Cleartext – August 13, 2026
Thursday, August 13, 2026·10:09
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – August 13, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 8 stories across 4 topic areas, including: Trump turns to private sector in offensive hacking operations memo; Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan; Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery.
Stories Covered
🌍 Geopolitical
Trump turns to private sector in offensive hacking operations memo
CyberScoop · Aug 13 · Relevance: ██████████ 10/10
Why it matters to CISOs: This policy shift could expose enterprises to legal, reputational, and retaliatory risk if government-contracted offensive operations are attributed to private sector entities—CISOs in defense, critical infrastructure, and government contracting sectors need to assess exposure immediately.
- White House memo authorizes private sector participation in government-directed offensive cyber operations against transnational groups
- Experts describe it as 'a pretty big shift in U.S. cyber policy' with significant escalation and attribution risks
- Historical reservations about private sector offensive cyber involvement now overridden by executive directive
Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan
CyberScoop · Aug 12 · Relevance: █████████░ 9/10
Why it matters to CISOs: The emergence of AI frameworks capable of self-correction and mid-operation adaptation fundamentally changes the threat model for enterprise security programs, compressing response windows and demanding automated defenses that match attacker sophistication.
- Israeli firm Dream documented a near-autonomous AI attack framework targeting a Taiwanese government entity
- The AI framework adapted mid-operation, self-corrected mistakes, and autonomously expanded its attack scope
- Represents a documented first for near-autonomous AI-driven cyber operations against a government target
📡 Macro Trends
Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
The Record (Recorded Future) · Aug 12 · Relevance: ████████░░ 8/10
Why it matters to CISOs: AI-assisted vulnerability discovery is producing patch volumes approximately five times historical norms, fundamentally straining enterprise patch management programs and demanding a strategic rethink of prioritization frameworks and patching velocity.
- August 2026 Patch Tuesday volume is approximately five times the pre-AI-era monthly average for Microsoft
- AI-assisted bug discovery is accelerating both Microsoft's internal research and adversarial exploit development simultaneously
- NIST is separately modernizing NVD to handle AI-scale vulnerability research, signaling a systemic shift in vulnerability management infrastructure
🔓 Data Breach
153GB of stolen credentials surface after LiteLLM supply chain attack
Help Net Security · Aug 13 · Relevance: █████████░ 9/10
Why it matters to CISOs: A supply chain compromise of the widely used LiteLLM AI framework has exposed CI/CD credentials across thousands of corporate domains including AWS, Samsung, Cisco, and Salesforce—CISOs must audit AI toolchain dependencies and rotate any secrets associated with LiteLLM integrations immediately.
- 153GB archive containing 433,909 files stolen in a LiteLLM supply chain attack, including CI runner dumps from 2,488 corporate domains
- Named enterprises affected include AWS, Samsung, Cisco, and Salesforce
- Hudson Rock conducting global ethical disclosure effort; full scope of downstream compromise still being assessed
A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
Help Net Security · Aug 12 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A 17-month covert data harvesting campaign exploiting misconfigured guest user access in Salesforce and ServiceNow portals highlights systemic SaaS misconfiguration risk—CISOs should treat this as an urgent prompt to audit guest/anonymous access controls across their SaaS estate.
- Campaign dubbed 'City-Forum' has been systematically pulling records from misconfigured Salesforce and ServiceNow portals globally for at least 17 months
- Exploitation leverages legitimate guest user access configurations, not a software vulnerability—'everything working as designed'
- Activity is ongoing and expanding, tracked by Reco researchers
Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
Infosecurity Magazine · Aug 12 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A joint US-Korean government warning about Gunra ransomware exploiting Fortinet vulnerabilities to exfiltrate data from Microsoft services targeting critical infrastructure demands immediate review of Fortinet patch posture and Microsoft data access controls.
- Gunra ransomware actors exploiting Fortinet vulnerabilities to gain initial access to critical infrastructure organizations
- Attackers using stealth techniques to exfiltrate large volumes of data from Microsoft services
- Joint advisory issued by US and Korean government agencies, elevating geopolitical significance
🚨 Critical Vulnerability
Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer · Aug 12 · Relevance: █████████░ 9/10
Why it matters to CISOs: A DPRK nation-state actor actively exploiting a Windows zero-day (CVE-2026-68820) to achieve SYSTEM access against defense and aerospace firms across multiple countries demands immediate patching verification, especially with CISA's two-week federal remediation deadline already issued.
- CVE-2026-68820 exploited by Lazarus Group as part of Operation Dream Job targeting defense and aerospace companies in France, Germany, Brazil, and India
- Lazarus used post-quantum key exchange to protect delivery of the exploit, signaling advanced operational security
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalog; federal agencies must patch by deadline
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
The Hacker News · Aug 13 · Relevance: █████████░ 9/10
Why it matters to CISOs: Active exploitation of a CVSS 9.1 SharePoint authentication bypass is underway following public PoC release—organizations running on-premises SharePoint must validate July patch deployment immediately, as this affects a ubiquitous enterprise collaboration platform.
- CVE-2026-55040 (CVSS 9.1) is a critical authentication bypass in Microsoft SharePoint now being actively exploited following Rapid7's public PoC release
- Patched in July 2026 Patch Tuesday; organizations that delayed deployment are at immediate risk
- Authentication bypass flaws in SharePoint have historically been chained with code execution vulnerabilities for full compromise
Further Reading
- 🌍 Trump turns to private sector in offensive hacking operations memo — CyberScoop
- 🌍 Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan — CyberScoop
- 📡 Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery — The Record (Recorded Future)
- 🔓 153GB of stolen credentials surface after LiteLLM supply chain attack — Help Net Security
- 🔓 A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months — Help Net Security
- 🔓 Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure — Infosecurity Magazine
- 🚨 Lazarus hackers exploited Windows zero-day to target defense firms — BleepingComputer
- 🚨 Attackers Exploit SharePoint Authentication Bypass After Public PoC Release — The Hacker News
Full Transcript
Click to expand full episode transcript
Alex: Good morning. It's Thursday, August 13th, 2026. This is Cleartext. I'm Alex Chen, here with Jordan Reeves. We've got a packed show today. The White House just dropped a memo that could fundamentally redraw the line between government and private sector in offensive cyber operations. We're going to spend real time on that. We've also got the first documented near-autonomous AI attack framework hitting a government target in Taiwan, a massive supply chain breach through LiteLLM that's spilling credentials across thousands of corporate domains, a SaaS misconfiguration campaign that's been quietly harvesting data for seventeen months, and a stack of critical vulnerabilities that need your attention this morning, including a Lazarus zero-day and active SharePoint exploitation. Jordan, let's get into it.
Jordan: So the big one. The White House issued a memo authorizing private sector companies to participate in government-directed offensive cyber operations against transnational threat groups. Full stop. That sentence alone should have every CISO in the defense industrial base, critical infrastructure, and government contracting space reaching for their risk register.
Alex: Let's be precise about what this is and what it isn't. This isn't hack-back legislation for the private sector broadly. This is the executive branch saying it will direct and authorize specific private companies to conduct offensive operations on behalf of the government. But that distinction, which sounds clean in a policy memo, gets very messy in practice.
Jordan: Extremely messy. And I'll tell you why, from someone who spent years on the government side of these operations. Attribution is the core problem. When NSA or Cyber Command runs an operation, there's a sovereign shield. The operation is an act of state. When a private company does it, even under government direction, you're introducing commercial entities into what is fundamentally a military and intelligence activity. If that operation gets attributed, and operations do get attributed, the company is exposed. Their clients are exposed. Their supply chain partners are exposed.
Alex: And this is where CISOs need to think carefully. If you're a defense contractor or a major technology vendor with government contracts, you need to understand whether your organization or your partners could be pulled into this framework. Because the retaliatory risk is real. Nation-state actors don't necessarily distinguish between the company that ran the operation and the company that shares infrastructure with them.
Jordan: One expert called this a pretty big shift in U.S. cyber policy, which is diplomatic understatement. There have been deep reservations about this for decades, going back to debates about letters of marque in cyberspace. Those reservations existed for good reasons. The escalation dynamics are unpredictable. You're essentially creating state-sponsored cyber mercenaries with commercial attack surfaces.
Alex: The board-level conversation here is about involuntary risk inheritance. If your company operates anywhere near the government contracting ecosystem, your general counsel and your CISO need to be jointly assessing whether this memo changes your threat profile. And if you're a technology company whose products could be leveraged in these operations, you need to think about what that means for your global customer base and your reputation in markets outside the U.S.
Jordan: Let's pivot to the second geopolitical story because it connects thematically. Israeli cyber firm Dream has documented what they're calling the first near-autonomous AI attack framework used against a government target, specifically a Taiwanese government entity. And Alex, this one is significant not because AI is being used in attacks, we've been tracking that trend, but because of how it was used.
Alex: Walk us through what near-autonomous actually means here.
Jordan: The framework adapted mid-operation. It self-corrected when it hit errors. It autonomously expanded its attack scope without human intervention. This isn't an attacker using ChatGPT to write phishing emails. This is an AI system making tactical decisions during an intrusion. It's the difference between a power tool and a self-driving car.
Alex: And the defensive implication is stark. If your adversary's attack chain can adapt in real time, your detection and response windows compress dramatically. Human-speed incident response is already strained. Against an AI framework that can pivot faster than your SOC can triage, you need automated defenses that can match that tempo.
Jordan: The Taiwan targeting is also geopolitically loaded, obviously. We don't have public attribution yet, but the context speaks for itself. What I'd say to CISOs is this: start pressure-testing your detection and response assumptions against an adversary that doesn't pause, doesn't sleep, and doesn't make the same mistake twice. That's the threat model now.
Alex: Let's move to the LiteLLM breach because this is an immediate action item. A hundred and fifty-three gigabytes of stolen credentials have surfaced from a supply chain compromise of LiteLLM, the AI proxy framework that a lot of organizations are using to manage LLM API calls. The archive contains over four hundred thirty thousand files, including CI runner dumps from nearly twenty-five hundred corporate domains. Named victims include AWS, Samsung, Cisco, and Salesforce.
Jordan: This is a textbook example of AI toolchain risk that security teams have been warning about. LiteLLM sits in the middle of your AI infrastructure. It touches API keys, model credentials, CI/CD pipelines. Compromise it and you're not stealing one thing, you're stealing everything that flows through it.
Alex: If your organization uses LiteLLM in any capacity, the action is immediate: audit every integration, rotate every secret that has touched that toolchain, and validate the integrity of your CI/CD pipelines. Hudson Rock is conducting a global ethical disclosure effort, but the full scope of downstream compromise is still being assessed. Don't wait for a notification.
Jordan: And broaden the lesson. How many AI tools in your stack have this kind of privileged access? LiteLLM is one. There are dozens of similar frameworks, wrappers, and orchestration layers that your development teams have adopted. Most of them were never subjected to the same supply chain security scrutiny you'd apply to a traditional enterprise vendor.
Alex: Next up, the City-Forum campaign. Researchers at Reco have been tracking a campaign that's been systematically harvesting data from misconfigured Salesforce and ServiceNow portals worldwide for at least seventeen months. And Jordan, the uncomfortable part of this story is that nothing is broken.
Jordan: Right. There's no CVE here. There's no exploit. This is guest user access working exactly as configured. Someone registered a domain in 2002, let it lapse, brought it back, pointed it at a rented German server, and has been methodically pulling records from organizations that left their guest access settings too permissive. It's elegant, it's patient, and it's been running for a year and a half.
Alex: This is a SaaS governance problem, pure and simple. And it's systemic. Most enterprises have hundreds of SaaS applications with externally facing access controls that were configured once and never revisited. Guest access, anonymous access, public-facing knowledge bases. These are the digital equivalent of leaving your filing cabinets in the lobby. CISOs should treat this as an urgent prompt to audit guest and anonymous access across their entire SaaS estate. Not just Salesforce and ServiceNow. Everything.
Jordan: The seventeen-month dwell time is the number that should bother people. That's not a smash-and-grab. That's systematic intelligence collection. And it's still active and expanding.
Alex: Let's shift to vulnerabilities. We've got three that matter this morning and I want to move through them efficiently. Jordan, start with Lazarus.
Jordan: CVE-2026-68820. Windows zero-day, actively exploited by Lazarus Group as part of Operation Dream Job, targeting defense and aerospace companies in France, Germany, Brazil, and India. Achieves SYSTEM-level access. CISA has added it to the Known Exploited Vulnerabilities catalog. Federal agencies already have a remediation deadline. Here's the notable detail: Lazarus used post-quantum key exchange to protect delivery of the exploit. That's a level of operational security that signals they're planning for a future where current encryption is breakable. Defense and aerospace CISOs, verify your patch status this morning.
Alex: Next, SharePoint. CVE-2026-55040, CVSS 9.1. Critical authentication bypass in on-premises SharePoint. It was patched in July's Patch Tuesday. Rapid7 released a public proof-of-concept, and active exploitation is now underway. If you delayed your July patches, you are at risk right now. Authentication bypasses in SharePoint have historically been chained with code execution vulnerabilities for full domain compromise. This is not theoretical.
Jordan: And third, Gunra ransomware. Joint advisory from U.S. and Korean government agencies. Gunra actors are exploiting Fortinet vulnerabilities to gain initial access to critical infrastructure organizations, then using stealth techniques to exfiltrate large volumes of data from Microsoft services. If you're in critical infrastructure, check your Fortinet patch posture and review your Microsoft data access controls. The joint U.S.-Korean advisory elevates this beyond a typical ransomware warning.
Alex: Which brings us to the patch volume story. August Patch Tuesday from Microsoft is running at approximately five times the pre-AI-era monthly average. AI-assisted vulnerability discovery is producing patch volumes that are fundamentally straining enterprise patch management programs. And it's a double-edged sword, because the same AI capabilities accelerating Microsoft's internal bug discovery are also accelerating adversarial exploit development.
Jordan: NIST is separately modernizing the NVD to handle AI-scale vulnerability research, which tells you the infrastructure itself is buckling under the volume. CISOs need to accept that traditional patch cycles are no longer viable at this scale. Risk-based prioritization isn't optional anymore. It's the only way to operate.
Alex: Jordan, let's close with the bigger picture. What's the thread connecting today's stories?
Jordan: The thread is the collapse of boundaries. The boundary between government and private sector in offensive operations. The boundary between human-directed and autonomous attacks. The boundary between manageable and unmanageable patch volumes. The boundary between configured-as-intended and actually-secure. Every one of these stories is about a line that used to exist and no longer does, or is about to stop existing.
Alex: And the strategic implication for CISOs is that the frameworks, the assumptions, the operating models that were built for a world with those boundaries need to be rebuilt. Your threat model needs to account for autonomous AI adversaries. Your vendor risk model needs to account for AI toolchain supply chain risk. Your SaaS governance model needs to account for misconfigurations that aren't vulnerabilities. And your government contracting risk model might need to account for being pulled into offensive operations. These aren't future problems. They're today's stories.
Jordan: The organizations that will navigate this well are the ones that can update their assumptions as fast as the environment is changing. And right now, the environment is changing very fast.
Alex: That's our show for Thursday, August 13th. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-13.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.