Cleartext logocleartext_
daily briefing

Cleartext – August 28, 2026

Friday, August 28, 2026·9:46

Cleartext – August 28, 2026
9:46·6.0 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – August 28, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 4 topic areas, including: White House bans foreign-made equipment for power generation over cyber backdoor concerns; APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations; China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access.

Stories Covered

🌍 Geopolitical

White House bans foreign-made equipment for power generation over cyber backdoor concerns

The Record (Recorded Future) · Aug 27 · Relevance: █████████░ 9/10

Why it matters to CISOs: This executive action directly affects supply chain security programs and procurement policies for any enterprise operating or supporting critical infrastructure; CISOs must assess vendor exposure and update third-party risk frameworks immediately.

  • White House is banning acquisition of foreign-made components used to manage electricity and power generation
  • Administration cites foreign actors exploiting and creating vulnerabilities in energy management technology
  • Order has immediate implications for utility sector supply chains and industrial control system procurement

📖 Read full article

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

The Hacker News · Aug 28 · Relevance: ████████░░ 8/10

Why it matters to CISOs: APT28's deployment of a previously undocumented backdoor against European government and diplomatic targets signals continued Russian state-sponsored espionage campaigns that frequently pivot to private-sector entities in adjacent industries; CISOs with European operations or government contractor relationships should review indicators of compromise immediately.

  • APT28-linked campaigns targeted government and diplomatic organizations in Romania, Spain, and Türkiye between late 2025 and April 2026
  • New backdoor HOOKEDGE is a lightweight Windows batch script not previously documented
  • Campaigns were attributed by Recorded Future's Insikt Group based on TTPs and infrastructure overlap

📖 Read full article

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

The Hacker News · Aug 28 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Factory-implanted firmware backdoors in Chinese-manufactured networking hardware are a direct supply chain threat; CISOs should audit network device procurement and assess whether ZBT routers appear in their infrastructure or that of key third parties.

  • Two factory-embedded implants (SPEAKINGSTONE and DARKLANTERN) discovered in ZBT router firmware by VulnCheck
  • Both implants allow unauthenticated remote attackers to execute commands as root
  • Tracked as CVE-2026-74232 and CVE-2026-74233; implants were present in devices as shipped

📖 Read full article

North Korean remote workers are broadening their job hunt beyond IT

Help Net Security · Aug 28 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The expansion of DPRK insider threat activity into sales, marketing, and healthcare roles means HR and security teams can no longer limit screening efforts to technical positions; CISOs must widen identity verification and insider threat programs across all remote hiring.

  • Huntress has identified suspected DPRK remote workers embedded in sales, marketing, and medical roles — not just IT
  • Workers are being hired through deception rather than system compromise, making traditional detection methods ineffective
  • DPRK workers often perform legitimate job duties, making behavioral detection particularly difficult

📖 Read full article

📡 Macro Trends

Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations

Infosecurity Magazine · Aug 28 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The documented weaponization of a commercial AI coding agent (Cursor) to support ransomware reconnaissance and exploitation marks a meaningful escalation in AI-enabled threats that CISOs must factor into AI tool governance policies and acceptable-use frameworks.

  • Aurora ransomware operators are abusing Cursor Agent AI to conduct reconnaissance and exploitation tasks
  • This represents a real-world case of commercial AI tooling being integrated into ransomware kill chains
  • The incident underscores risks of broadly available agentic AI tools being leveraged by criminal actors at scale

📖 Read full article

Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn

Infosecurity Magazine · Aug 28 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A coordinated warning from over 100 major technology companies — including OpenAI, Anthropic, Google, and Microsoft — signals that AI-accelerated attacks are approaching an inflection point that should directly inform board-level risk conversations and defense investment priorities.

  • Over 100 companies including OpenAI, Anthropic, Google, and Microsoft issued a collective warning about AI-enabled cyberattacks
  • Statement calls for collective action to deploy AI defensively to protect critical public services
  • Industry leaders characterize the window for effective defensive response as narrowing rapidly

📖 Read full article

🔓 Data Breach

ATF confirms cyberattack hit system containing info on its investigation targets

CyberScoop · Aug 28 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Qilin ransomware successfully breaching a federal law enforcement agency demonstrates the group's continued operational tempo against high-value targets, and the sensitivity of the compromised data (active investigation targets) raises significant counterintelligence concerns relevant to enterprises working with law enforcement.

  • Qilin ransomware group claimed responsibility for the attack on the ATF
  • Compromised system contained information on ATF investigation targets
  • ATF claims the incident was limited to a standalone system and did not impact critical operations

📖 Read full article

Manchester Airports Group breached, millions of customers’ data stolen

Help Net Security · Aug 28 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A confirmed large-scale breach at a major critical infrastructure operator affecting millions of travelers has immediate UK GDPR notification and regulatory implications; CISOs in the transportation and travel sector should review analogous controls and third-party data exposure.

  • Manchester Airports Group confirmed unauthorized access to customer data across three UK airports
  • Breach described as involving a 'quantity' of customer data affecting millions of individuals
  • Incident highlights ongoing targeting of critical infrastructure and travel sector by threat actors

📖 Read full article

🚨 Critical Vulnerability

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

The Hacker News · Aug 28 · Relevance: █████████░ 9/10

Why it matters to CISOs: ServiceNow is ubiquitous in enterprise environments for IT and security operations workflows; three simultaneous CVSS 10.0 vulnerabilities enabling unauthenticated code execution require immediate patch verification, particularly for self-hosted or partner-managed deployments that may not have received the automated update.

  • Three CVSS 10.0 flaws affect the ServiceNow AI Platform, enabling code injection, SQL injection, and privilege escalation by unauthenticated attackers
  • ServiceNow has patched hosted instances automatically but self-hosted and partner-managed customers must apply the update manually
  • A fourth vulnerability was also patched in the same release cycle

📖 Read full article

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

The Hacker News · Aug 28 · Relevance: ████████░░ 8/10

Why it matters to CISOs: PaperCut is widely deployed for print management across enterprise and education environments; active exploitation of chained zero-days with unauthenticated RCE and a bypassed first patch demands emergency verification of patch status across all NG and MF deployments.

  • Attackers are actively chaining two PaperCut vulnerabilities to achieve unauthenticated remote code execution on all versions of PaperCut NG and MF
  • Initial emergency patch was bypassed, requiring PaperCut to release a second emergency fix with additional hardening
  • PaperCut has confirmed active customer incidents and is treating the situation as highest priority

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Welcome to Cleartext. It's Friday, August 28th, 2026. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Alex: We have a packed show today. The White House just dropped a sweeping executive action banning foreign-made components in power generation equipment. We've got factory-embedded backdoors shipping in Chinese routers, APT28 rolling out a new backdoor across European governments, three simultaneous CVSS 10.0 vulnerabilities in ServiceNow, North Korean operatives expanding well beyond IT roles, AI tools being weaponized for ransomware, a federal law enforcement breach, millions of airport customer records stolen, and PaperCut getting chained into oblivion. Jordan, let's start with the big one.

Jordan: Yeah, let's talk about the executive order. The White House is banning acquisition of foreign-made components used in electricity management and power generation. The stated rationale is that foreign actors are, quote, "increasingly creating and exploiting vulnerabilities" in energy management technology. And look, this is not new rhetoric, but the action itself is significant. We've been dancing around this for years. The original bulk power system executive order from 2020 got paused, revived, modified. This one appears to have real teeth.

Alex: What makes this one different is the breadth. This isn't just about transformers from China, which was the previous conversation. This covers the full stack of components involved in managing electricity and power generation. If you're a CISO at a utility, an energy company, or frankly any enterprise that operates or supports critical infrastructure, you need to be pulling your procurement lists today. Your third-party risk framework needs an update, and you need to be having conversations with your supply chain teams about where your industrial control system components actually come from.

Jordan: And here's the thing that doesn't get said enough. Most organizations don't actually know. The bill of materials for a substation or a generation facility is sprawling, and the visibility into sub-tier suppliers is often terrible. This order is going to force a reckoning with that opacity.

Alex: Which connects perfectly to the ZBT router story, because this is the exact scenario the executive order is trying to prevent.

Jordan: Right. VulnCheck disclosed two factory-embedded implants in firmware for routers built by Shenzhen Zhibotong Electronics. These aren't vulnerabilities that got introduced through sloppy coding. These are implants, named SPEAKINGSTONE and DARKLANTERN, present in devices as shipped. Both give an unauthenticated remote attacker root access. They've been assigned CVEs. This is supply chain compromise at the manufacturing level.

Alex: And for CISOs, the question is straightforward but uncomfortable. Do you know if ZBT hardware is in your environment? Do you know if it's in your third parties' environments? These aren't enterprise-grade routers that show up in your procurement system with a nice label. They're often white-labeled, rebranded, embedded in other products. They show up in branch offices, in OT networks, in partner environments. The audit here is not trivial, but it's necessary.

Jordan: This is the supply chain story that keeps repeating. Whether it's Huawei, whether it's TP-Link, whether it's ZBT. The pattern is consistent, and the executive order we just discussed is essentially the policy response to exactly this class of threat.

Alex: Let's pivot to the APT28 campaign. Jordan, walk us through HOOKEDGE.

Jordan: So Recorded Future's Insikt Group attributed a campaign running from late September 2025 through April 2026 targeting government and diplomatic organizations in Romania, Spain, and Türkiye. The novel element is HOOKEDGE, a previously undocumented backdoor that is, interestingly, a lightweight Windows batch script. It's not a sophisticated compiled binary. It's a batch script. And that's the point. It's designed to be simple, to blend in, to avoid triggering the kinds of detection that more complex malware would.

Alex: APT28 has always been pragmatic about tooling. They use what works. And a batch script backdoor is going to fly under a lot of EDR solutions that are looking for compiled executables, DLL injection, the usual suspects. For CISOs with European operations, government contractor relationships, or diplomatic adjacency, the IOCs from the Insikt Group report should be in your threat intel platform today. But beyond the indicators, think about whether your detection logic would catch a weaponized batch script that's doing command and control.

Jordan: And the targeting of Romania, Spain, and Türkiye is geopolitically coherent. All three are NATO members. All three have been active in various dimensions of the Ukraine-related diplomatic and military landscape. This isn't opportunistic. This is targeted collection.

Alex: Let's stay geopolitical for a moment and talk about the DPRK remote worker expansion. This one is evolving fast.

Jordan: Huntress is now identifying suspected North Korean remote workers embedded in sales, marketing, and medical roles. Not IT. Sales and marketing. This is a significant expansion of the operational playbook. Previously, the guidance was focused on screening technical hires, looking for remote IT workers with fabricated identities. Now the attack surface is the entire remote workforce.

Alex: And here's what makes this so difficult. These individuals perform legitimate job duties. They do the work. They show up to meetings. They complete tasks. The revenue they generate goes back to Pyongyang, and in some cases they're positioned to access sensitive data, customer information, strategic plans. Traditional cybersecurity detection doesn't catch this because there's nothing to detect from a technical standpoint. This is a hiring and identity verification problem.

Jordan: Which means CISOs need to be in the room with HR leadership, with legal, with recruiting. Identity verification for remote hires needs to be significantly more rigorous, and it can't be limited to engineering and IT roles anymore.

Alex: Let's talk about the AI threat landscape. Two stories that are really two sides of the same coin.

Jordan: The first is concrete. Aurora ransomware operators are documented using Cursor Agent AI, the coding assistant, to conduct reconnaissance and exploitation tasks. This is a real-world case of a commercial AI tool being integrated into a ransomware kill chain. Not a proof of concept. Not a research paper. Actual criminal operations.

Alex: And the second story is the strategic framing. Over a hundred companies, including OpenAI, Anthropic, Google, and Microsoft, issued a collective warning that the window for effective defensive response to AI-enabled attacks is narrowing rapidly. When you see competitors setting aside their differences to issue a joint statement, that should tell you something about the severity of the assessment.

Jordan: For CISOs, the tactical takeaway from the Cursor story is that your AI governance policy needs teeth. Who has access to agentic AI tools in your environment? What are the acceptable use boundaries? Can those tools be used to interact with production systems? The strategic takeaway from the joint warning is that your board needs to understand that AI is not just a productivity story. It is an asymmetric force multiplier for attackers, and your defensive investment needs to reflect that.

Alex: Two breaches to cover. Jordan, the ATF hit first.

Jordan: Qilin ransomware claimed the ATF. The compromised system contained information on active investigation targets. That is an extraordinary intelligence win for a criminal group. ATF says it was a standalone system, didn't impact critical operations. Maybe. But the sensitivity of the data, the identities of people under federal investigation, that has real-world safety implications.

Alex: And for CISOs who work with law enforcement, who share threat intelligence, who have joint investigation relationships, this raises the question of what data you've shared and where it lives on their systems. The counterintelligence dimension here is not theoretical.

Jordan: Manchester Airports Group is the other breach. Unauthorized access to customer data across three UK airports, affecting millions of individuals. Transportation and travel remain persistent targets. Under UK GDPR, the notification and regulatory obligations here are significant.

Alex: If you're in the travel or transportation sector, or if your business involves handling passenger data, this is your reminder to pressure-test your incident response plan against a scenario exactly like this one.

Jordan: Let's hit the vulnerability stories quickly because both of them demand action today. ServiceNow disclosed three CVSS 10.0 vulnerabilities in the AI Platform. Code injection, SQL injection, privilege escalation, all exploitable by unauthenticated attackers. ServiceNow patched hosted instances automatically, but if you're self-hosted or partner-managed, you need to verify the patch manually. Today. Not Monday.

Alex: ServiceNow is the backbone of IT operations and security workflows in most large enterprises. A CVSS 10.0 in ServiceNow is not a hypothetical risk. It's a direct path to your crown jewels. Verify your patch status before you leave for the weekend.

Jordan: PaperCut is the other one. Attackers are actively chaining two vulnerabilities to achieve unauthenticated remote code execution across all versions of PaperCut NG and MF. The initial emergency patch was bypassed, so PaperCut had to release a second fix with additional hardening. There are confirmed customer incidents. If you run PaperCut, confirm you're on the second patch, not the first.

Alex: All right, let's step back for the outlook. Jordan, when you look at today's stories collectively, what's the thread?

Jordan: The thread is supply chain integrity, and I mean that broadly. Foreign components in power infrastructure, factory-implanted backdoors in routers, North Korean operatives embedded in your workforce through your hiring pipeline, AI tools built for productivity being co-opted for attack. Every one of these stories is about something entering your environment through a channel you thought was trusted.

Alex: I agree. And the policy response is accelerating. The executive order on power generation components, the joint industry warning on AI. The regulatory and policy environment is moving faster than most security programs are adapting. If you're heading into budget season, and many of you are, supply chain integrity and AI governance need to be top-line items. These aren't emerging risks anymore. They're present-tense operational realities.

Jordan: And the velocity of exploitation is compressing. ServiceNow patches three 10.0s, PaperCut's first emergency patch gets bypassed within the exploitation window. The time between disclosure and active exploitation is approaching zero in some cases. Your patch management SLAs need to reflect that reality.

Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, everyone. Stay sharp.

Jordan: See you Monday.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-28.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.