Cleartext logocleartext_
daily briefing

Cleartext – August 26, 2026

Wednesday, August 26, 2026·10:27

Cleartext – August 26, 2026
10:27·6.4 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – August 26, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 5 topic areas, including: U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches; Average Cyber Insurance Losses Increase Despite Fewer Claims; AI vulnerability discovery scores the highest impact of 20 emerging risks.

Stories Covered

🌍 Geopolitical

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

The Hacker News · Aug 25 · Relevance: █████████░ 9/10

Why it matters to CISOs: Treasury sanctions signal escalating U.S.-Iran cyber tensions, with direct implications for critical infrastructure operators who should reassess threat actor targeting and attribution intelligence feeds. Board-level briefings on geopolitical risk posture are warranted.

  • U.S. Treasury announced sanctions on Iranian cyber actors as part of a 'whole-of-government economic campaign' against Iran
  • Sanctions tied to breaches of critical infrastructure targets
  • Part of a broader effort to sever Iran's global financial connections

📖 Read full article

📡 Macro Trends

Average Cyber Insurance Losses Increase Despite Fewer Claims

Infosecurity Magazine · Aug 26 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Rising per-claim cyber insurance costs driven by privacy litigation have direct implications for enterprise risk transfer strategy and premium negotiations; CISOs must factor surging loss trends into cyber insurance program reviews and board risk discussions.

  • Chubb reported that growing privacy litigation is a primary driver of surging cyber claim costs in the US
  • Average losses per claim are increasing even as the total number of claims declines
  • Trend suggests higher-severity, lower-frequency incidents are dominating the insurance loss picture

📖 Read full article

AI vulnerability discovery scores the highest impact of 20 emerging risks

Help Net Security · Aug 26 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A Gartner survey of 316 companies now ranks AI-assisted vulnerability discovery as the highest-impact emerging risk, overtaking information integrity risk—CISOs must factor accelerated adversarial exploit development timelines into patching SLAs and threat modeling assumptions.

  • Gartner survey of 316 risk managers and senior executives ranked AI vulnerability discovery as the top emerging risk by impact in Q2 2026
  • The same metric was not in the top five just three months prior, reflecting rapid perception shift
  • AI systems are lowering the bar for discovering previously unknown flaws, compressing the window between vulnerability existence and active exploitation

📖 Read full article

Is Cyber Facing an Affordability Crisis?

Dark Reading · Aug 25 · Relevance: ██████░░░░ 6/10

Why it matters to CISOs: As global cybersecurity defense spending approaches $240 billion and breach costs hit record highs, CISOs at large enterprises face growing supply chain exposure from dangerously under-resourced SMB partners and suppliers who cannot afford adequate defenses.

  • Global cybersecurity defense spending is approaching $240 billion annually
  • Breach costs are at record highs while small businesses remain dangerously underprotected
  • The affordability gap in SMB security creates systemic supply chain risk for large enterprise organizations

📖 Read full article

🔓 Data Breach

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

The Hacker News · Aug 25 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A commercially available AiTM phishing kit has compromised Microsoft 365 accounts at scale across thousands of enterprises, demonstrating that MFA alone is insufficient and pushing CISOs toward phishing-resistant authentication (FIDO2/passkeys) and Conditional Access hardening.

  • Mirage2FA phishing-as-a-service toolkit targeted Microsoft 365 accounts across 4,500+ US and EU companies between 2024 and 2026
  • 48% of targeted email addresses were potentially compromised according to ANY.RUN research
  • The kit abuses legitimate Microsoft login flows to bypass two-factor authentication in real time

📖 Read full article

Employee benefits platform Paylogix says hackers stole financial and health data

The Record (Recorded Future) · Aug 25 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Akira ransomware's breach of a benefits administration platform highlights third-party vendor risk for enterprises whose employee health and financial data is processed by HR tech providers; CISOs should review vendor access controls and breach notification obligations in benefits platform contracts.

  • Paylogix, an employee benefits management firm, disclosed that hackers stole sensitive financial and health data on tens of thousands of individuals
  • The Akira ransomware group has been attributed to the attack
  • Data stolen includes the type of sensitive HR/benefits information held by countless enterprise third-party vendors

📖 Read full article

⚖️ Governance & Policy

Water sector passes, government sector fails attempts to spot and halt simulated CISA attack

CyberScoop · Aug 25 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: CISA's red team report provides a rare sector-level benchmark on detection and containment capability, offering CISOs a credible reference point for assessing their own program maturity and justifying investment in detection engineering and incident response readiness.

  • CISA red teamers achieved initial access to both a government agency and a water utility in simulated attack exercises
  • The water sector organization quickly detected, isolated, and shut down the attack before lateral movement
  • The government sector organization failed to detect or halt the simulated intrusion in time

📖 Read full article

🚨 Critical Vulnerability

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

The Hacker News · Aug 26 · Relevance: █████████░ 9/10

Why it matters to CISOs: CVE-2026-60004 (CVSS 9.8) is actively exploited in the wild against self-hosted Gitea instances, representing a supply chain risk for any enterprise using Gitea for source code management; CISA KEV listing mandates federal agency remediation and should trigger enterprise patch prioritization immediately.

  • CVE-2026-60004 carries a CVSS score of 9.8 and allows unauthenticated RCE via arbitrary shell command execution by any user with repository write access
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog following confirmed active exploitation
  • Reported attack dropped a cryptocurrency miner-like payload; source code repositories at risk of full compromise

📖 Read full article

Hackers breached over 270 Zimbra servers in ongoing attacks

BleepingComputer · Aug 25 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Active mass exploitation of a high-severity Zimbra RCE flaw has already compromised 270+ servers, and CISA has issued a KEV mandate; any enterprise running on-premises Zimbra Collaboration Suite must treat this as an emergency patching event given the email platform's access to sensitive communications.

  • Over 270 Zimbra Collaboration Suite servers have been compromised in ongoing RCE attacks
  • CISA ordered federal agencies to patch the actively exploited Zimbra flaw
  • Zimbra's developer took nearly a full month to release a patch after initial disclosure

📖 Read full article

Australia Warns of Active Exploitation of Critical TeamCity Server Flaw

Infosecurity Magazine · Aug 25 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Active exploitation of a critical TeamCity flaw—now flagged by both Australian and US government agencies—targets CI/CD infrastructure that sits at the heart of enterprise software supply chains, making this a high-priority patching event for any organization using JetBrains TeamCity.

  • Australian cyber authorities issued an urgent advisory warning of active exploitation of a critical TeamCity server vulnerability
  • The warning follows a similar advisory from US government agencies
  • TeamCity is widely deployed CI/CD infrastructure; compromise enables supply chain attacks via build pipeline access

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Welcome to Cleartext. It's Wednesday, August 26th, 2026. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Alex: We have a packed show today. Iran sanctions, a phishing kit that's chewing through Microsoft 365 at industrial scale, some critical vulns that need your attention this morning, and a cyber insurance trend that should change how you're thinking about risk transfer. Plus, a fascinating CISA red team report that gives us a rare apples-to-apples comparison between sectors. But Jordan, let's start where you want to start.

Jordan: Yeah, let's start with the Treasury sanctions because the language coming out of Washington yesterday was notably aggressive. Treasury announced sanctions against Iranian cyber actors, and they framed it as part of an "unprecedented, whole-of-government economic campaign" to sever Iran's financial connections globally. The stated objective, and I'm quoting here, is to "sever every economic lifeline that sustains this tyrannical regime." That's not diplomatic hedging. That's an escalation posture.

Alex: And for our audience, the immediate question is what does this mean operationally. If you're in critical infrastructure, energy, water, transportation, you've been on notice about Iranian threat actors for years. But sanctions like these tend to correlate with retaliatory cyber activity. Iran has historically responded to economic pressure with cyber operations. It's one of their asymmetric levers.

Jordan: Exactly right. And the timing matters. We're seeing this alongside broader tensions in the region. Iranian-linked groups have a track record of going after operational technology environments, not just IT. They've hit water treatment facilities, they've probed energy infrastructure. The sanctions specifically tied to critical infrastructure breaches tell you what the intelligence community is seeing in terms of targeting.

Alex: So the action item here is straightforward. If you're a CISO at a critical infrastructure operator, this warrants a board-level briefing on geopolitical risk posture. Update your threat intelligence feeds. Make sure your attribution intelligence is current. And honestly, if you don't have a relationship with CISA's regional office, today's a good day to start one.

Jordan: And if you're not in critical infrastructure, don't tune out. Iranian groups have targeted financial services, healthcare, and tech companies as secondary objectives. The blast radius of geopolitical escalation doesn't respect sector boundaries.

Alex: Let's pivot to something that hit a lot of inboxes yesterday. Mirage2FA. Jordan, this one is significant at scale.

Jordan: This is a phishing-as-a-service toolkit that has been running a campaign against Microsoft 365 accounts across more than 4,500 companies in the US and EU between 2024 and now. ANY.RUN's research suggests 48 percent of targeted email addresses were potentially compromised. Let that number sit for a second. Nearly half.

Alex: And the mechanism here is what makes it dangerous. This isn't your garden-variety credential phishing page. Mirage2FA is an adversary-in-the-middle kit that abuses legitimate Microsoft login flows in real time. It proxies the actual authentication process, which means it captures session tokens after the user has completed MFA. Your user does everything right, they authenticate properly, and they still get compromised.

Jordan: This is the story that should finally kill the "we have MFA, we're fine" narrative in any remaining boardroom where it still lives. MFA is necessary. It is not sufficient. The answer here is phishing-resistant authentication. FIDO2, passkeys, hardware tokens. And Conditional Access policies that evaluate device compliance, network location, and risk signals before granting session tokens.

Alex: If you're running Microsoft 365 at enterprise scale and you haven't deployed phishing-resistant MFA, this is your case study for the budget conversation. Forty-eight percent potential compromise rate across thousands of companies. That's the number you bring to your CFO.

Jordan: And check your Conditional Access policies. Token theft mitigation, continuous access evaluation, those need to be on. Not tomorrow. Today.

Alex: Let's stay on the breach and vulnerability track for a minute because we have three active exploitation stories that need attention this morning. Jordan, rapid fire.

Jordan: First, CVE-2026-60004 in Gitea. CVSS 9.8. Unauthenticated remote code execution. If you have write access to a repository, you can execute arbitrary shell commands on the server. CISA added it to the Known Exploited Vulnerabilities catalog yesterday. Attacks in the wild are dropping crypto miner payloads, but let's be clear, the capability is full server compromise. If you self-host Gitea for source code management, this is a patch-now event. Your source code is the crown jewel.

Alex: Second, Zimbra. Over 270 Zimbra Collaboration Suite servers already compromised through an RCE flaw. CISA has ordered federal agencies to patch. And here's the detail that should bother you: Zimbra's developer took nearly a full month to release a patch after initial disclosure. A month. Your email platform, with access to every sensitive communication in your organization, sitting exposed for a month.

Jordan: And third, TeamCity. Both Australian and US government agencies have issued urgent advisories for active exploitation of a critical JetBrains TeamCity flaw. TeamCity sits in CI/CD pipelines. Compromise here means an attacker can inject malicious code into your build process. This is supply chain attack infrastructure. If you're running TeamCity, patch immediately and audit your build pipeline integrity.

Alex: Three different platforms, three active exploitation campaigns, all hitting infrastructure that touches your most sensitive assets: source code, email, and software delivery. If you're a CISO hearing this, the question isn't whether to patch. It's whether your vulnerability management program can actually execute on three simultaneous emergency patches across different teams. That's the real test.

Jordan: And this connects directly to the Gartner survey that dropped today. Three hundred sixteen risk managers ranked AI-assisted vulnerability discovery as the number one emerging risk by impact in Q2 2026. Three months earlier, it wasn't even in the top five.

Alex: That's a dramatic shift in perception.

Jordan: It is, and it's grounded in reality. AI systems are lowering the bar for discovering previously unknown flaws. The window between a vulnerability existing and being actively exploited is compressing. What used to be weeks or months is becoming days. The three vulns we just discussed, that's the current tempo. It's going to accelerate.

Alex: Which means your patching SLAs need to reflect this new reality. If your organization's standard remediation window for critical vulnerabilities is still 30 days, you are operating on assumptions from a different era. Threat modeling needs to account for faster adversarial exploit development. This is a structural change, not a temporary spike.

Jordan: Let's talk about the Paylogix breach because it illustrates a different dimension of risk. Akira ransomware hit an employee benefits administration platform and stole sensitive financial and health data on tens of thousands of individuals.

Alex: This is the third-party vendor risk story that keeps repeating. Your HR tech stack processes some of the most sensitive data in your organization. Health information, financial data, dependent details. And it's sitting in platforms that your security team may have limited visibility into.

Jordan: The action here is to review your vendor access controls and breach notification obligations in your benefits platform contracts. Most enterprises have dozens of HR tech vendors processing employee data. How many of those have you actually assessed in the last twelve months? How many have contractual obligations around notification timelines and remediation standards that you could actually enforce?

Alex: And this feeds into the broader affordability story from Dark Reading. Global cybersecurity spending is approaching 240 billion dollars annually. Breach costs are at record highs. But small and mid-sized businesses, many of which are your vendors, your supply chain partners, are dangerously underprotected. The affordability gap in SMB security creates systemic supply chain risk for large enterprises.

Jordan: You can spend whatever you want on your own defenses. If your benefits administrator, your logistics partner, or your regional law firm can't afford adequate security, their breach becomes your breach. That's the math.

Alex: Which brings us to the insurance side. Chubb reported that average losses per cyber claim are increasing even as total claim volume is declining. The driver is privacy litigation. Higher severity, lower frequency. Fewer incidents, but each one costs dramatically more.

Jordan: This is the trend that should reshape your risk transfer strategy. If you're in your annual cyber insurance renewal cycle, the conversation needs to include these loss trends. Underwriters are seeing this data. Your premiums and coverage terms will reflect it. And if you're not modeling privacy litigation exposure in your risk quantification, you're underestimating your tail risk.

Alex: One more story before we look ahead. CISA published a red team report comparing outcomes across a government agency and a water utility. Both were breached initially. The water utility detected, isolated, and shut down the intrusion before lateral movement. The government agency did not.

Jordan: This is rare. We almost never get sector-level benchmarking on detection and response capability from a credible source. The water sector organization did what we all say we want to do. They detected adversary activity early and contained it before it mattered. The government organization failed that test.

Alex: For CISOs, this is a reference point. Use it. When you're justifying investment in detection engineering, in incident response readiness, in purple teaming, this report gives you a credible external benchmark. CISA tested two organizations under comparable conditions and got dramatically different outcomes. The difference was detection and response maturity.

Jordan: And the fact that it was a water utility that succeeded is worth noting. This isn't a Fortune 50 company with unlimited budget. It's an organization that prioritized the right capabilities.

Alex: Let's close with outlook. Jordan, what's the thread that ties today together?

Jordan: Compression. Time to exploit is compressing. The gap between vulnerability discovery and weaponization is shrinking because of AI. The gap between a phishing kit being developed and compromising thousands of companies is shrinking because of commercialization. And the gap between geopolitical tension and cyber retaliation is shrinking because that's the playbook now.

Alex: And on the business side, the cost per incident is going up while the window to prevent it is going down. That's the fundamental challenge. Your board needs to understand that the threat landscape isn't just getting more dangerous, it's getting faster. Your security program's value isn't just measured in what it prevents. It's measured in how quickly it can detect and contain what gets through.

Jordan: Watch the Iran situation. If we see retaliatory cyber operations in the next few weeks, it won't be a surprise. But preparation beats prediction every time.

Alex: That's the show for today. Show notes and links to every story we covered are at cleartext.fm. Thanks for listening. We'll see you tomorrow.

Jordan: Stay sharp.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-26.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.