Cleartext – July 28, 2026
Tuesday, July 28, 2026·10:30
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – July 28, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 10 stories across 5 topic areas, including: Hackers used autonomous AI agent to spy on Thailand's finance ministry; Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays; NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework.
Stories Covered
🌍 Geopolitical
Hackers used autonomous AI agent to spy on Thailand's finance ministry
The Record (Recorded Future) · Jul 27 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The first confirmed use of an autonomous AI agent in a state-level cyber-espionage campaign against a government finance ministry signals a step-change in attacker capability — CISOs at financial institutions and government contractors should treat AI-assisted persistent access as an emergent threat model requiring updated detection logic.
- Threat actors deployed an autonomous AI agent to conduct cyber-espionage against Thailand's Ministry of Finance
- This represents one of the first publicly confirmed uses of agentic AI in a nation-state intrusion campaign
- The incident highlights that AI agents can operate autonomously to maintain persistence and exfiltrate data at scale
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Hacker News · Jul 28 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: An Iranian state-backed group is deploying a previously undocumented backdoor and custom WebSocket tunnelers across Middle East, Africa, and South Asia targets — enterprises with operations or supply chains in these regions, particularly in defense, energy, and government-adjacent sectors, should update threat hunt rules to detect NightLedger indicators.
- Nimbus Manticore (UNC1549) has been attributed to attacks using a new Windows backdoor called NightLedger
- The group also uses two custom WebSocket tunnelers to proxy traffic through compromised victim systems as covert relays
- Targeting spans entities across the Middle East, Africa, and South Asia
📡 Macro Trends
NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework
The Hacker News · Jul 27 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A 37-member industry alliance anchored by NVIDIA, Microsoft, Cisco, CrowdStrike, and Palo Alto Networks forming a shared open framework for securing AI agents signals an emerging industry standard — CISOs should track the NOOA framework as a likely baseline for AI agent security requirements in enterprise procurement and compliance frameworks.
- NVIDIA and 36 partners including Microsoft, Cisco, CrowdStrike, Palo Alto Networks, IBM, and Cloudflare have formed the Open Secure AI Alliance
- The alliance open-sourced the NOOA framework for securing AI agents
- The coalition spans cloud, security, enterprise software, and AI companies, giving the framework broad industry backing
🔓 Data Breach
Ernst & Young data breach claimed by ShinyHunters extortion gang
BleepingComputer · Jul 27 · Relevance: █████████░ 9/10
Why it matters to CISOs: A supply-chain attack compromising one of the world's largest professional services firms creates direct exposure risk for any enterprise that shares sensitive data with EY for audits, consulting, or advisory work. CISOs should assess third-party data flows and contractual notification obligations with EY immediately.
- ShinyHunters claimed responsibility and says credentials were obtained via a supply-chain attack
- EY has recently disclosed a data breach, confirming the incident has some validity
- ShinyHunters is a prolific extortion group with a track record of monetizing large stolen datasets
Coca-Cola confirms data theft in Fairlife ransomware attack
BleepingComputer · Jul 27 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A confirmed data-theft ransomware attack against a Fortune 500 subsidiary underscores that ransomware groups are routinely executing double-extortion against large consumer brands, and that subsidiary isolation and OT/IT segmentation remain critical gaps. Board-level communications on ransomware readiness will likely be triggered by this story.
- Coca-Cola confirmed hackers stole data from its Fairlife dairy subsidiary during a ransomware attack earlier in July 2026
- Coca-Cola stated it does not expect a material financial impact on operations
- The attack caused operational disruptions requiring restoration of production capacity
New Certighost PoC exploit lets attackers hijack Windows domains
BleepingComputer · Jul 27 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A public PoC exploit for an Active Directory Certificate Services vulnerability enabling domain compromise will dramatically lower the bar for attackers targeting enterprise Windows environments — CISOs should verify ADCS hardening posture and monitor threat intelligence for exploitation activity against this PoC.
- A proof-of-concept exploit for 'Certighost' has been publicly released targeting Windows Active Directory Certificate Services
- Authenticated attackers can use the exploit to potentially compromise an entire Windows domain
- Public PoC release substantially increases exploitation risk for unpatched enterprise environments
⚖️ Governance & Policy
UK court rejects Bahrain immunity claim in spyware case
The Record (Recorded Future) · Jul 27 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A UK court ruling that state immunity does not shield a foreign government from civil liability in a commercial spyware-enabled hacking case sets a significant legal precedent — it signals increasing judicial willingness to impose accountability for state-sponsored cyber operations and has implications for enterprises considering legal remedies after nation-state intrusions.
- A UK court rejected Bahrain's claim of sovereign immunity in a civil case involving alleged hacking via commercial spyware
- The alleged hacking enabled exfiltration of data and use of microphones and cameras to surveil the respondents
- The ruling opens the door for civil litigation against nation-states for cyber intrusions conducted through commercial tools
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
CyberScoop · Jul 27 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Congressional pressure on federal agencies to eliminate legacy public-facing VPNs in favor of zero-trust architecture will accelerate procurement and policy changes that enterprise CISOs should anticipate — regulated industries and government contractors may face analogous requirements, and this provides useful political cover to fast-track internal zero-trust initiatives.
- Senator Ron Wyden sent a letter urging federal agencies to replace older insecure public-facing VPNs
- Wyden cited 'devastating' attacks on federal government attributed to legacy VPN weaknesses
- The letter pushes agencies toward zero-trust architecture as the replacement paradigm
🚨 Critical Vulnerability
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
The Hacker News · Jul 28 · Relevance: █████████░ 9/10
Why it matters to CISOs: A CVSS 10.0 actively exploited command injection vulnerability in SD-WAN orchestration infrastructure is an existential risk for enterprises running on-premises VeloCloud — attackers with access to the orchestrator can pivot to branch networks enterprise-wide. Immediate patching or isolation of on-prem VCO instances is required.
- CVE-2026-16812 carries a CVSS score of 10.0 and is actively being exploited in the wild
- The flaw is an OS command injection enabling arbitrary code execution on Arista VeloCloud Orchestrator on-premises deployments
- Arista has released a patch; VeloCloud Cloud instances are not affected
Hackers target US firms in FastJson RCE zero-day attacks
BleepingComputer · Jul 27 · Relevance: ████████░░ 8/10
Why it matters to CISOs: FastJson is one of the most widely used Java JSON libraries in enterprise middleware, microservices, and API layers — an unauthenticated RCE zero-day being actively exploited against US firms demands immediate inventory of FastJson usage across application portfolios and emergency patching or WAF mitigation.
- Attackers are actively exploiting a zero-day RCE vulnerability in the FastJson open-source Java library
- Exploitation requires no user interaction and no elevated privileges
- Targeting has been observed against US-based firms specifically
Further Reading
- 🌍 Hackers used autonomous AI agent to spy on Thailand's finance ministry — The Record (Recorded Future)
- 🌍 Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays — The Hacker News
- 📡 NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework — The Hacker News
- 🔓 Ernst & Young data breach claimed by ShinyHunters extortion gang — BleepingComputer
- 🔓 Coca-Cola confirms data theft in Fairlife ransomware attack — BleepingComputer
- 🔓 New Certighost PoC exploit lets attackers hijack Windows domains — BleepingComputer
- ⚖️ UK court rejects Bahrain immunity claim in spyware case — The Record (Recorded Future)
- ⚖️ Sen. Wyden urges feds to discard older, insecure, public-facing VPNs — CyberScoop
- 🚨 Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw — The Hacker News
- 🚨 Hackers target US firms in FastJson RCE zero-day attacks — BleepingComputer
Full Transcript
Click to expand full episode transcript
Alex: Good morning. It's Tuesday, July 28th, 2026. This is Cleartext. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Let's get into it.
Alex: We've got a packed show today. An autonomous AI agent used in a confirmed state-level espionage campaign. ShinyHunters claiming a breach at Ernst & Young through a supply-chain attack. A CVSS 10 in Arista VeloCloud that's being actively exploited right now. A FastJson zero-day hitting US companies. A new ADCS exploit going public. NVIDIA standing up a 37-member alliance to secure AI agents. And a UK court ruling that could reshape how nation-states answer for cyber operations. Let's start where we should start.
Jordan: Yeah. Thailand's Ministry of Finance. Researchers have confirmed that threat actors deployed an autonomous AI agent, not AI-assisted tooling, not a chatbot generating phishing lures, an actual agentic system, to conduct a sustained cyber-espionage campaign against a sovereign government's finance ministry. This is the first publicly confirmed instance of agentic AI being used in a nation-state intrusion at this level. And I want to be precise about why this matters. The agent operated autonomously to maintain persistence and exfiltrate data at scale. It made decisions. It adapted. That's a fundamentally different threat model than what we've been defending against.
Alex: Let's be clear about the implication for CISOs. Your detection logic is built around human-speed operations. Even sophisticated APTs have operational rhythms, working hours, dwell time patterns, decision latency. An autonomous agent doesn't have those constraints. It can test, adapt, and move laterally at machine speed, around the clock. If you're running a financial institution, a treasury function, anything adjacent to government finance, you need to be rethinking your detection assumptions today. Not next quarter.
Jordan: And the attribution question is interesting here too. We don't have a named threat actor yet, which itself is telling. When the operator is an AI agent, the human fingerprints get thinner. Attribution becomes harder. DFIR teams are going to need new forensic methodologies to even characterize these intrusions. I think we're going to look back at this Thailand case as a watershed moment, the way we look back at Stuxnet for operational technology.
Alex: That's a strong comparison, but I think it's earned. Let's stay in the geopolitical lane. Nimbus Manticore.
Jordan: Iranian state-backed group, also tracked as UNC1549, Smoke Sandstorm, and about four other names depending on your vendor. They've deployed a previously undocumented Windows backdoor called NightLedger, along with two custom WebSocket tunnelers. The tunnelers are the interesting part. They're turning compromised victim systems into covert relay nodes, essentially building an anonymization network out of other people's infrastructure. Targeting spans the Middle East, Africa, and South Asia. Defense, energy, government-adjacent sectors.
Alex: If you have operations or supply chain touchpoints in those regions, this is actionable. Your threat hunt teams should be looking for anomalous WebSocket traffic patterns and updating detection rules for NightLedger indicators. The relay infrastructure is particularly concerning because it means a compromised system in your environment might not be the target. It might be the plumbing for someone else's operation, and you're now a co-conspirator in an espionage campaign without knowing it.
Jordan: Exactly. And the WebSocket tunneling is clever because it blends into legitimate web traffic. Most security stacks aren't deeply inspecting WebSocket frames at scale. That's a gap worth closing.
Alex: Let's shift to breaches. The EY situation.
Jordan: ShinyHunters claimed responsibility for a data breach at Ernst & Young. They say they obtained credentials through a supply-chain attack. EY has confirmed a breach occurred, which gives the claim credibility. ShinyHunters has a well-documented track record of monetizing large datasets, so this isn't bluster.
Alex: Here's where I want every CISO listening to stop and think about their own exposure. EY is one of the Big Four. If your organization uses EY for audit, consulting, tax advisory, M&A due diligence, there is a non-trivial chance that your sensitive data traversed their systems. You need to assess what data you've shared with EY, review your contractual notification obligations, and determine whether your data is in scope. Don't wait for EY's notification letter. Get ahead of it internally, especially with your general counsel and your board.
Jordan: Supply-chain attacks against professional services firms are uniquely dangerous because those firms are trusted with crown jewel data by design. Your auditor has your financials. Your consultant has your strategy decks. Your tax advisor has your corporate structure. It's a target-rich environment.
Alex: And then Coca-Cola confirmed data theft from Fairlife, their dairy subsidiary, in a ransomware attack earlier this month. They're saying no material financial impact, but there were operational disruptions requiring restoration of production capacity.
Jordan: The "no material impact" framing is doing a lot of heavy lifting there. Production capacity had to be restored. That means OT was affected, or at minimum, the IT systems that orchestrate production were compromised enough to halt operations. For CISOs at large conglomerates, the subsidiary question is critical. Is your subsidiary segmented? Are their IT and OT environments truly isolated from the parent? Because ransomware actors are specifically targeting subsidiaries as softer entry points into larger corporate ecosystems.
Alex: It's also a board communications issue. When Coca-Cola shows up in a ransomware headline, every board in America asks their CISO the same question at the next meeting. Make sure you have a current, credible answer about your ransomware readiness, your subsidiary governance, and your recovery capabilities.
Jordan: Let's talk vulnerabilities. Two critical items. First, CVE-2026-16812 in Arista VeloCloud Orchestrator. CVSS 10.0. Actively exploited. OS command injection enabling arbitrary code execution on on-premises VCO deployments. Cloud instances are not affected. Arista has a patch available.
Alex: If you run on-prem VeloCloud, this is a drop-everything situation. The orchestrator is the brain of your SD-WAN. An attacker with code execution on your orchestrator can pivot to every branch in your network. That's not a single-system compromise. That's enterprise-wide exposure. Patch immediately. If you can't patch immediately, isolate the orchestrator from any untrusted network path. Today.
Jordan: Second, a FastJson zero-day. FastJson is one of the most widely deployed Java JSON parsing libraries in enterprise environments. It's everywhere, in middleware, microservices, API layers. The vulnerability enables unauthenticated remote code execution with no user interaction and no elevated privileges. It's being actively exploited against US firms right now.
Alex: The challenge here is visibility. Most CISOs don't have a clean inventory of where FastJson lives in their application portfolio. It's a transitive dependency in countless Java projects. Your application security team needs to run a software composition analysis sweep across your entire codebase today. If you can't patch immediately, deploy WAF rules to filter malicious payloads targeting known FastJson deserialization patterns.
Jordan: And then there's Certighost. A proof-of-concept exploit targeting Active Directory Certificate Services that allows an authenticated attacker to compromise an entire Windows domain. The PoC is public, which means the exploitation bar just dropped dramatically.
Alex: ADCS has been a known soft spot since the original Certifried and ESC vulnerabilities. If you haven't hardened your ADCS deployment, the urgency just increased. Review your certificate templates, enforce certificate approval workflows, and monitor for anomalous certificate enrollment activity. This is the kind of thing red teams have been exploiting for years. Now every script kiddie has the playbook.
Jordan: Let's pivot to something more constructive. NVIDIA and 36 partners, including Microsoft, Cisco, CrowdStrike, Palo Alto Networks, IBM, and Cloudflare, have formed the Open Secure AI Alliance and open-sourced the NOOA framework for securing AI agents.
Alex: This is significant because of the breadth of the coalition. When you have cloud providers, security vendors, enterprise software companies, and AI companies all signing onto the same framework, you're looking at a de facto standard. CISOs should be tracking NOOA closely. I expect it will show up in procurement requirements, in compliance frameworks, and eventually in regulatory guidance. If you're deploying AI agents in your environment, or your vendors are, the NOOA framework is likely going to become the baseline expectation for how those agents are secured.
Jordan: And given what we just discussed about the Thailand case, the timing is fitting. We're seeing autonomous AI agents used offensively in nation-state campaigns, and simultaneously seeing the industry try to build defensive guardrails. Those two timelines are going to be in a race for a while.
Alex: Two more items. Senator Wyden sent a letter to federal agencies urging them to replace legacy public-facing VPNs and move to zero-trust architecture. He cited devastating attacks attributed to legacy VPN weaknesses.
Jordan: This has been obvious to the security community for years, but Congressional pressure changes the procurement calculus. For CISOs in regulated industries or government contracting, this is a signal that analogous requirements are coming your way. And frankly, it's useful political cover. If you've been trying to get budget to rip out your legacy VPN infrastructure and accelerate zero trust, print this letter and bring it to your next budget meeting.
Alex: And finally, a UK court rejected Bahrain's claim of sovereign immunity in a civil case involving alleged hacking via commercial spyware. The court found that state immunity doesn't shield a foreign government from liability when it uses commercial tools to hack individuals.
Jordan: This is a genuinely important legal precedent. It means nation-states can potentially face civil litigation in UK courts for cyber operations conducted through commercial spyware. For enterprises, it opens a door. If you're the target of a nation-state intrusion that leveraged commercial tools, you may have a legal remedy you didn't have before. It also puts commercial spyware vendors on notice that their government clients aren't bulletproof in Western courts.
Alex: Looking at the week ahead, the through-line today is unmistakable. The threat landscape is undergoing a capability step-change. Autonomous AI agents conducting espionage. Supply-chain attacks hitting the Big Four. CVSS 10 vulnerabilities in network orchestration infrastructure. Zero-days in ubiquitous open-source libraries. The tools are getting more powerful, the targets are getting more central, and the attack surface is getting more abstract.
Jordan: And the defensive side is trying to organize. The NOOA framework, the zero-trust push, the legal precedents. But there's a lag. The offense is moving faster than the defense right now. CISOs who recognize that and adjust their assumptions, their detection logic, their incident response plans, are going to be better positioned than those waiting for the frameworks to catch up.
Alex: Agreed. Don't wait for the framework. Use it when it arrives, but act on what you know today. That's all for this Tuesday. Show notes and links to every story we covered are at cleartext.fm.
Jordan: Stay sharp. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-07-28.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.