Cleartext logocleartext_
daily briefing

Cleartext – August 11, 2026

Tuesday, August 11, 2026·11:00

Cleartext – August 11, 2026
11:00·6.8 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – August 11, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 4 topic areas, including: Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine; China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw; Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development.

Stories Covered

🌍 Geopolitical

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

The Hacker News · Aug 11 · Relevance: █████████░ 9/10

Why it matters to CISOs: This attack demonstrates a novel OT intrusion vector via private APN cellular networks that bypasses traditional IT perimeter controls, directly relevant to any enterprise operating OT/ICS environments or managing distributed infrastructure. The first confirmed use of this technique signals a new threat model CISOs must address.

  • Attackers shut down a steam turbine and process-water treatment system at a Polish combined heat and power plant serving ~50,000 residents
  • Entry point was the private APN (Access Point Name) cellular network used by the grid operator to reach remote equipment—a previously unseen attack vector per CERT Polska
  • Attackers remained active inside the network while recovery operations began, indicating persistent access

📖 Read full article

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

The Hacker News · Aug 10 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A China-nexus nation-state actor pivoting to ransomware deployment represents a significant threat escalation, blurring lines between espionage and financially motivated attacks and complicating attribution-based response strategies. CISOs with N-central RMM deployments must treat this as an emergency patching priority.

  • Microsoft Threat Intelligence linked Storm-1175, a China-affiliated actor, to a new ransomware strain called StormEncryptor written in C++
  • Deployment vector is likely an unpatched flaw in N-central, a widely used remote monitoring and management platform
  • Marks a strategic shift from the group's prior use of Medusa ransomware, indicating evolving TTPs

📖 Read full article

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

The Hacker News · Aug 10 · Relevance: ████████░░ 8/10

Why it matters to CISOs: North Korea's Kimsuky operating AI infrastructure offline to enhance phishing quality and automate malware development represents a qualitative leap in nation-state threat capability that will degrade the effectiveness of existing phishing detection and signature-based defenses.

  • South Korean firm Genians identified Kimsuky running AI models on air-gapped servers with RAG-style document search capabilities
  • The offline AI stack is being used to improve phishing content quality and automate components of malware development
  • This development signals nation-state AI adoption moving beyond public LLM experimentation into operational, sanctions-evading infrastructure

📖 Read full article

Russian military hackers pose as recruiters to target Ukrainian IT workers

The Record (Recorded Future) · Aug 10 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Sandworm's use of fake recruiter personas to target IT workers is a tactic that can easily bleed into enterprise environments via employees with Ukrainian ties or organizations operating in or near the conflict zone. HR and talent acquisition workflows represent an expanding social engineering attack surface.

  • CERT-UA attributed the campaign to Sandworm, Russia's GRU military intelligence hacking unit
  • Campaign has been running since at least May 2026, targeting Ukrainian IT professionals via fake recruitment outreach
  • Tactic demonstrates continued evolution of Sandworm's social engineering playbook beyond purely technical exploitation

📖 Read full article

📡 Macro Trends

OpenAI says Daybreak will expand to offer specialized cyber services

CyberScoop · Aug 10 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: OpenAI's Daybreak program formalizes a new class of AI-powered offensive security services through vetted vendor partnerships, which CISOs should evaluate both as a procurement option and as a new threat surface—the same capabilities approved partners use could inform adversary tooling within months.

  • OpenAI launched Daybreak Blue and Daybreak Red tiers granting vetted cybersecurity partners access to frontier AI models for defensive and offensive security work respectively
  • 16 major cybersecurity vendors announced as initial Daybreak partners; customers receive findings but not direct model access
  • GPT-5.6-Cyber is trained specifically for exploit development and vulnerability research with significantly reduced safety refusals

📖 Read full article

Coruna, DarkSword iOS Exploits Proliferate Globally

Dark Reading · Aug 10 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Nation-state-grade iOS exploit chains spreading to organized cybercrime dramatically expands the pool of threat actors capable of compromising executive devices and mobile endpoints, which CISOs should factor into their mobile device management and executive protection programs.

  • Sophisticated iPhone exploit chains previously restricted to nation-state actors are now in use by organized cybercrime groups globally
  • Coruna and DarkSword represent distinct exploit chains capable of compromising fully patched iOS devices
  • Proliferation likely driven by commercial exploit broker markets and dark web sales, lowering the barrier to advanced mobile compromise

📖 Read full article

🔓 Data Breach

A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond

TechCrunch Security · Aug 10 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The Ceva Logistics breach is a textbook third-party supply chain incident with a wide blast radius spanning financial services, retail, and technology sectors—CISOs must assess whether their organization relies on Ceva for logistics and initiate vendor breach notification protocols accordingly.

  • Cyberattack on Ceva Logistics between July 29–August 1, 2026 resulted in theft of customer names, addresses, and order data
  • Blast radius spans multiple industries including banks, retailers, and consumer tech companies such as Valve/Steam
  • Valve is actively notifying affected European customers, indicating GDPR notification timelines are in motion

📖 Read full article

FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure

The Record (Recorded Future) · Aug 10 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A joint FBI and South Korean government advisory on Gunra ransomware—which exploits known firewall vulnerabilities to breach critical infrastructure—carries significant weight for CISOs in healthcare, financial services, and government-adjacent sectors who need to validate perimeter device patch status.

  • Gunra ransomware gang is breaching organizations through vulnerabilities in widely deployed firewall products including Fortinet and Schneider Electric systems
  • Targets span healthcare, financial services, government, and professional services globally
  • Joint advisory from FBI and South Korea's National Police Agency elevates the geopolitical dimension, suggesting possible state-nexus or state-tolerance

📖 Read full article

🚨 Critical Vulnerability

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

BleepingComputer · Aug 11 · Relevance: █████████░ 9/10

Why it matters to CISOs: SharePoint is pervasive across enterprise environments and its exploitation by ransomware gangs at scale means this has crossed the emergency bar—CISOs must confirm patch status immediately and validate that SharePoint-facing systems are not exposed to the internet without compensating controls.

  • CISA confirmed ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability
  • The flaw has been flagged as actively exploited since early July 2026, meaning unpatched organizations have had extended exposure
  • Ransomware deployment via SharePoint RCE represents a direct path to enterprise-wide encryption events

📖 Read full article

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

BleepingComputer · Aug 10 · Relevance: ████████░░ 8/10

Why it matters to CISOs: SonicWall SMA1000 appliances are widely deployed as enterprise remote access gateways, and active ransomware exploitation of a maximum-severity SSRF flaw makes this a critical patching emergency for any organization using this product as part of their VPN or zero-trust access architecture.

  • CISA confirmed ransomware gangs are exploiting two recently patched SonicWall SMA1000 vulnerabilities
  • One of the flaws is a maximum-severity server-side request forgery (SSRF) vulnerability
  • SMA1000 is an enterprise-grade secure access gateway, meaning successful exploitation can provide broad network access

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Good morning. It's Tuesday, August 11th, 2026. This is Cleartext. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Alex: We have a packed show today. Attackers breached a Polish power plant through a private cellular network and shut down a turbine. China-linked actors are deploying custom ransomware through RMM tools. Kimsuky is running offline AI to sharpen its phishing and malware ops. We've got iOS zero-days proliferating to criminal groups, a supply chain breach rippling across industries, and two critical vulnerabilities CISA says ransomware gangs are actively exploiting right now. Let's start where the real alarms are ringing.

Jordan: Poland. A combined heat and power plant serving about fifty thousand residents. Attackers came in through the private APN cellular network the grid operator uses to communicate with remote equipment. They shut down a steam turbine and the process-water treatment system. CERT Polska says this is the first confirmed use of this specific intrusion vector. And here's what makes it worse: when recovery operations started around seven thirty in the morning, the attackers were still inside the network.

Alex: Let's unpack why this matters at the board level. Every CISO running OT environments, whether it's energy, manufacturing, water treatment, has been focused on the IT-OT convergence problem for years. But the assumption has generally been that the threat enters through IT and pivots to OT. This attack skipped the IT perimeter entirely. It came in through the cellular backhaul that connects remote equipment to the control network. That's infrastructure most security teams don't even have visibility into because it's managed by the telecom provider or the grid operator.

Jordan: Right. Private APNs have been treated as trusted pipes. They're not routed over the public internet. There's an implicit trust model baked in: if the traffic is on this APN, it's authorized. That assumption just got demolished. And the persistent access piece is critical. Recovery was happening in parallel with active adversary presence. That tells me either the defenders didn't know the attackers were still there when they started, or they knew and had no choice but to restore service anyway because people needed heat.

Alex: Either scenario is bad. If you're a CISO with distributed OT infrastructure relying on private cellular connectivity, your action item today is to map every cellular connection into your control environment, understand who manages those APN configurations, and figure out what monitoring you actually have on that traffic. Because if the answer is none, you have a blind spot that just became a proven attack path.

Jordan: And for what it's worth, residents didn't lose heat. The plant recovered. But the fact that a turbine was shut down remotely through a cellular network should be a wake-up call far beyond Poland.

Alex: Let's pivot to the China-nexus ransomware story, because this connects to a broader pattern. Microsoft Threat Intelligence linked Storm-1175, a China-affiliated group, to a new ransomware strain called StormEncryptor. It's written in C++, appends a .encrypted extension, and the deployment vector appears to be an unpatched flaw in N-central, the remote monitoring and management platform.

Jordan: Two things jump out. First, this is a known China-nexus actor shifting from Medusa ransomware to a custom-built strain. That's not just new malware. That's investment. They built their own tool, which means they want operational independence from shared ransomware ecosystems. Second, the vector. N-central is everywhere. It's what MSPs use to manage their clients' environments. If you compromise an RMM platform, you don't just get one victim. You get every organization that MSP manages.

Alex: If you're running N-central or your managed service provider is, treat this as an emergency patching event. Full stop. And the broader strategic point here is that the line between espionage-motivated and financially motivated attacks from China-nexus actors continues to blur. That complicates your threat model. You can't neatly categorize these groups anymore.

Jordan: Which brings us to Kimsuky, because North Korea is making its own investments. South Korean firm Genians found that Kimsuky is running AI models on air-gapped servers with retrieval-augmented generation capabilities, using it to improve phishing content and automate malware development. This isn't prompting ChatGPT from a Pyongyang internet café. This is purpose-built, offline AI infrastructure designed to evade sanctions and API controls.

Alex: The practical implication for defenders is that the quality floor on phishing just went up. If Kimsuky can generate contextually rich, linguistically polished phishing at scale using offline AI tuned on their own document collections, your employees' ability to spot a bad email by looking for broken grammar or generic language is degrading fast.

Jordan: And the malware automation piece means faster iteration on tooling. Shorter dwell times between when a vulnerability is disclosed and when Kimsuky has a working exploit or payload. This is exactly the scenario the threat intel community has been warning about. Nation-states building AI into their offensive pipelines. It's happening now.

Alex: Let's touch on the Sandworm campaign briefly. CERT-UA attributed a fake recruiter operation to Russia's GRU that's been running since May, targeting Ukrainian IT professionals. Jordan, this one's interesting because it weaponizes the hiring process.

Jordan: Sandworm has always been creative with social engineering, but posing as recruiters is smart because it exploits a moment of vulnerability. People actively looking for work are motivated to open attachments, click links, engage with strangers. And this doesn't stay contained to Ukraine. Any organization with Ukrainian employees, contractors, or hiring pipelines touching Eastern Europe should be aware. Your HR and talent acquisition workflows are an attack surface. Treat them accordingly.

Alex: Now let's talk about two things that are operationally urgent. CISA confirmed ransomware gangs are actively exploiting a high-severity SharePoint remote code execution vulnerability. This has been flagged as exploited since early July. And separately, CISA confirmed ransomware exploitation of two SonicWall SMA1000 vulnerabilities, including a maximum-severity SSRF flaw.

Jordan: SharePoint first. It's everywhere. It's the document backbone of most enterprises. A remote code execution flaw in SharePoint that ransomware operators are using is a direct path to an encryption event. If you haven't patched this since July, you've had over a month of exposure. That's not a risk acceptance conversation. That's a gap.

Alex: Same urgency on SonicWall SMA1000. These are enterprise remote access gateways. If ransomware actors can exploit a max-severity SSRF on your VPN concentrator, they're inside your network with broad access. Patch today. Validate your exposure. If you can't patch immediately, pull it behind additional controls or take it offline until you can.

Jordan: And I'll connect these two to the Gunra ransomware advisory. FBI and South Korea's National Police Agency jointly warned that the Gunra gang is breaching critical infrastructure through vulnerabilities in Fortinet and Schneider Electric systems. Healthcare, financial services, government. The joint nature of that advisory, FBI plus South Korea, suggests there may be a state-nexus or at minimum state tolerance behind this group.

Alex: Three separate ransomware exploitation warnings in forty-eight hours, all targeting perimeter infrastructure. If you're a CISO and you haven't done a perimeter device audit this quarter, this is your prompt.

Jordan: Let's shift gears. The Ceva Logistics breach. Cyberattack between July 29th and August 1st. Customer names, addresses, order data stolen. The blast radius is enormous. Banks, retailers, Valve notifying Steam customers in Europe. GDPR timelines are in motion.

Alex: This is supply chain risk in its purest form. Ceva is a logistics provider. They ship physical goods for companies across every sector. If your organization uses Ceva for fulfillment, your customer data may be in this breach, and your notification obligations may have already started. Check your vendor risk register. Initiate your breach notification protocol if Ceva is in your supply chain.

Jordan: Two more items worth your attention. First, the Coruna and DarkSword iOS exploit chains. These were previously nation-state only. Now they're in the hands of organized cybercrime groups. Fully patched iPhones are being compromised. If you have executives carrying iPhones and you rely on the Apple ecosystem's reputation for security as your mobile strategy, that assumption needs revisiting. Lockdown Mode, MDM controls, and executive device monitoring should all be on the table.

Alex: And finally, OpenAI's Daybreak program. They've launched Red and Blue tiers giving vetted cybersecurity vendors access to frontier models for offensive and defensive work. GPT-5.6-Cyber is specifically trained for exploit development with reduced safety refusals. Sixteen vendors are initial partners.

Jordan: I have mixed feelings about this. On one hand, giving defenders access to AI-powered vulnerability research is genuinely useful. On the other hand, a model specifically trained to develop exploits with reduced guardrails is going to leak. Not the model itself necessarily, but the techniques, the approaches, the outputs. Whatever approved partners learn from GPT-5.6-Cyber will inform adversary tooling within months. That's just how this works.

Alex: Agreed. CISOs should evaluate Daybreak as a procurement option but also as a leading indicator of what's coming at them offensively.

Jordan: So stepping back, what's the theme today?

Alex: Perimeter assumptions are failing. The Polish attack bypassed IT perimeters through cellular. SharePoint and SonicWall are perimeter devices being exploited at scale. iOS exploit chains that were supposed to be contained to nation-states are in criminal hands. The walls we built are not holding the way we designed them to hold.

Jordan: And the adversaries are getting more capable faster. Kimsuky with offline AI. Storm-1175 building custom ransomware. Sandworm weaponizing HR processes. The sophistication curve is steepening, and it's steepening across multiple nation-state actors simultaneously. That's not a coincidence. That's a trend.

Alex: For CISOs listening, the action items from today are concrete. Audit your cellular connectivity into OT environments. Patch SharePoint and SonicWall SMA1000 immediately. Check whether N-central is in your environment or your MSP's. Verify whether Ceva Logistics is in your supply chain. And revisit your mobile device security strategy with the assumption that iOS zero-days are now available to criminal groups, not just governments.

Jordan: Busy Tuesday.

Alex: That's Cleartext for August 11th, 2026. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.

Jordan: See you then.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-11.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.