Cleartext Week in Review – July 11, 2026
Saturday, July 11, 2026·11:14
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – July 11, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 17 stories across 5 topic areas, including: Srsly Risky Biz: US Supreme Court undermines Section 702 intel; Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year; China, India ran separate spying campaigns against same Pakistani police force.
Stories Covered
🌍 Geopolitical
Srsly Risky Biz: US Supreme Court undermines Section 702 intel
Risky Business News · Jul 09 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A Supreme Court ruling that puts the EU-US Data Privacy Framework at risk could invalidate the legal basis for transatlantic data transfers, forcing CISOs at multinationals to urgently revisit data residency, SCCs, and cross-border incident sharing agreements.
- A new US Supreme Court decision threatens the current EU-US data sharing agreement by challenging Section 702 intelligence collection from Europe
- If the current framework is struck down, it would mirror the Schrems I and II disruptions and force another scramble for alternative transfer mechanisms
- Canada separately disclosed active offensive cyber operations against adversaries in the same week, signaling a broader shift in allied nations' cyber posture transparency
Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year
TechCrunch Security · Jul 06 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Canada's unprecedented public disclosure of offensive cyber operations against a ransomware gang signals that Five Eyes nations are moving toward active offensive disruption as a normalized policy tool — a shift that affects threat actor risk calculus and may reduce some ransomware-group operational tempo.
- Canada's CSE publicly disclosed it conducted offensive cyber operations against drug traffickers, extremists, and a ransomware gang in its annual report
- Marks a significant transparency shift for an agency that historically never acknowledged offensive operations
- Aligns with the UK and Australia's increased willingness to attribute and disrupt adversary infrastructure
China, India ran separate spying campaigns against same Pakistani police force
The Record (Recorded Future) · Jul 10 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Simultaneous nation-state intrusions by rival APTs into the same target illustrate that shared infrastructure and geopolitically sensitive supply-chain partners can be breached by multiple adversaries concurrently — a scenario that complicates attribution and incident response for multinationals operating in contested regions.
- China and India independently conducted espionage operations against the same Pakistani provincial police force between February 2024 and April 2026
- In some cases, attackers from both nations breached the exact same systems simultaneously
- Centered on the force responsible for Balochistan province, site of a long-running separatist insurgency with regional geopolitical significance
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
CyberScoop · Jul 07 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: China-aligned actors exploiting Roundcube webmail in physics and engineering departments of US and Canadian universities suggests active pre-positioning for technology and research theft — organizations with academic research partnerships or alumni networks should audit their email infrastructure exposure.
- Proofpoint identified ongoing exploitation of Roundcube CVE-2024-42009 (CVSS 9.3) against physics and engineering departments at US and Canadian universities
- Campaign assessed as likely ongoing with credential harvesting as the primary objective
- Parallels UAT-7810's separate ORB network expansion via LONGLEASH malware targeting internet-facing network devices, reported the same week
📡 Macro Trends
JadePuffer: The First Complete LLM-Driven Ransomware Attack
Dark Reading · Jul 06 · Relevance: █████████░ 9/10
Why it matters to CISOs: The first documented end-to-end LLM-orchestrated ransomware attack marks a qualitative shift in threat actor capability that demands CISOs reassess detection dwell-time assumptions and accelerate pre-attack resilience postures.
- An agentic AI actor exploited a Langflow vulnerability to exfiltrate data from a production database and encrypt other systems
- The attack represents the first known complete ransomware chain executed by an LLM-driven agent, not just an AI-assisted human
- Langflow CVE was simultaneously added to CISA's KEV catalog, confirming active exploitation at scale
🔓 Data Breach
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
Dark Reading · Jul 08 · Relevance: █████████░ 9/10
Why it matters to CISOs: A single threat actor using agentic AI compressed what would typically be a weeks-long cloud compromise into 72 hours, directly challenging the response window assumptions baked into most enterprise incident response plans.
- Solo attacker used AI workflows to chain cloud misconfigurations and stolen credentials to extort a large AWS customer
- Sygnia's forensic report confirmed agentic AI dramatically accelerated the attack timeline to just 72 hours
- Highlights that AI is collapsing the detection-to-damage window, making pre-attack resilience essential
Accenture faces massive data breach that could put clients at risk
Cybersecurity Dive · Jul 08 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A breach at one of the world's largest cybersecurity and IT services firms — with source code, encryption keys, and client data allegedly exfiltrated — is a direct third-party risk event for any enterprise that has Accenture managing security operations, cloud environments, or sensitive development work.
- Threat actor claims to have stolen source code, encryption keys, and additional sensitive data from Accenture
- Potential downstream impact on Accenture's global enterprise client base across financial services, government, and critical infrastructure sectors
- Breach disclosed in the same week as the CISA contractor credential leak, amplifying concerns about security services supply chain integrity
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access
The Hacker News · Jul 10 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Attackers are now specifically targeting passkey enrollment flows — the very MFA upgrade organizations are deploying to replace phishable credentials — meaning CISOs cannot treat passkey adoption as a finish line without also securing the enrollment process itself.
- Threat actor O-UNC-066 uses voice-based fake security requests to trick Microsoft 365 users into enrolling attacker-controlled Entra passkeys
- Attack uses a panel-controlled phishing kit capable of hijacking the passkey enrollment process, bypassing the security benefit of the upgrade
- Simultaneous campaigns using DEBULL device-code phishing and Forg365 AI-assisted AiTM kits confirm M365 identity remains the dominant enterprise attack surface this week
Another massive data breach exposed millions of driver’s license numbers
TechCrunch Security · Jul 08 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: AssuranceAmerica's breach of 6.9 million records — achieved via a single employee compromise — is the largest known driver's license number breach of 2026 and a reminder that identity data aggregators remain high-value, under-defended targets with cascading fraud implications for individuals and insurers.
- Hackers accessed more than 6.9 million records at US insurance provider AssuranceAmerica by targeting a single employee
- Designated the largest known breach of driver's license numbers so far in 2026
- Attack vector was employee-targeted, consistent with the broader vishing and credential-theft campaigns observed across the week
⚖️ Governance & Policy
Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence
The Record (Recorded Future) · Jul 10 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Dual ransomware convictions in a single week — including the unprecedented jailing of a ransomware negotiator who double-crossed his own clients — signals sustained DOJ momentum on ransomware prosecution and raises the legal risk profile for any firm that plays both sides of an extortion event.
- Ryuk operator Karen Vardanyan pleaded guilty, faces 15 years and agreed to pay $1.2M in restitution
- Former ransomware negotiator Angelo Martino sentenced to 70 months for feeding confidential client data to BlackCat affiliates, enabling $75.3M in extortion across five victims
- Third ransomware negotiator jailed in the same week, establishing a pattern of DOJ scrutiny of the incident response ecosystem
CISA looks to remedy ailments from big May credential leak
CyberScoop · Jul 10 · Relevance: ████████░░ 8/10
Why it matters to CISOs: CISA's public forensic post-mortem on its own credential leak — revealing the agency had to build its incident playbook during the incident — is a direct object lesson for CISOs: if the nation's top cyber defense agency lacked a tested playbook, most enterprises are similarly exposed.
- A CISA contractor employee uploaded credentials and cloud access keys to a public GitHub repository in May
- CISA's forensic report admitted the agency had to build its incident playbook in real time during the response
- Agency is now strengthening sensitive material protections, researcher vulnerability reporting, and incident preparedness plans under congressional scrutiny
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
CyberScoop · Jul 09 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Operation First Light's scale — 5,800 arrests, 142,000 identified victims across 97 countries — demonstrates that multilateral law enforcement is increasingly effective against the fraud and social-engineering ecosystem that feeds enterprise phishing and BEC losses.
- Operation First Light 2026 resulted in 5,811 arrests across 97 countries
- More than 142,000 victims of social-engineering scams were identified
- Operation was notably funded by the Chinese government via Interpol, adding a geopolitical dimension to the coordination
Alleged member of Scattered Spider extradited to US
Cybersecurity Dive · Jul 06 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: The Scattered Spider extradition — combined with court filings revealing a Windows device ID helped FBI trace a second suspect — shows law enforcement has developed repeatable forensic techniques against this group that previously seemed untouchable, relevant context for boards asking about cyber insurance and legal liability.
- Dual US-Estonian citizen extradited and charged in connection with a luxury jewelry retailer hack
- Separate court filing revealed a persistent Windows device ID was used to link a 19-year-old suspect to a May 2025 intrusion
- Group-IB analysis this week characterized Scattered Spider as a decentralized collective of independent clusters, complicating attribution and defense
🚨 Critical Vulnerability
URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
The Hacker News · Jul 10 · Relevance: █████████░ 9/10
Why it matters to CISOs: Progress Software's emergency directive to shut down on-premises ShareFile servers mirrors the MOVEit playbook and signals another mass-exploitation event targeting enterprise file-transfer infrastructure — immediate action required for any org running Storage Zone Controllers.
- Progress identified a 'credible external security threat' and preemptively disabled affected customer accounts
- Customers instructed to immediately shut down Windows servers running Storage Zone Controllers
- Progress has a prior history with MOVEit mass exploitation; initial access brokers have already been linked to CitrixBleed2 exploitation in the same window
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
The Hacker News · Jul 09 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The 'Friendly Fire' proof-of-concept shows that AI security tooling from Anthropic and OpenAI can be weaponized against the very organizations deploying them, creating a new liability surface for teams that have adopted AI-assisted code review.
- AI Now Institute demonstrated that Claude Code and OpenAI Codex, running in autonomous mode, can be tricked into executing attacker-supplied code during security scans
- Attack works without any privilege escalation — the agent's own approved permissions become the attack vector
- Coincides with HalluSquatting research showing AI coding assistants can be tricked into fetching malicious packages via hallucinated package names
Initial access broker linked to weaponization of CitrixBleed2 flaw
Cybersecurity Dive · Jul 10 · Relevance: ████████░░ 8/10
Why it matters to CISOs: CitrixBleed2 exploitation by a known initial access broker feeding DragonForce ransomware means any organization with unpatched NetScaler appliances faces imminent ransomware risk, not just credential theft.
- An initial access broker has weaponized the CitrixBleed2 NetScaler memory-disclosure flaw and is selling access to ransomware affiliates
- DragonForce ransomware group is the identified downstream buyer of compromised access
- Pattern mirrors the original CitrixBleed exploitation wave that impacted hundreds of enterprises in 2023
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
The Hacker News · Jul 08 · Relevance: ████████░░ 8/10
Why it matters to CISOs: CVE-2026-43499 ships by default in virtually every mainstream Linux distribution since 2011 and requires no special permissions to exploit — any enterprise running Linux servers, cloud instances, or containers must treat this as a priority patch regardless of existing compensating controls.
- GhostLock (CVE-2026-43499) is a 15-year-old kernel flaw present in essentially all mainstream Linux distributions since 2011
- Any logged-in user can achieve full root control with no special permissions, unusual settings, or network access required
- Google separately paid $250K for a related Linux VM-escape flaw the same week, underscoring the severity of the Linux vulnerability cluster
Further Reading
- 🌍 Srsly Risky Biz: US Supreme Court undermines Section 702 intel — Risky Business News
- 🌍 Canadian spy agency says it hacked drug traffickers, extremists, and a ransomware gang last year — TechCrunch Security
- 🌍 China, India ran separate spying campaigns against same Pakistani police force — The Record (Recorded Future)
- 🌍 Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities — CyberScoop
- 📡 JadePuffer: The First Complete LLM-Driven Ransomware Attack — Dark Reading
- 🔓 Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours — Dark Reading
- 🔓 Accenture faces massive data breach that could put clients at risk — Cybersecurity Dive
- 🔓 Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access — The Hacker News
- 🔓 Another massive data breach exposed millions of driver’s license numbers — TechCrunch Security
- ⚖️ Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence — The Record (Recorded Future)
- ⚖️ CISA looks to remedy ailments from big May credential leak — CyberScoop
- ⚖️ Interpol cybercrime crackdown nets 5,800 arrests across 97 countries — CyberScoop
- ⚖️ Alleged member of Scattered Spider extradited to US — Cybersecurity Dive
- 🚨 URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat — The Hacker News
- 🚨 Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It — The Hacker News
- 🚨 Initial access broker linked to weaponization of CitrixBleed2 flaw — Cybersecurity Dive
- 🚨 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros — The Hacker News
Full Transcript
Click to expand full episode transcript
Jordan: If there's one sentence that captures this week, it's this: the machines are faster than your playbook. We saw the first fully autonomous LLM-driven ransomware attack, a solo operator compressing an AWS breach into 72 hours using agentic AI, and the security tools we're deploying to defend ourselves getting weaponized against us. The assumption that you have days or weeks to detect and respond is now formally obsolete.
Alex: Welcome to Cleartext. I'm Alex Chen, alongside Jordan Reeves. This is your Saturday Week in Review for the week ending July 11th, 2026. If you couldn't keep up this week, here's what mattered and what it means. We've got four big themes. First, the one Jordan just flagged — AI as an autonomous threat actor is no longer theoretical, it's operational. Second, the identity and authentication stack is under siege, and the very passkey rollouts you're investing in are being targeted. Third, the legal and enforcement landscape shifted materially, from ransomware convictions to a Supreme Court ruling that could blow up transatlantic data transfers again. And fourth, critical vulnerabilities — including a MOVEit-style déjà vu from Progress Software — that demand Monday morning action. Let's get into it.
Jordan: So let's start with the AI threat story because I think it's the most consequential development of the week, possibly of the quarter. JadePuffer. An agentic AI actor — not a human using ChatGPT to write a phishing email, but an autonomous LLM agent — exploited a Langflow vulnerability, exfiltrated data from a production database, and encrypted systems. Soup to nuts. No human operator in the loop on the attack side.
Alex: And that Langflow CVE was simultaneously added to CISA's Known Exploited Vulnerabilities catalog, which tells you this isn't one isolated incident. This is being exploited at scale. But Jordan, what makes JadePuffer different from every other AI-assisted attack we've covered?
Jordan: The word "assisted" is doing all the work there. Every previous case was a human using AI to accelerate a phase — write better phishing lures, generate polymorphic payloads, whatever. JadePuffer is the first documented case where the entire kill chain was executed by an autonomous agent. Reconnaissance, exploitation, data exfiltration, encryption. The agent made tactical decisions during the attack. That is a qualitative shift in what we're defending against.
Alex: And then layer on the Sygnia report about the lone attacker who breached an AWS environment in 72 hours using agentic AI workflows. This was a human operator, but a single individual who chained cloud misconfigurations and stolen credentials at a speed that would have taken a team weeks. Sygnia's forensic analysis confirmed the AI dramatically compressed the timeline.
Jordan: Right, so you've got two data points in the same week. One fully autonomous, one AI-augmented solo operator. Both arriving at the same conclusion: your detection-to-damage window just collapsed. If your IR plan assumes you have five to seven days of dwell time to detect lateral movement, you are working with outdated assumptions.
Alex: For the CISOs listening, the practical implication is this: pre-attack resilience is now the game. You cannot rely on detection speed alone. Immutable backups, microsegmentation, assume-breach architecture — these move from best practice to table stakes. And honestly, this needs to be a board conversation this month. The threat model has changed.
Jordan: And here's the darker twist. The Friendly Fire research from the AI Now Institute showed that Claude Code and OpenAI Codex, running autonomously, can be tricked into executing attacker-supplied code during security scans. The AI agents you're deploying to find vulnerabilities in your code can be weaponized to run the attacker's code on your infrastructure. Using the agent's own approved permissions. No privilege escalation needed.
Alex: So we're in a world where AI is simultaneously the threat actor, the attack accelerant, and a potential liability in your own defensive stack. If you've adopted AI-assisted code review, you need to audit what autonomous permissions those tools have. This week.
Jordan: And the HalluSquatting research compounds it — AI coding assistants hallucinating package names that attackers then register with malicious payloads. The attack surface of AI tooling itself is expanding faster than most security teams are tracking it.
Alex: Let's pivot to identity, because this was also a significant week on that front. The passkey enrollment phishing campaign is the one I want CISOs to really internalize.
Jordan: O-UNC-066. Tracked by Okta. They're using voice-based social engineering — vishing — to trick Microsoft 365 users into enrolling attacker-controlled passkeys in Entra. They have a panel-controlled phishing kit specifically designed to hijack the passkey enrollment flow. Think about what that means. Organizations are investing heavily in passkeys as the post-password future. And attackers are now specifically targeting the enrollment ceremony itself.
Alex: This is critical. Passkeys are genuinely more secure than passwords and legacy MFA. But the enrollment process is a moment of trust establishment, and if you don't secure that moment, you've handed the attacker a credential that's harder to revoke and harder to detect as compromised. CISOs cannot treat passkey deployment as a finish line. You need to secure the enrollment lifecycle with the same rigor you'd apply to certificate issuance.
Jordan: And this wasn't the only M365 identity attack this week. We also saw the DEBULL device-code phishing campaign and the Forg365 AI-assisted adversary-in-the-middle kit. Three separate campaigns all targeting Microsoft 365 identity in the same week. M365 identity is the dominant enterprise attack surface, full stop. The AssuranceAmerica breach reinforces this — 6.9 million records, largest driver's license number breach of the year, achieved by compromising a single employee. One person. One credential. 6.9 million records.
Alex: The common thread across all of these is that identity remains the perimeter. And every flavor of identity attack was represented this week — vishing, phishing, credential theft, enrollment hijacking. If your identity security program isn't your single largest security investment right now, you're misallocated.
Jordan: Let's move to the legal and geopolitical landscape because there were some genuinely consequential developments. The biggest one, and I think the most underappreciated story of the week, is the Supreme Court ruling that threatens Section 702 and the EU-US Data Privacy Framework.
Alex: This is a potential earthquake for any multinational. The current framework is what allows lawful transatlantic data transfers. If this ruling leads to the framework being invalidated, we're looking at Schrems III. CISOs at global companies need to be talking to their DPOs and general counsel right now about Standard Contractual Clauses, data residency architectures, and whether their cross-border incident sharing agreements survive a framework collapse.
Jordan: And the practical problem is worse than Schrems II because organizations have now built more infrastructure on the assumption that the current framework is stable. Unwinding that is harder and more expensive. I'd say probability of full invalidation is still moderate, but the downside risk is enormous. This is a scenario-plan-now situation.
Alex: On the enforcement side, the dual ransomware convictions were remarkable. Ryuk operator Vardanyan pleading guilty, facing 15 years, agreeing to $1.2 million in restitution. And then Angelo Martino — a ransomware negotiator who was feeding confidential client data to BlackCat affiliates — sentenced to 70 months.
Jordan: The Martino case is the one that should make every CISO's ears perk up. This is a person who was hired by victim organizations to negotiate on their behalf, and he was secretly feeding their data — their financial exposure, their willingness to pay, their internal communications — to the attackers. He enabled $75.3 million in extortion across five victims. Three ransomware negotiators jailed in the same week. DOJ is clearly scrutinizing the entire incident response ecosystem now.
Alex: The implication for CISOs is direct: vet your incident response partners with the same rigor you'd apply to any critical vendor. Understand their conflicts of interest. Get contractual protections around data handling during an incident. And brief your board that the IR ecosystem itself has become a risk surface.
Jordan: On the geopolitical front, Canada's CSE publicly disclosing offensive cyber operations against a ransomware gang is a notable transparency shift. Five Eyes nations are normalizing offensive disruption as a public policy tool. Combined with the Interpol operation — 5,800 arrests across 97 countries — law enforcement pressure on the cybercrime ecosystem is genuinely intensifying.
Alex: Although I'll note the Interpol operation was notably funded by the Chinese government, which adds a fascinating geopolitical layer when you consider that Chinese APTs were simultaneously running espionage operations against Pakistani police alongside Indian intelligence, and separately exploiting Roundcube webmail to target physics and engineering departments at US and Canadian universities. The geopolitical picture is, as always, complicated.
Jordan: Now let's talk vulnerabilities, because there are items here that require action Monday morning. Progress Software telling ShareFile customers to shut down their Storage Zone Controllers immediately. This is the MOVEit company. Same playbook. Credible external security threat, preemptive account disablement, emergency shutdown directive.
Alex: If you're running on-premises ShareFile Storage Zone Controllers, this should already be done. If you haven't confirmed with your team, do it before Monday. The pattern here is identical to MOVEit in 2023 — enterprise file transfer infrastructure targeted for mass exploitation. We know how this movie ends if you're slow.
Jordan: CitrixBleed2 is the other urgent one. An initial access broker has weaponized the NetScaler memory-disclosure flaw and is actively selling access to DragonForce ransomware affiliates. If you have unpatched NetScaler appliances, you don't have a vulnerability management problem. You have a ransomware problem.
Alex: And then GhostLock. CVE-2026-43499. A 15-year-old Linux kernel flaw present in every mainstream distribution since 2011. Any logged-in user can achieve full root. No special permissions required. Container escape is possible. Google paid a quarter million dollars for a related VM-escape flaw the same week. If you run Linux anywhere — servers, cloud instances, containers — this is a priority patch.
Jordan: Oh, and the Accenture breach. Source code, encryption keys, client data allegedly exfiltrated from one of the world's largest IT and security services firms. If Accenture manages any of your security operations, cloud environments, or development work, you have a third-party risk event to investigate. Coming the same week as the CISA credential leak forensic report, the theme is unmistakable: the security supply chain itself is compromised.
Alex: Which brings us to the defining characteristic of this week. Jordan, what's your take?
Jordan: This was the week the assumptions broke. The assumption that you have days to detect an intrusion — broken by agentic AI. The assumption that passkeys solve your identity problem — broken by enrollment hijacking. The assumption that your IR negotiator is on your side — broken by criminal prosecution. The assumption that your security vendor is secure — broken by Accenture and CISA. Every layer of the trust model took a hit this week.
Alex: I agree. And for CISOs going into next week, the action items are concrete. One, reassess your dwell-time assumptions in light of AI-accelerated attacks. Two, audit your passkey enrollment controls. Three, confirm ShareFile and NetScaler patching status. Four, assess your Accenture exposure if applicable. And five, get ahead of the Data Privacy Framework risk with your legal team. This is a week where waiting costs you.
Jordan: Monday morning, not Monday afternoon.
Alex: That's the Week in Review for July 11th, 2026. The daily show returns Monday with fresh coverage. Full show notes and links to every story we discussed today are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. Have a good weekend. Patch something.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-11.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.