Cleartext logocleartext_
daily briefing

Cleartext – August 12, 2026

Wednesday, August 12, 2026·10:27

Cleartext – August 12, 2026
10:27·6.3 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – August 12, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 4 topic areas, including: Lazarus hackers pair fake job offers with Windows zero-day exploit; Sandworm hackers target IT pros with trojanized WireGuard VPN client; Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers.

Stories Covered

🌍 Geopolitical

Lazarus hackers pair fake job offers with Windows zero-day exploit

Help Net Security · Aug 12 · Relevance: █████████░ 9/10

Why it matters to CISOs: North Korea's Lazarus Group is actively targeting defense sector employees with a Windows zero-day embedded in fake recruiter outreach, making HR and talent acquisition workflows a live attack vector that security leaders must address with policy and detection controls.

  • Lazarus Group is using trojanized PDF software and a Windows zero-day as part of Operation Dream Job, targeting defense-sector employees
  • Decoy documents include Lockheed Martin job descriptions to lend credibility to the social engineering lure
  • Check Point researchers uncovered the campaign, which combines a zero-day exploit with spear-phishing via fake recruitment channels

📖 Read full article

Sandworm hackers target IT pros with trojanized WireGuard VPN client

BleepingComputer · Aug 11 · Relevance: █████████░ 9/10

Why it matters to CISOs: Russia's Sandworm APT is specifically targeting system administrators and IT staff — the keys-to-the-kingdom personnel — using fake job offers to deliver backdoored VPN software, meaning privileged access workflows and software installation controls for IT staff are now a priority threat surface.

  • Sandworm (UAC-0145) has been running fake IT job interview campaigns since at least May 2026 targeting system administrators
  • The campaign delivers a trojanized WireGuard VPN client capable of executing attacker commands on compromised systems
  • CERT-UA has formally attributed the activity to the Sandworm subgroup and issued an advisory

📖 Read full article

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

The Hacker News · Aug 11 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Controlled research demonstrating how easily North Korean operatives pass standard onboarding with fabricated US identities gives CISOs concrete intelligence on the fraudulent IT worker threat, along with actionable red flags — mismatched ID documents, geographic inconsistencies — to embed in HR and vendor vetting processes.

  • Researchers created a fake cryptocurrency startup, ran real job postings, and successfully onboarded three individuals believed to be North Korean state operatives
  • All virtual machines issued to hires were under continuous monitoring; behavioral and identity anomalies were documented throughout
  • One hire claimed Texas residency but submitted a California driver's license and a New York bank account — a pattern now documented as a North Korean IT worker indicator of compromise

📖 Read full article

Russian-Linked Hackers Accessed Polish Power Plant OT Network Through Private APN, Says CERT.PL

Infosecurity Magazine · Aug 12 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Russian-linked actors achieving OT network access at a European power plant via a private APN — bypassing traditional IT/OT segmentation approaches — is a critical case study for CISOs responsible for critical infrastructure or OT environments on the limits of perimeter-based segmentation.

  • CERT.PL has released a detailed post-incident report on a 2025 Russian-linked attack on a Polish combined heat and power plant
  • Attackers gained access to the OT network via a private APN (Access Point Name), circumventing conventional IT/OT network segmentation controls
  • The disclosure provides rare public attribution and technical detail on a successful attack against European energy critical infrastructure

📖 Read full article

📡 Macro Trends

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The Hacker News · Aug 11 · Relevance: ████████░░ 8/10

Why it matters to CISOs: DeadLock's use of blockchain-based infrastructure for victim communications and data leak operations fundamentally undermines law enforcement takedown efficacy, meaning organizations can no longer rely on disruption operations as a meaningful backstop once ransomware operators establish a foothold.

  • DeadLock ransomware group uses Polygon smart contracts and the Session messaging network to host extortion infrastructure that cannot be seized via traditional server takedowns
  • Microsoft Threat Intelligence has formally analyzed and attributed the blockchain-backed operational model
  • The architecture stores and delivers extortion resources through decentralized services, making law enforcement disruption significantly harder

📖 Read full article

OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

The Hacker News · Aug 11 · Relevance: ████████░░ 8/10

Why it matters to CISOs: OpenAI releasing a frontier AI model purpose-built for zero-day discovery and exploit chain development — with reduced safety refusals — materially lowers the barrier for sophisticated offensive capability and forces CISOs to reassess threat actor capability timelines for AI-assisted attacks.

  • OpenAI's GPT-5.6-Cyber is explicitly trained for finding zero-day vulnerabilities and developing exploit chains, with reduced refusals for higher-risk cybersecurity tasks
  • The model is released alongside a two-tier access program (Daybreak Blue and Daybreak Red) with differentiated guardrail levels for blue and red team use cases
  • This represents a significant milestone in the democratization of advanced offensive AI capability beyond nation-state actors

📖 Read full article

🔓 Data Breach

Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe

The Record (Recorded Future) · Aug 11 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A cyberattack disrupting eight European warehouses of CEVA Logistics with cascading effects across multiple retail and digital distribution clients illustrates the third-party supply chain risk that CISOs must account for in vendor risk programs and business continuity planning.

  • Operations at eight European CEVA Logistics warehouses have been disrupted by a cyberattack
  • Downstream impact is spreading to retailers and Steam (gaming platform) customers across Europe
  • CEVA Logistics is a major global supply chain operator, making this a high-blast-radius third-party risk event

📖 Read full article

Former BlackFile affiliates linked to extortion campaign targeting private equity

Cybersecurity Dive · Aug 11 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Former ransomware affiliates pivoting to vishing-based extortion specifically against private equity firms signals a sophisticated, targeted threat to M&A-active organizations where deal confidentiality and portfolio company access create high-value attack surfaces.

  • Former BlackFile ransomware affiliates are conducting voice-phishing campaigns targeting private equity firms
  • Attackers impersonate IT help desk personnel to manipulate company employees into granting access
  • The campaign represents a ransomware-to-extortion pivot using social engineering rather than malware as the primary intrusion vector

📖 Read full article

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Dark Reading · Aug 11 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A ransomware-as-a-service group successfully bypassing MFA on Fortinet VPN appliances while targeting critical infrastructure highlights that MFA alone is insufficient against determined actors exploiting unpatched network edge devices, reinforcing the urgency of firewall and VPN patching cadence.

  • Gunra ransomware-as-a-service operation is built on leaked Conti source code and is actively targeting critical infrastructure organizations
  • The group is exploiting known but unpatched Fortinet firewall and VPN vulnerabilities to gain initial access
  • The campaign includes MFA bypass techniques, undermining a commonly assumed defensive control at the network perimeter

📖 Read full article

🚨 Critical Vulnerability

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

The Hacker News · Aug 12 · Relevance: █████████░ 9/10

Why it matters to CISOs: Active exploitation of a CVSS 9.8 RCE flaw in VMware vCenter means any organization running on-premises VMware infrastructure faces immediate risk of full virtualization layer compromise; emergency patching and network-level isolation of vCenter management interfaces is warranted now.

  • CVE-2026-59310 is a directory-traversal vulnerability in VMware vCenter Server with a CVSS score of 9.8
  • Threat actors with network access can exploit the flaw to execute arbitrary code remotely with no authentication required
  • Active exploitation is already confirmed by QUIRSO researchers, meaning patch windows are effectively closed

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Welcome to Cleartext. It's Wednesday, August 12th, 2026. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Alex: So Jordan, you wanted to open with something that ties together multiple stories today.

Jordan: Yeah. Two separate nation-state groups, Lazarus and Sandworm, are both running the same play right now — fake job offers weaponized with zero-days and backdoored software. Different countries, different targets, same playbook. Your HR pipeline is now an attack surface, and I don't mean that metaphorically.

Alex: It's a theme day. We've got nation-state social engineering at scale, a research team that literally hired North Korean operatives on purpose, a ransomware group that's gone fully decentralized, OpenAI releasing an offensive cyber model, a major logistics breach cascading across Europe, a critical VMware zero-day under active exploitation, and more. Let's start with the fake job campaigns.

Jordan: So the Lazarus story first. Check Point has documented the latest iteration of Operation Dream Job, which has been running in various forms for years now. What's new is the pairing. They're combining a Windows zero-day — unpatched at time of targeting — with trojanized PDF reader software, delivered through fake recruiter outreach. The decoy documents are Lockheed Martin job descriptions. They're targeting defense sector employees specifically.

Alex: And the sophistication here matters. These aren't spray-and-pray phishing emails. This is targeted social engineering through recruitment channels — LinkedIn messages, email threads that look like legitimate headhunter outreach. The victim opens what they think is a job description PDF, and the reader software itself is the payload.

Jordan: Right. And then hours later, you see the Sandworm story. CERT-UA has formally attributed a parallel campaign to UAC-0145, a Sandworm subgroup. They've been running fake IT job interviews since at least May, but their target set is different. They're going after system administrators and IT professionals specifically. The payload is a trojanized WireGuard VPN client.

Alex: Which is diabolical, because if you're hiring a sysadmin, asking them to install a VPN client as part of the interview process is completely plausible.

Jordan: Exactly. And sysadmins are keys-to-the-kingdom personnel. You compromise one sysadmin at a target organization and you potentially have domain admin, you have access to backup infrastructure, you have the credentials that matter. The Russians aren't being subtle about who they want.

Alex: So for CISOs listening, the action items here are concrete. First, recruitment workflows need security controls. If your talent acquisition team is sending candidates software to install, that process needs to be reviewed. Second, your privileged users — your sysadmins, your IT staff — need specific guidance about unsolicited job outreach. And third, endpoint detection needs to account for trojanized legitimate tools, not just known malware signatures.

Jordan: And this connects directly to story three, which I find genuinely fascinating. A team of security researchers built a fake cryptocurrency startup from scratch, posted real job listings, and successfully onboarded three individuals they believe are North Korean state operatives posing as developers.

Alex: This is the controlled experiment that validates what we've been warning about for over a year. Every VM issued to the hires was under continuous monitoring. They documented the entire lifecycle — the application, the identity documents, the behavioral patterns.

Jordan: And the identity red flags are incredibly useful for HR and security teams. One hire claimed Texas residency but submitted a California driver's license and a New York bank account. That geographic mismatch pattern is now a documented indicator of compromise for North Korean IT worker infiltration. These are things your onboarding process should be catching.

Alex: The broader point for boards and executives is this: the North Korean IT worker program isn't theoretical. Researchers proved they could encounter it by simply posting developer jobs at a small startup. If you're hiring remote technical talent, you are exposed to this threat. Your identity verification during onboarding is now a security control, not just an HR compliance checkbox.

Jordan: Let's pivot to the Polish power plant story, because this one has real implications for anyone in critical infrastructure.

Alex: CERT.PL released a detailed post-incident report on a 2025 Russian-linked attack against a combined heat and power plant in Poland. And the access vector is what makes this significant. The attackers got into the OT network through a private APN — an Access Point Name, which is essentially a dedicated cellular data connection.

Jordan: For people who aren't in OT every day, the standard assumption is that your IT/OT segmentation is your primary defensive boundary. Air gaps, firewalls between the corporate network and the operational network. What this attack shows is that a private APN — which many utilities use for remote monitoring and telemetry — can become a bypass path that completely sidesteps your segmentation architecture.

Alex: This is a case study that OT-responsible CISOs need to pull into their next architecture review. If you have private cellular connections into your OT environment, those need the same scrutiny as any other network path. The perimeter model breaks down when you have wireless backchannels you're not monitoring with the same rigor.

Jordan: Moving to the ransomware landscape. Two stories here that represent an evolution worth tracking. DeadLock ransomware is using Polygon blockchain smart contracts and the Session encrypted messaging network to host their entire extortion infrastructure.

Alex: And the significance is operational resilience for the attackers. Microsoft Threat Intelligence has formally analyzed this. Traditional law enforcement takedowns work by seizing servers, killing domains, disrupting command and control infrastructure. When your extortion portal, your victim communication channel, and your data leak site are all on decentralized infrastructure, there's nothing to seize.

Jordan: This is the logical endpoint of what we've been watching ransomware groups do for years — progressively hardening their infrastructure against disruption. The implication for CISOs is straightforward. You cannot factor law enforcement takedowns into your risk calculus as a meaningful backstop anymore. If DeadLock or groups like them establish a foothold in your environment, the extortion infrastructure will survive any disruption effort. Prevention and early detection are your only reliable controls.

Alex: The second ransomware story is different but equally concerning. Former BlackFile affiliates have pivoted from traditional ransomware to voice-phishing-based extortion campaigns, and they're specifically targeting private equity firms.

Jordan: They're impersonating IT help desk personnel, calling employees directly, and manipulating them into granting access. No malware as the initial intrusion vector — just social engineering over the phone.

Alex: For CISOs at PE firms or portfolio companies, this is acute. Private equity environments are uniquely vulnerable because of deal confidentiality pressure, because portfolio companies often have immature security programs, and because the access patterns across a PE firm's holdings create lateral movement opportunities that are hard to monitor centrally. Your help desk callback verification procedures need to be airtight.

Jordan: And the Gunra ransomware story rounds out the picture. RaaS operation built on leaked Conti source code, actively targeting critical infrastructure by exploiting known Fortinet firewall and VPN vulnerabilities and bypassing MFA.

Alex: The key word there is "known." These are not zero-days. These are unpatched Fortinet flaws. And the MFA bypass is the twist that should concern people, because MFA on your VPN is often treated as the compensating control for delayed patching. If that assumption fails, you're exposed. Patch your network edge devices. Full stop.

Jordan: Now let's talk about the OpenAI story, because this one is going to generate debate.

Alex: GPT-5.6-Cyber. OpenAI has released a frontier model explicitly trained for zero-day vulnerability discovery and exploit chain development, with reduced safety refusals for offensive security tasks. They've created a two-tier access program — Daybreak Blue for defensive use cases and Daybreak Red for offensive research, with different guardrail levels.

Jordan: I want to be measured about this because there's a real argument that defenders need these capabilities. But the practical reality is that this materially lowers the barrier for sophisticated offensive capability. The nation-state advantage in exploit development has been eroding for years. This accelerates that erosion significantly.

Alex: For CISOs, the planning implication is about threat actor capability timelines. Your threat models that assumed certain exploit development capabilities were limited to top-tier nation-states need to be revised. The democratization of offensive AI means your mid-tier threat actors — organized crime groups, hacktivist collectives — are going to get faster at weaponizing vulnerabilities. Your patch windows just got shorter.

Jordan: And speaking of patch windows that have already closed — VMware vCenter. CVE-2026-59310, CVSS 9.8. Directory traversal to unauthenticated remote code execution. Active exploitation confirmed by QUIRSO researchers.

Alex: If you're running on-premises VMware infrastructure, this is your fire drill for today. vCenter is the management plane for your entire virtualization layer. Compromise vCenter, and you compromise every VM it manages. Patches are available. Apply them now. If you can't patch immediately, isolate your vCenter management interfaces at the network level. No vCenter management port should be reachable from general-purpose network segments, period.

Jordan: And the last story — CEVA Logistics. A cyberattack has disrupted eight European warehouses belonging to CEVA, which is a major global supply chain operator. Downstream impact is hitting multiple retailers and Steam gaming platform customers across Europe.

Alex: This is third-party risk materialized. CEVA is a logistics backbone provider. When they go down, their clients' fulfillment operations go down. For CISOs, this is a reminder to stress-test your vendor risk program against the question: what happens when a critical logistics or supply chain partner is offline for a week? Do you have contractual protections? Do you have alternative fulfillment paths? Have you tabletop-exercised this scenario?

Jordan: Let's close with the outlook. Alex, what's the thread you're pulling on?

Alex: The theme today is that the attack surface has shifted to people and trust relationships. Fake job offers targeting your employees, North Korean operatives infiltrating your workforce, voice phishing impersonating your help desk, supply chain partners as single points of failure. Technical controls matter, but the human layer is where the most sophisticated actors are focusing their creativity. CISOs who are still running security programs primarily oriented around technical perimeter defense are fighting the last war.

Jordan: Agreed. And I'd add that we're entering a period where the infrastructure supporting both attackers and the tools available to them are becoming more resilient and more capable simultaneously. Decentralized ransomware infrastructure you can't take down. AI models that accelerate exploit development. These are structural shifts, not individual incidents. Plan accordingly.

Alex: Well said. That's Cleartext for Wednesday, August 12th, 2026. Show notes and links to every story we covered today are at cleartext.fm.

Jordan: Stay sharp. We'll see you tomorrow.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-12.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.