Cleartext – August 31, 2026
Monday, August 31, 2026·11:25
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – August 31, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 9 stories across 4 topic areas, including: China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs; DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims; North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales.
Stories Covered
🌍 Geopolitical
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
The Hacker News · Aug 31 · Relevance: █████████░ 9/10
Why it matters to CISOs: A Chinese espionage group is compromising Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts—core network infrastructure—in a campaign that actively blinds security logs, making detection and incident response extremely difficult. Any enterprise running Cisco IOS XR at the perimeter or in core routing should treat this as an active threat requiring immediate audit.
- Fire Ant (China-nexus) has expanded beyond VMware hypervisors to target Cisco IOS XR routers and TACACS authentication servers
- Attackers establish covert GRE tunnels not visible in running configs or commit history, enabling persistent, stealthy access
- The campaign targets credential theft and log blinding, undermining the integrity of authentication and monitoring infrastructure
DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
The Hacker News · Aug 31 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The DoJ's public correction distinguishing 'targeted' from 'victim' status for NASA, the Fed, DOE, and DoJ itself signals sensitivity around attribution and breach disclosure language—a nuance CISOs should track when managing their own regulatory notifications and public statements after incidents. It also confirms the breadth of Chinese targeting of critical U.S. institutions.
- DoJ issued a formal correction to prior statements: NASA, Federal Reserve, DOE, and DoJ were targeted by Chinese threat actors but not confirmed as victims
- The distinction between 'targeted' and 'compromised' carries significant legal and regulatory disclosure implications
- The correction follows a prior public statement that named these agencies as victims, highlighting risks of premature breach attribution
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
The Hacker News · Aug 31 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The DPRK IT worker insider threat scheme has materially broadened its target surface to healthcare and sales roles, meaning enterprises outside the technology sector can no longer treat this as someone else's problem—identity verification, contractor vetting, and HR-security collaboration must extend across all hiring functions.
- DPRK-linked threat actors are now placing fraudulent workers in healthcare and sales/marketing roles, not just IT
- The insider threat scheme enables DPRK to generate revenue and potentially exfiltrate sensitive data or plant access for future operations
- The expansion signals a maturation of the program and increased risk for any organization hiring remote contractors or employees globally
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails
Help Net Security · Aug 31 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Russia-aligned UAC-0099 is deliberately embedding prompts into malware to trigger AI safety filters and disrupt AI-assisted malware analysis pipelines—a novel adversarial technique that directly degrades the effectiveness of AI-augmented SOC tooling. CISOs deploying AI for threat detection must account for adversarial manipulation of those systems as part of their security architecture.
- UAC-0099 embeds 'nuclear weapon' prompts as comments in VBS malware scripts to trigger AI safety guardrails and block automated analysis
- ESET named the technique 'GuardBreaker'; the group has prior ties to Sandworm/GRU operations
- The tactic represents a deliberate effort to degrade AI-powered security tooling, not just evade human analysts
🔓 Data Breach
ShinyHunters claims it stole 284 million patient records from McKesson
Help Net Security · Aug 31 · Relevance: ██████████ 10/10
Why it matters to CISOs: A breach of this scale at a top-tier pharmaceutical distributor—284 million patient records claimed by ShinyHunters—sets an immediate benchmark for HIPAA exposure, third-party application risk, and supply chain vulnerability across every health system McKesson serves. CISOs in healthcare and adjacent sectors must assess their McKesson integrations and vendor risk posture now.
- ShinyHunters claims 284 million patient records stolen from McKesson via a third-party application compromise
- McKesson filed an SEC disclosure; incident detected August 25, 2026, investigation described as 'early stages'
- Company distributes pharmaceuticals and medical supplies to pharmacies, hospitals, and clinics across the U.S., amplifying downstream impact
Berlin confirms data theft after Rhysida ransomware attack claims
BleepingComputer · Aug 31 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A ransomware attack on Berlin's city government—with confirmed data theft and a public refusal to pay ransom—illustrates the reputational and operational calculus senior leaders face post-incident, and adds to a growing pattern of Rhysida targeting government entities that may signal wider public sector campaigns relevant to regulated industries.
- Rhysida ransomware gang listed Berlin's city administration on its data leak site; the city confirmed data theft
- Berlin's Governing Mayor publicly stated the city will not pay the ransom demand
- The breach was discovered in mid-August 2026, with extortion demand received subsequently
Anthropic locks out Claude users after infostealers hijack login sessions
Help Net Security · Aug 31 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Enterprise adoption of Claude and other AI coding/productivity tools creates a new credential theft surface: infostealer malware targeting developer endpoints can now compromise AI tool sessions with access to sensitive codebases, API keys, and business data. CISOs must extend endpoint protection and session management policies explicitly to AI tooling.
- Anthropic is locking accounts after infostealers including Vidar, LummaC2, StealC, RedLine, and Atomic Stealer compromised user login sessions
- Malware arrives via unofficial downloads or malicious apps on both Windows and macOS endpoints
- The incident underscores that AI productivity tools used in enterprise environments are now active targets for credential-harvesting campaigns
⚖️ Governance & Policy
The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
CyberScoop · Aug 31 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: The proposed AI Kill Switch Act would mandate government-controlled shutdown mechanisms for AI agents—a regulatory development that could force CISOs to redesign AI deployment architectures and governance frameworks to comply, while simultaneously introducing new attack surfaces if those mechanisms are exploited by adversaries.
- The AI Kill Switch Act would mandate remote shutdown capabilities for AI agents operating in the U.S.
- Critics draw parallels to the Clipper Chip debate, arguing mandated backdoors threaten critical infrastructure security and U.S. AI competitiveness
- Congress is actively considering the legislation, making this a near-term governance issue for enterprises deploying autonomous AI systems
🚨 Critical Vulnerability
Attackers plant remote access tools on compromised PaperCut servers
Help Net Security · Aug 31 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Active zero-day exploitation of PaperCut NG/MF print management servers—deployed broadly in enterprise and higher-ed environments—is escalating with attackers now installing persistent remote access tools, making this a live incident response priority for any organization running internet-facing PaperCut instances.
- PaperCut zero-days are being actively exploited as of August 27, 2026; vendor urged customers to restrict web access to trusted IPs immediately
- Attackers are covertly installing legitimate remote access software on compromised PaperCut Application Servers for persistent access
- Emergency patches have been issued; any unpatched internet-facing PaperCut NG or MF instance should be treated as potentially compromised
Further Reading
- 🌍 China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs — The Hacker News
- 🌍 DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims — The Hacker News
- 🌍 North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales — The Hacker News
- 🌍 Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails — Help Net Security
- 🔓 ShinyHunters claims it stole 284 million patient records from McKesson — Help Net Security
- 🔓 Berlin confirms data theft after Rhysida ransomware attack claims — BleepingComputer
- 🔓 Anthropic locks out Claude users after infostealers hijack login sessions — Help Net Security
- ⚖️ The AI Kill Switch Act is repeating the Clipper Chip’s mistakes — CyberScoop
- 🚨 Attackers plant remote access tools on compromised PaperCut servers — Help Net Security
Full Transcript
Click to expand full episode transcript
Alex: Welcome to Cleartext. It's Monday, August 31st, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Two hundred and eighty-four million patient records. That's the number ShinyHunters is claiming from the McKesson breach. If even a fraction of that holds up, we're looking at one of the largest healthcare data compromises in history, and it happened through a third-party application. We'll get into that. But first, we need to talk about what's happening inside your routers right now, because a Chinese espionage group just demonstrated they can hide inside Cisco IOS XR infrastructure in ways that don't show up in your running config. That's where we start.
Alex: Big show today. We've got the Fire Ant campaign hitting core network infrastructure, the DoJ walking back who was actually breached versus merely targeted by Chinese actors, North Korea's job fraud scheme spreading well beyond IT roles, Russian hackers deliberately poisoning AI analysis tools, the McKesson breach, Berlin getting hit by Rhysida, Anthropic locking out Claude users after infostealer compromises, a proposed AI kill switch law that should concern every CISO deploying autonomous systems, and active exploitation of PaperCut servers. Let's get into it.
Jordan: So Fire Ant. This is a China-nexus group that Sygnia has been tracking. They were previously known for going after VMware hypervisors, which was already alarming enough. Now they've expanded to Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. And Alex, the technique here is what makes this genuinely frightening. They're establishing covert GRE tunnels that do not appear in running configurations or commit history.
Alex: Let me make sure the audience absorbs that. Your network team runs show running-config, everything looks clean. They check commit history, nothing unusual. But there's an active tunnel exfiltrating data. That is a fundamental breakdown of the trust model that network operations teams rely on every single day.
Jordan: Exactly. And it gets worse. The campaign is specifically designed to blind security logs and steal credentials from TACACS servers. So they're not just hiding in the infrastructure, they're actively degrading your ability to detect them and stealing the keys to the kingdom simultaneously. TACACS is how you authenticate privileged access to network devices. If that's compromised, your entire network management plane is owned.
Alex: So what should CISOs do Monday morning? If you're running Cisco IOS XR at the perimeter or in core routing, this requires an immediate audit. And I don't mean running show commands from the CLI, because as we just discussed, those can't be trusted. You need out-of-band verification. You need to be looking at traffic flows for unexpected GRE tunnels. You need to audit your TACACS infrastructure independently. And frankly, you need to have a conversation with your network team about whether your current monitoring architecture can even detect this class of threat.
Jordan: The broader pattern here is that nation-state actors are increasingly living in network infrastructure, not endpoints. We saw this with Volt Typhoon in edge devices. Fire Ant in hypervisors and now routers. The adversary has figured out that your EDR doesn't run on a Cisco router.
Alex: And that connects directly to our second story. The Department of Justice issued a formal correction last Friday. They had previously stated that NASA, the Federal Reserve, the Department of Energy, and the DoJ itself were victims of Chinese cyber operations. They're now saying those agencies were targeted but not confirmed as compromised.
Jordan: That's a fascinating correction. And look, on the surface it might seem like bureaucratic hair-splitting, but the distinction between targeted and compromised carries enormous legal and regulatory weight. For CISOs listening, this is actually a masterclass in why precision matters in your own incident disclosures.
Alex: Absolutely. If you tell your board or your regulators that you were breached when you were actually targeted but not compromised, you've created liability where none existed. Conversely, if you downplay a confirmed compromise as merely being targeted, you're in a different kind of trouble. The DoJ just demonstrated how easily this can go wrong at the highest levels of government. Your legal counsel, your communications team, and your security team need to be aligned on this taxonomy before an incident, not during one.
Jordan: And let's not lose the forest for the trees. Whether these agencies were compromised or merely targeted, the scope of Chinese cyber operations against core U.S. government institutions is extraordinary. This is happening alongside Fire Ant, alongside the broader Volt Typhoon campaign. The strategic picture is consistent and it's aggressive.
Alex: Staying with nation-state threats, North Korea's IT worker fraud scheme has expanded significantly. Jordan, this one has been simmering for a while, but the expansion beyond IT roles is a material change.
Jordan: It is. We've been tracking DPRK's fake worker program for years now, and the conventional wisdom was that it was primarily an IT problem. Fake developers, fake engineers getting hired at tech companies. What we're seeing now is placement in healthcare roles and sales and marketing positions. That's a completely different risk surface.
Alex: And it means the mitigation can't live solely with IT hiring managers anymore. This has to be an enterprise-wide HR security initiative. Identity verification, contractor vetting, background check processes, all of it needs to extend to every function that hires remote workers. And I'd argue especially healthcare, where access to patient data and clinical systems creates both an espionage value and a revenue generation opportunity for the DPRK.
Jordan: The maturation of this program is impressive from a tradecraft perspective. They're not just generating revenue anymore. They're positioning for data access and potentially planting long-term access for future operations. Every CISO should be asking their head of HR this week: what is our verification process for remote hires, and does it account for this threat?
Alex: Now, Jordan, I want to pivot to something genuinely novel. Russian hackers are deliberately embedding prompts into malware to trip AI safety guardrails. Walk us through this.
Jordan: So ESET has identified a technique they're calling GuardBreaker, attributed to UAC-0099, which is a Russia-aligned group with ties to Sandworm and GRU operations. What they're doing is embedding strings like nuclear weapon construction prompts as comments inside VBS malware scripts. When an AI-powered analysis tool ingests that malware sample, the safety filter triggers and the AI refuses to analyze it. The malware effectively says to the AI, I'm too dangerous for you to look at, and the AI complies.
Alex: That is brilliant and terrifying in equal measure. We have spent the last two years telling boards that AI is going to transform our SOC operations, that it's going to accelerate threat detection and analysis. And now adversaries are specifically designing malware to exploit the safety mechanisms built into those AI tools.
Jordan: Right. And this isn't a theoretical concern. This is happening in production, in Ukraine, against real targets. If you're deploying AI-augmented analysis in your security operations, and most of the major vendors are now building this in, you need to understand that the adversary is already adapting. Your AI tools need adversarial robustness testing. The safety filters need to be tuned so that content within a malware sample doesn't trigger the same guardrails designed for user-generated prompts.
Alex: It's an architectural problem. You can't just bolt AI onto your analysis pipeline and assume it's additive. The AI itself is now an attack surface.
Jordan: Let's move to breaches. The McKesson story is the biggest thing on the board today, and maybe this quarter.
Alex: ShinyHunters is claiming 284 million patient records stolen from McKesson through a third-party application compromise. McKesson filed with the SEC. The intrusion was detected August 25th, so we're less than a week in. They describe the investigation as early stages.
Jordan: For context, McKesson distributes pharmaceuticals and medical supplies to pharmacies, hospitals, and clinics across the United States. The downstream exposure here is enormous. If you are a health system, a pharmacy chain, a clinic that works with McKesson, you need to be assessing your integration points right now. What data flows between your systems and theirs? What APIs are connected? What credentials are shared?
Alex: And the third-party application vector is the story within the story. This wasn't a direct compromise of McKesson's core infrastructure, at least based on what we know. It came through a third-party app. We keep having this conversation about vendor risk management, and we keep seeing it validated in the worst possible way. Two hundred and eighty-four million records. If that number holds, it dwarfs the Anthem breach, it dwarfs most of the healthcare breaches we've seen. The HIPAA exposure alone is staggering.
Jordan: Two other breaches worth noting quickly. Berlin's city government confirmed data theft following a Rhysida ransomware attack. The Governing Mayor publicly stated the city will not pay the ransom. That's a clear policy position, and it adds to the pattern of Rhysida targeting government entities specifically. If you're in the public sector or regulated industries that interact with government, this group is actively hunting.
Alex: And Anthropic locked out Claude users after infostealer malware, including Vidar, LummaC2, RedLine, and Atomic Stealer, compromised login sessions. This is the story I want every CISO to internalize. Your developers and knowledge workers are using Claude, ChatGPT, Copilot, and these tools have access to codebases, API keys, business data. If an infostealer grabs that session token, the attacker inherits all of that access. AI tools need to be in your credential management and endpoint protection scope explicitly. They're not nice-to-haves anymore. They're high-value targets.
Jordan: Two more items to cover quickly. The proposed AI Kill Switch Act would mandate government-controlled remote shutdown mechanisms for AI agents operating in the U.S. CyberScoop's op-ed draws a direct parallel to the Clipper Chip debacle of the nineties.
Alex: And it's an apt parallel. Mandating a kill switch is mandating a backdoor. It doesn't matter what you call it. If there's a mechanism to remotely shut down an AI agent, that mechanism can be discovered and exploited by adversaries. For CISOs deploying autonomous AI systems, this legislation, if it passes, would force significant architectural changes and simultaneously introduce new attack surfaces. Watch this one closely.
Jordan: And finally, PaperCut. Active zero-day exploitation of PaperCut NG and MF print management servers. Attackers are installing persistent remote access tools on compromised instances. Emergency patches are out as of August 27th. If you have internet-facing PaperCut, patch immediately or restrict web access to trusted IPs. If you haven't patched yet, assume compromise and investigate.
Alex: All right, let's wrap with what we're watching. Jordan, the through-line today is infrastructure trust. Fire Ant hiding in router configs you can't see. AI tools being weaponized against themselves. Third-party apps as the entry point for a potentially historic breach. The common thread is that the things we rely on to operate and to defend ourselves are being subverted at a foundational level.
Jordan: Agreed. And I'd add that the adversary sophistication we're seeing across all four major nation-state actors, China in network infrastructure, Russia in AI manipulation, North Korea in human operations, it's converging. They're all getting better at exploiting the gaps between our security domains. The router team doesn't talk to the SOC AI team. HR doesn't talk to threat intel. These seams are where the adversary lives now.
Alex: For this week, three actions. One, audit your Cisco IOS XR and TACACS infrastructure for Fire Ant indicators using out-of-band methods. Two, assess your McKesson integration points and third-party application exposure. Three, review your AI tooling, both your defensive AI pipeline for adversarial robustness and your enterprise AI tool access for credential theft exposure.
Jordan: It's going to be a busy week.
Alex: That's Cleartext for Monday, August 31st, 2026. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-31.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.