-backed actors. Not ransomware for profit. Destructive. Novel ransomware variants with deliberate attribution obfuscation.
Jordan: This is important to parse carefully. When we say destructive with attribution obfuscation, what that means operationally is the attackers wanted to cause damage and make it hard to prove who did it. That's a different playbook than criminal ransomware. Criminal groups want you to know who they are so you pay them. State actors deploying destructive capability behind false flags are sending a geopolitical message while maintaining deniability. The strategic timing here aligns with broader Russian patterns of hitting Western corporate targets during periods of diplomatic tension.
Alex: For CISOs at large manufacturers, critical infrastructure, anyone in the automotive supply chain, this is a direct signal to elevate your threat posture. The conversation with your board should be explicit: state-sponsored destructive attacks against Western corporations are not theoretical. They're happening to household names. Your incident response plans need to account for scenarios where the attacker's objective is destruction, not monetization.
Jordan: And rounding out the Russia picture, Gamaredon, which ESET has documented running thirty-five distinct spear-phishing campaigns against new targets throughout 2025. They've expanded their malware arsenal and, critically, they're abusing legitimate cloud services for command and control.
Alex: The cloud C2 piece is what I want CISOs to focus on. When your threat actors are tunneling command and control through services that your firewalls and proxies are configured to trust, your standard network detection controls have a significant blind spot. This is a TTP that routinely spills over from conflict-zone targeting into Western enterprise supply chains, particularly if you have any partners, subsidiaries, or operations touching Eastern Europe.
Jordan: Three Russian stories, three different attack vectors, one coherent escalation pattern. That's the macro picture this Monday morning.
Alex: Let's shift to the NAIC breach, because this one has direct financial sector implications. The National Association of Insurance Commissioners, which sets regulatory standards for the entire US federal insurance system, confirmed that attackers exploited a zero-day in Oracle PeopleSoft to access their IT systems.
Jordan: The nature of the target matters as much as the exploit here. NAIC holds sensitive regulatory data, industry standards, examination information. If you're a CISO at an insurance company or any financial institution that interacts with NAIC regulatory frameworks, you need to be asking what data was exposed and whether it has downstream implications for your organization's regulatory posture.
Alex: And this connects directly to our next story. CVE-2026-46817, a critical vulnerability in Oracle E-Business Suite, now under active exploitation. Threat intelligence from Defused confirms attackers have moved from proof of concept to active campaigns. Oracle EBS runs financial operations, HR, supply chain for thousands of large enterprises.
Jordan: Two Oracle enterprise products, PeopleSoft and E-Business Suite, both under active targeted attack simultaneously. If you're running either of these, patch prioritization is not a debate. It's an emergency. And if your patching cycle for Oracle is quarterly, you need to have a conversation about whether that cadence is survivable in this threat environment.
Alex: The action items are straightforward. Immediate patching for CVE-2026-46817 if you're on E-Business Suite. Threat hunting in your PeopleSoft environments. And an honest assessment of your Oracle patching velocity relative to the speed at which these vulnerabilities are being weaponized.
Jordan: Let's talk about something that's going to reshape how CISOs think about their development pipelines. Mozilla's Zero Day Investigative Network published a proof of concept showing that a malicious GitHub repository can compromise a developer's machine through AI coding agents, specifically Claude Code, without containing a single line of malicious code.
Alex: I want to make sure that lands properly. No malicious code in the repository. The attack uses indirect prompt injection to manipulate the AI agent into taking harmful actions on the developer's machine. Your static analysis tools won't catch it. Your code review process won't catch it. Because there's nothing malicious to find in the code itself.
Jordan: The attack surface here scales with adoption. Every enterprise that's rolling out AI-assisted development, and that's most of you at this point, has just inherited a novel supply chain risk that your existing controls were not designed to address. The AI agent becomes the vulnerability. It reads context from the repository, gets manipulated by crafted content, and then acts with whatever permissions it's been granted on the developer's workstation.
Alex: If you're a CISO who's been approving AI coding tool rollouts, and you should be, because the productivity gains are real, you now need a governance framework around what those agents can do, what permissions they operate with, and how you're monitoring their behavior. This isn't about blocking adoption. It's about establishing guardrails before this vector gets weaponized at scale.
Jordan: And speaking of AI governance, OpenAI is previewing GPT-5.6 Sol, which they're positioning as their flagship cybersecurity-oriented model, exclusively to vetted partners at the US government's request before broader release.
Alex: This is a watershed moment. The US government is treating advanced AI cybersecurity capabilities as strategically sensitive dual-use technology. Gated access. Export control dynamics. This will directly affect your procurement. If you're evaluating AI-powered security tools, the most capable models may come with access restrictions, compliance requirements, and geopolitical considerations that didn't exist six months ago.
Jordan: It also creates a two-tier market. Organizations with government relationships and appropriate clearances get early access to the most capable defensive tools. Everyone else waits. CISOs need to factor that asymmetry into their AI security strategy and vendor evaluation processes.
Alex: Let's close our coverage with post-quantum cryptography, because the CyberScoop piece on the executive order deadlines deserves attention. Federal PQC migration deadlines are set for 2030 and 2031. That sounds far away. It is not.
Jordan: Four years to inventory every cryptographic asset in your environment, evaluate quantum-vulnerable implementations, plan migration paths, test compatibility, and execute the transition. Most organizations haven't started step one. And the harvest-now-decrypt-later threat means adversaries are already collecting your encrypted data today, betting they'll be able to decrypt it with quantum capabilities within a decade.
Alex: This is a board-level capital planning conversation. PQC migration is not a technology project. It's a multi-year transformation program that touches every system, every protocol, every certificate, every key. If you haven't started the cryptographic inventory, you're already behind the curve. The window for orderly execution is closing, and disorderly execution of cryptographic transitions is how you break production systems.
Jordan: Briefly on the KDDI breach in Japan. Fourteen point two million email credentials exposed across six ISPs sharing common infrastructure. The shared infrastructure model amplified the blast radius dramatically.
Alex: The enterprise angle is credential stuffing. Your employees have personal email accounts at ISPs. If they've reused passwords or linked those accounts to corporate identities, this breach feeds directly into attacks against your SSO portals, your VPN gateways, your cloud tenants. Proactive dark web monitoring and an MFA enforcement audit are warranted.
Jordan: Looking at the week ahead, Alex, there's a clear theme. The perimeter of what CISOs have to defend keeps expanding in ways that traditional security architecture wasn't built for. AI coding agents as attack vectors. Encrypted messaging platforms compromised through social engineering. Cloud services weaponized for C2. State actors deploying destructive capability against commercial targets.
Alex: The common thread is that the trust assumptions embedded in our architectures are being systematically exploited. We trust encrypted messaging. We trust AI agents to read code safely. We trust cloud services. We trust that our Oracle patches can wait until the quarterly cycle. Every one of those assumptions took a hit today. The CISOs who will navigate this well are the ones having honest conversations with their boards about which trust assumptions they're still carrying and which ones need to be revisited.
Jordan: And doing it with urgency. Because the adversaries on the other side of these stories aren't waiting for your next board meeting.
Alex: That's our show for Monday, June 29th. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.
Jordan: Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-06-29.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.