Cleartext – August 24, 2026
Monday, August 24, 2026·10:15
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – August 24, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 8 stories across 5 topic areas, including: Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant; Risky Bulletin: Expired credit cards can be used for malicious transactions; UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit.
Stories Covered
🌍 Geopolitical
Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant
Infosecurity Magazine · Aug 24 · Relevance: ██████████ 10/10
Why it matters to CISOs: A confirmed Iranian nation-state attack that physically disrupted a UK power plant represents a landmark escalation in OT/ICS threat activity, forcing CISOs at critical infrastructure and adjacent organizations to reassess their CNI risk posture and resilience planning immediately.
- Iranian threat actors conducted a cyberattack that resulted in shutdown of a UK power plant
- The incident highlights persistent and escalating threats to operational technology and critical national infrastructure
- Security experts are calling for urgent reassessment of CNI cyber defenses across sectors
Risky Bulletin: Expired credit cards can be used for malicious transactions
Risky Business News · Aug 24 · Relevance: █████████░ 9/10
Why it matters to CISOs: The combination of Lazarus Group compromising South Korea's Presidential Office and the Iranian CNI attack signals a surge in state-sponsored offensive cyber operations, with direct implications for threat intelligence programs and geopolitical risk assessments at enterprise level.
- North Korea's Lazarus Group successfully breached South Korea's Presidential Office
- Iranian hackers caused a UK power plant shutdown in a separate incident covered in the same briefing
- Multiple simultaneous nation-state attacks across different geographies signal a broader escalation pattern
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
The Hacker News · Aug 24 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A Chinese-speaking threat group using AI to scale attacks and deploying tooling specifically engineered to bypass EDR solutions signals a meaningful capability shift that should prompt CISOs to evaluate the resilience of their endpoint detection assumptions.
- UAT-10147, a Chinese-speaking cybercrime group, is using AI to operationalize and scale attacks against Windows and Linux web servers globally
- The group deploys a backdoor called SPECTRE with built-in EDR bypass capabilities and a Linux rootkit
- Targets span education, media, technology, and gaming sectors across multiple countries including Canada and Brazil
📡 Macro Trends
Ransomware attackers are zeroing in on mid-market companies
Help Net Security · Aug 24 · Relevance: ██████░░░░ 6/10
Why it matters to CISOs: The finding that mid-market companies ($10M–$1B revenue) account for 73% of ransomware incidents has direct implications for enterprise CISOs managing supply chain and third-party risk, as many of their vendors and partners fall squarely in this high-target band.
- Mid-market firms accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe from January 2023 to June 2026
- The analysis covered 13,336 incidents; the mid-market share has been consistently between 72–75% throughout the period
- Mid-market is defined as $10M–$1B in annual revenue, capturing a large share of enterprise supply chain partners
🔓 Data Breach
Researchers Uncover Thousands of Leaked AWS Keys
Infosecurity Magazine · Aug 24 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Over 9,000 active AWS key pairs publicly exposed represents a systemic secrets-management failure at enterprise scale, giving CISOs direct evidence to justify or accelerate investments in secrets scanning, rotation automation, and developer security training.
- Truffle Security discovered over 9,000 publicly accessible and active AWS key pairs
- Active keys indicate these credentials have not been rotated or revoked following exposure
- Public exposure of cloud credentials enables lateral movement, data exfiltration, and resource abuse at scale
⚖️ Governance & Policy
CISA’s logging guidance works beyond government
Help Net Security · Aug 24 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: CISA's new Logging Reference Architecture, while targeted at federal agencies under OMB M-26-14, provides a defensible framework that enterprise CISOs can adopt to benchmark their own logging strategies and demonstrate detection and forensic readiness to boards and regulators.
- CISA released a Logging Reference Architecture (LRA) in August 2026 to support OMB Memorandum M-26-14 compliance
- CISA explicitly encourages critical infrastructure operators and private sector organizations to adopt the guidance
- The framework centers on operational utility of logs: can you detect and reconstruct an attack from what you collect?
🚨 Critical Vulnerability
CISA orders urgent patching of actively exploited Zimbra flaw
BleepingComputer · Aug 24 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A CISA emergency directive with a three-day patching deadline for a Zimbra flaw under active exploitation requires immediate action from any enterprise running ZCS, and signals the severity of ongoing email infrastructure targeting by threat actors.
- CISA has mandated US federal agencies patch the Zimbra Collaboration Suite vulnerability within three days
- The flaw is confirmed to be actively exploited in the wild
- Zimbra is widely deployed in enterprise and government email environments globally
Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
The Hacker News · Aug 24 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A CVSS 9.1 unauthenticated account takeover flaw in Keycloak — a widely adopted open-source IAM platform used across enterprise and cloud-native environments — poses existential risk to identity infrastructure and warrants emergency patching prioritization.
- CVE-2026-18963 is rated CVSS 9.1 and allows unauthenticated remote attackers to take over any user account via forced password reset
- Red Hat and the Keycloak project have released patches
- Keycloak is broadly deployed as an identity and access management layer in enterprise and cloud environments
Further Reading
- 🌍 Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant — Infosecurity Magazine
- 🌍 Risky Bulletin: Expired credit cards can be used for malicious transactions — Risky Business News
- 🌍 UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit — The Hacker News
- 📡 Ransomware attackers are zeroing in on mid-market companies — Help Net Security
- 🔓 Researchers Uncover Thousands of Leaked AWS Keys — Infosecurity Magazine
- ⚖️ CISA’s logging guidance works beyond government — Help Net Security
- 🚨 CISA orders urgent patching of actively exploited Zimbra flaw — BleepingComputer
- 🚨 Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account — The Hacker News
Full Transcript
Click to expand full episode transcript
Alex: Good morning. It's Monday, August 24th, 2026. This is Cleartext. I'm Alex Chen, alongside Jordan Reeves, and we have a packed show for you today. An Iranian cyberattack physically shut down a UK power plant over the weekend. We're going to spend real time on that because it changes the calculus for anyone touching critical infrastructure. We'll also cover a Lazarus Group breach of South Korea's Presidential Office, a Chinese-speaking threat group using AI to scale server compromises with purpose-built EDR bypass tooling, a systemic cloud credentials problem that should embarrass the industry, a critical Keycloak identity flaw, a Zimbra emergency directive, CISA's new logging framework, and some important data on why your mid-market suppliers are the soft underbelly of your risk program. Jordan, let's get into it. You want to start with the big one.
Jordan: Yeah, let's start exactly where we should. An Iranian threat group successfully conducted a cyberattack that physically shut down a UK power plant. Not degraded. Not disrupted IT systems adjacent to operations. Shut down. This is a line we've been watching for years, and it got crossed this weekend. For context, the last time we saw a confirmed nation-state attack cause physical disruption to power infrastructure in a Western allied nation, you have to go back to the Ukrainian grid attacks in 2015 and 2016, and those were Russian. Iran achieving this against UK critical national infrastructure is a significant capability demonstration.
Alex: And the implications ripple well beyond the energy sector. If you're a CISO at a water utility, a pipeline operator, a port authority, a hospital system, anything that falls under the CNI umbrella, this is your board conversation this week. The question isn't whether you're an Iranian target. The question is whether your OT environment could withstand a similarly motivated and resourced adversary. Because the techniques that work against one ICS environment tend to be transferable. The specifics of this attack will take weeks to fully unpack, but the strategic signal is immediate.
Jordan: What I'd emphasize to this audience is that the security expert consensus coming out of the UK right now is blunt. They're calling the state of CNI cyber defense fragile. That's the word being used. Fragile. And that's not hyperbole from vendors trying to sell something. That's the UK security establishment looking at their own infrastructure and saying we have systemic gaps. If you run OT, today is the day you pressure-test your assumptions about air gaps, about network segmentation between IT and OT, about your visibility into programmable logic controllers and SCADA systems. Because the adversary just proved they can get deep enough to cause physical consequences.
Alex: And this connects directly to the second story, which is the Lazarus Group successfully breaching South Korea's Presidential Office. Same weekend. Different adversary, different geography, same signal. We are in a period of escalating state-sponsored offensive cyber operations across multiple theaters simultaneously. North Korea hitting the South Korean presidency, Iran hitting UK energy infrastructure. These aren't isolated incidents. This is a pattern.
Jordan: Exactly. And for CISOs, the operational takeaway is that your threat intelligence program needs to be treating geopolitical risk as a first-class input, not a nice-to-have appendix in your quarterly threat report. If you're operating in sectors or geographies that intersect with Iranian, North Korean, Chinese, or Russian strategic interests, your threat model needs to reflect that reality with specific detection priorities and response playbooks. The days of generic threat intelligence are over.
Alex: Let's stay on the nation-state theme because the third story fits perfectly. UAT-10147, a Chinese-speaking cybercrime group, is using AI to operationalize and scale attacks against web servers globally. They're deploying a backdoor called SPECTRE that has built-in EDR bypass capabilities and a Linux rootkit. The targets span education, media, technology, gaming, across multiple countries.
Jordan: This one is important for a specific reason. It's not just another threat group with custom tooling. It's the AI-assisted scaling piece combined with purpose-built EDR evasion. If your security architecture assumes that your EDR stack is your last reliable line of detection, this group is explicitly engineering around that assumption. The SPECTRE backdoor is designed to be invisible to the tools most enterprises rely on. And the AI component means they're not doing this one server at a time. They're industrializing initial access.
Alex: So the practical question for CISOs is, what's your detection strategy when EDR fails? Do you have network-level anomaly detection? Do you have behavioral analytics that operate independently of endpoint agents? Do you have integrity monitoring on your web servers? Because this group is targeting exactly the gap between what EDR promises and what it actually catches.
Jordan: And they're hitting Linux servers, which in many enterprises are the forgotten stepchildren of the security program. All the budget goes to Windows endpoint protection, and the Linux web servers sitting in your DMZ are running last year's agent with last month's signatures.
Alex: Let's shift to the Keycloak vulnerability because this one demands immediate attention. CVE-2026-18963, rated CVSS 9.1. It allows an unauthenticated remote attacker to take over any user account by forcing a password reset. Red Hat and the Keycloak project have released patches.
Jordan: If you run Keycloak, and a lot of enterprises do because it's become the de facto open-source identity and access management layer in cloud-native environments, this is a drop-everything-and-patch situation. Unauthenticated account takeover in your identity provider is about as close to game over as it gets. An attacker doesn't need credentials, doesn't need to be on your network. They can remotely force a password reset and take over any account in your Keycloak instance. That's your SSO, your OAuth provider, your entire identity trust chain.
Alex: And the timing matters. A lot of organizations adopted Keycloak specifically to avoid vendor lock-in on identity. Good strategic decision, but open-source IAM means you own the patching lifecycle. There's no managed service provider pushing this update for you. Your team needs to validate the patch, test it, and deploy it. Today. Not this sprint. Today.
Jordan: Similarly, CISA has issued an emergency directive ordering federal agencies to patch an actively exploited Zimbra Collaboration Suite vulnerability within three days. Zimbra is still widely deployed in enterprise and government email environments. If you're running ZCS, this is confirmed active exploitation, not theoretical. Three-day deadline for federal, and honestly, that should be your deadline too.
Alex: Two critical vulnerabilities in identity infrastructure and email infrastructure in the same news cycle. That's a reminder that the foundational services, the ones nobody thinks about because they just work, are exactly where attackers are focusing.
Jordan: Alright, let's talk about the AWS keys story because this one is frustrating. Truffle Security discovered over 9,000 publicly accessible and active AWS key pairs. Active. Meaning these credentials have been exposed and nobody rotated or revoked them.
Alex: Nine thousand. And these aren't test accounts. Active key pairs mean active environments, production workloads, real data. Every one of those keys is a potential entry point for lateral movement, data exfiltration, cryptomining, or worse. This is a systemic secrets management failure, and it's happening across the industry despite the fact that we have mature tooling to prevent it. Secrets scanning, automated rotation, vault solutions. The technology exists. The discipline doesn't.
Jordan: If you need ammunition to fund a secrets management program or to mandate pre-commit hooks that scan for credentials, this is your evidence. Print this report out and put it in front of your CFO.
Alex: Let's touch on the mid-market ransomware data from Black Kite. They analyzed over 13,000 ransomware and data extortion incidents between January 2023 and June 2026. Mid-market companies, defined as ten million to one billion in annual revenue, accounted for 73% of incidents. And that number has been consistent, between 72 and 75 percent, for the entire period.
Jordan: This matters for enterprise CISOs not because you are mid-market, but because your supply chain is. Your law firm, your regional cloud provider, your logistics partner, your payroll processor. These are mid-market companies. And they are absorbing nearly three quarters of all ransomware activity. Your third-party risk program needs to weight this reality appropriately.
Alex: It also explains why supply chain compromises keep being the vector into larger enterprises. The attackers aren't coming through your front door. They're coming through your vendor's side window.
Jordan: Last piece before we look ahead. CISA released a Logging Reference Architecture in August to support the OMB M-26-14 mandate. It's aimed at federal agencies, but CISA explicitly encouraged critical infrastructure operators and private sector organizations to adopt it. The core question the framework asks is simple and brutal. When an attack hits, can you actually use the logs you collect to detect it and reconstruct what happened?
Alex: I love this framework because it reframes logging from a compliance checkbox to an operational capability question. Most enterprises collect enormous volumes of logs. Very few can actually use them forensically when it matters. If you're looking for a benchmark to evaluate your SIEM strategy, your log retention policies, your detection engineering maturity, this LRA is a gift. It's free, it's well-structured, and it gives you a defensible reference point for board conversations about detection readiness.
Jordan: Looking ahead this week, Alex, the theme is obvious. The threat environment just got materially worse across multiple dimensions simultaneously. Nation-state actors achieving physical disruption of Western critical infrastructure, AI-assisted scaling of offensive operations, identity infrastructure under direct attack. This isn't a trend line. This is a step function.
Alex: Agreed. And the operational implication is that CISOs need to be having honest conversations internally about assumptions. The assumption that your OT network is adequately segmented. The assumption that your EDR stack catches what matters. The assumption that your identity provider is hardened. The assumption that your suppliers can withstand what's being thrown at them. Every one of those assumptions got challenged this weekend. The CISOs who act on that this week will be in a materially better position than those who wait for the next incident to force the conversation.
Jordan: And for those of you heading into board meetings or budget cycles, the Iran-UK power plant attack is the clearest example of cyber risk becoming physical risk that you're going to get. Use it. Not to scare. To clarify. This is what the threat environment actually looks like now.
Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. We're back tomorrow. Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-24.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.