Cleartext logocleartext_
daily briefing

Cleartext – September 01, 2026

Tuesday, September 1, 2026·10:51

Cleartext – September 01, 2026
10:51·6.7 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – September 01, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 5 topic areas, including: Chinese Fire Ant hackers turn Cisco routers into spying platforms; North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales; Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis.

Stories Covered

🌍 Geopolitical

Chinese Fire Ant hackers turn Cisco routers into spying platforms

BleepingComputer · Aug 31 · Relevance: █████████░ 9/10

Why it matters to CISOs: Chinese state-sponsored actors implanting covert GRE tunnels on Cisco IOS XR routers—invisible to running configs and commit history—demands immediate audit of enterprise network infrastructure for signs of persistent, configuration-hiding backdoors.

  • Fire Ant (Chinese APT) discovered using covert GRE tunnel interfaces on Cisco IOS XR routers
  • Malicious tunnel could not be identified through running configuration or commit history, indicating advanced persistence technique
  • Represents a new tactic of turning enterprise network backbone hardware into long-term espionage platforms

📖 Read full article

North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales

The Hacker News · Aug 31 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The expansion of North Korea's IT worker insider threat scheme into healthcare and sales roles dramatically widens the attack surface for enterprise HR and hiring processes, requiring CISOs to extend insider threat controls and identity verification beyond the IT department.

  • DPRK-linked threat actors now confirmed placing fraudulent workers in sales, marketing, and medical roles—not just IT
  • Ongoing insider threat scheme designed to generate revenue for North Korea and potentially exfiltrate sensitive data
  • Expansion signals maturation of the program and increased difficulty detecting placement through technical controls alone

📖 Read full article

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News · Sep 01 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The GuardBreaker technique—deliberately embedding content to trip LLM safety filters and blind AI-assisted malware analysis—signals that adversaries are now actively targeting AI-augmented SOC tooling, requiring CISOs to stress-test AI analysis pipelines against adversarial evasion.

  • Russia-aligned UAC-0099 embedded nuclear weapon prompts inside malware to intentionally trigger LLM safety mechanisms and disrupt AI-assisted analysis
  • Technique dubbed 'GuardBreaker' discovered by ESET targeting Ukrainian organizations
  • First documented instance of a nation-state actor weaponizing AI guardrails as a defensive evasion technique against security tooling

📖 Read full article

📡 Macro Trends

Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns

The Record (Recorded Future) · Sep 01 · Relevance: █████████░ 9/10

Why it matters to CISOs: The Financial Stability Board's warning to G20 banking leaders about frontier AI cyber risks signals imminent regulatory pressure on financial-sector CISOs to document AI risk scenarios and model concentration risk across shared technology dependencies.

  • FSB Chair Andrew Bailey called on financial institutions and technology providers to prepare for severe simultaneous disruption scenarios
  • Warning specifically highlights concentration risk from shared technology dependencies across multiple firms
  • Directed at G20 banking leaders, indicating coordinated international regulatory focus

📖 Read full article

🔓 Data Breach

Healthcare Giant McKesson Investigates Data Breach Incident

Infosecurity Magazine · Sep 01 · Relevance: █████████░ 9/10

Why it matters to CISOs: A claimed 284 million record theft from a major healthcare distributor by ShinyHunters triggers immediate downstream risk assessment for any organization with McKesson in its supply chain, as well as regulatory notification obligations across HHS/HIPAA and state breach laws.

  • ShinyHunters claims to have stolen 284 million records from McKesson
  • McKesson distributes medicines and medical devices to hospitals and healthcare practices across the U.S.
  • Company acknowledged the attack and expects intermittent service degradation

📖 Read full article

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

Help Net Security · Sep 01 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The Spring Ring campaign's successful use of spoofed IT support identities on Microsoft Teams to compromise employees at 10+ companies in multiple industries is a direct signal to review external tenant access policies, Teams security configurations, and helpdesk impersonation awareness training.

  • Palo Alto Unit 42 identified the Spring Ring campaign running January–April 2026, reaching 150+ employees across 10+ companies in multiple industries
  • Attackers registered external Microsoft Teams tenants mimicking internal IT department names to conduct vishing and deliver malware or gain remote access
  • Campaign exploits default Microsoft Teams configurations that allow external tenant communications with internal users

📖 Read full article

Berlin refuses to be blackmailed after network breach

Help Net Security · Sep 01 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Berlin's state government publicly refusing an extortion demand following a confirmed data theft from its administrative network provides a live case study in crisis communication and ransomware response posture relevant to any CISO advising leadership on ransom payment policy.

  • Berlin's state government confirmed a data theft from its administrative network in August, followed by an extortion demand attributed to Rhysida ransomware group
  • Governing Mayor Kai Wegner publicly declared Berlin will not pay, following an emergency Senate session
  • State Criminal Police engaged; incident demonstrates nation-state-tier attackers targeting critical government administrative infrastructure

📖 Read full article

⚖️ Governance & Policy

NIS2 compliance: Fixing IAM and access control before the 2026 audit

Help Net Security · Sep 01 · Relevance: ████████░░ 8/10

Why it matters to CISOs: With NIS2 enforcement deadlines arriving in October across multiple EU member states, CISOs at essential entities face fines up to €10 million for non-compliance, making IAM remediation an immediate board-level financial risk issue.

  • NIS2 enforcement deadlines arrive in October 2026 as member states move from transposition to active enforcement
  • Austria and Poland among countries with imminent implementation and registration deadlines
  • Non-compliance exposes essential entities to fines up to €10 million, covering IAM, supply chain, incident reporting, and board accountability obligations

📖 Read full article

Identity and permissions aren’t enough to govern AI agent behavior

VentureBeat Security · Aug 31 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: As enterprises deploy autonomous AI agents, existing IAM frameworks designed for human users fail to constrain agent behavior once access is granted—CISOs must architect layered execution governance, not just access controls, before autonomous agents proliferate across enterprise data environments.

  • Traditional identity and permissions controls govern what AI agents can reach, not how they behave autonomously once active
  • Autonomous agents can convert legitimate enterprise data access into unintended or harmful actions in seconds
  • Box CISO highlights need to scope agent permissions dynamically and layer execution controls above access controls

📖 Read full article

🚨 Critical Vulnerability

Hackers push malicious Virtualizor update in BGP hijacking attack

BleepingComputer · Sep 01 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A BGP hijack used to poison a software vendor's update infrastructure represents a supply chain attack vector that bypasses traditional endpoint controls—CISOs should validate software update integrity mechanisms and monitor for BGP anomalies affecting critical vendor infrastructure.

  • Attackers hijacked BGP routing for Virtualizor's update infrastructure, redirecting update requests to malicious servers
  • Malicious updates were delivered directly to users of the Virtualizor VPS management platform
  • Demonstrates that BGP-level manipulation is now being weaponized for software supply chain attacks against enterprise tooling

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Good morning. It's Tuesday, September 1st, 2026. This is Cleartext. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Jordan: So here's the thing that should ruin your Tuesday morning coffee. Chinese state-sponsored hackers—a group researchers are calling Fire Ant—have figured out how to implant covert GRE tunnels on Cisco IOS XR routers that are completely invisible to the running configuration and the commit history. You read that right. You could stare at your router config all day and never see it. Your network backbone is potentially a long-term espionage platform and you wouldn't know.

Alex: That is exactly the kind of finding that should trigger an emergency conversation between every CISO running Cisco IOS XR and their network engineering teams today. Not tomorrow. Today. Let me set up what we're covering this morning because it's a dense news day. We've got the Fire Ant Cisco implant, North Korea's worker fraud scheme expanding way beyond IT roles, a genuinely novel AI evasion technique from a Russian-aligned group, a major FSB warning to global finance, a potential 284-million-record healthcare breach, a Teams vishing campaign you need to know about, Berlin refusing to pay ransomware, NIS2 deadlines bearing down, AI agent governance gaps, and a BGP hijack weaponized against software updates. Let's move.

Jordan: Back to Fire Ant. What makes this different from prior router compromises—and there have been many—is the persistence mechanism. Previous campaigns against network infrastructure, like the Volt Typhoon activity, relied on techniques that were at least theoretically discoverable through config review or forensic analysis. This is a step function. The GRE tunnel interface exists on the device but leaves no trace in the running configuration or the commit history. That's not just clever tradecraft, that's purpose-built capability against the way network teams actually operate.

Alex: And that's the business problem. Network teams validate state through config. If the config lies to you—or more precisely, omits the truth—your entire assurance model for network integrity breaks down. The action item here is clear: you need to go beyond config review. Talk to Cisco TAC, get guidance on out-of-band verification methods for IOS XR, and frankly, start thinking about whether your network monitoring would even detect anomalous GRE traffic flows. Because if Fire Ant is tunneling data out through your own routers, your perimeter controls are irrelevant.

Jordan: And the targeting logic is obvious. IOS XR sits in service provider and large enterprise backbone environments. These are the routers that move serious traffic. You compromise one of these, you're not just getting access to a single network, you're potentially positioning yourself to intercept traffic across entire regions or sectors. This is signals intelligence infrastructure being built inside commercial networks.

Alex: Let's stay in the nation-state threat space because the North Korea story connects thematically, even though the vector is completely different. The DPRK IT worker scheme—we've been tracking this for years now—has officially expanded beyond IT roles. Researchers have confirmed fraudulent North Korean operatives placed in sales, marketing, and medical positions.

Jordan: This is the maturation phase everyone predicted but few prepared for. The original scheme was elegant in its simplicity: place IT workers remotely, generate revenue, occasionally exfiltrate data. But it was containable because the hiring pipeline for IT roles could be hardened with technical verification, code tests, identity checks. Now they're in healthcare and sales. How do you technically verify a sales candidate's identity in the same way? The control framework is completely different.

Alex: This is a board-level conversation about insider threat program scope. Most insider threat programs are implicitly designed around IT and privileged access users. If your threat model doesn't account for a fraudulently placed sales representative with access to your CRM, your customer data, your pricing strategy—you have a gap. CISOs need to be partnering with HR and legal to extend identity verification across all remote hiring, not just technical roles.

Jordan: And let's be honest about the scale. This isn't a handful of operatives. The U.S. government has been saying for over a year that thousands of DPRK workers are embedded in companies globally. The expansion into non-technical roles means that number is growing, and the detection difficulty is increasing.

Alex: Let's pivot to something genuinely new. Jordan, the GuardBreaker technique.

Jordan: This one is fascinating and frankly a little unsettling if you've invested heavily in AI-augmented security operations. UAC-0099, a Russia-aligned group targeting Ukrainian organizations, deliberately embedded nuclear weapon-related content strings inside their malware. Not because the malware has anything to do with nuclear weapons—but because those strings trigger the safety guardrails in large language models. If your SOC is using an LLM to assist with malware analysis, the model refuses to analyze the sample because it thinks it's being asked about weapons of mass destruction.

Alex: So the adversary is weaponizing your AI tool's safety features against you. That's adversarial AI in a way most people weren't thinking about. Everyone's been worried about prompt injection and data poisoning. This is simpler and arguably more effective: just make the AI refuse to do its job.

Jordan: ESET is calling it the first documented instance of a nation-state actor doing this deliberately. But I guarantee it won't be the last. Every threat actor watching this will realize they can blind AI analysis pipelines with a few well-placed strings. CISOs who have deployed LLM-assisted analysis—and that's a growing number—need to stress-test those pipelines against this exact technique. Can your AI tooling handle adversarial content designed to trip safety filters? If you don't know, find out this week.

Alex: That connects directly to the broader AI governance conversation. The Financial Stability Board—chaired by Andrew Bailey—just issued a warning to G20 banking leaders that cyber risk from frontier AI is the most immediate concern to global financial system stability. That's not a think tank saying this. That's the FSB chair speaking to the people who regulate the world's largest banks.

Jordan: The specific language around concentration risk is what matters here. Bailey called out shared technology dependencies across multiple firms and told institutions to prepare for severe simultaneous disruption scenarios. Read between the lines: they're worried about what happens when a widely shared AI platform or cloud dependency fails or is compromised across the financial sector simultaneously.

Alex: For financial sector CISOs, this is a signal flare. Regulatory pressure is coming. You will be asked to document your AI risk scenarios, your concentration dependencies, your third-party AI provider risk assessments. If you don't have that work underway, you're behind. And this connects to the AI agent governance piece from VentureBeat—the Box CISO made the point that traditional IAM controls govern what an AI agent can access, but not how it behaves once it's active. Autonomous agents can convert legitimate data access into unintended actions in seconds. Access control is necessary but insufficient. You need execution governance layered on top.

Jordan: Which is a hard architectural problem that most enterprises haven't even started scoping.

Alex: Let's move to the McKesson breach. ShinyHunters claims 284 million records stolen from one of the largest healthcare distributors in the United States. McKesson has acknowledged the attack and warned of intermittent service degradation.

Jordan: ShinyHunters has a track record of legitimate claims. They're not typically bluffers. If this number holds up, we're talking about one of the largest healthcare data compromises in history. McKesson distributes medicines and devices to hospitals and practices across the country—the downstream exposure is enormous.

Alex: If McKesson is anywhere in your supply chain—and if you're in healthcare, there's a good chance it is—you need to be running your downstream risk assessment right now. HIPAA notification obligations, state breach notification laws, potential exposure of patient data, operational data, supply chain data. This is a multi-month regulatory and legal process that starts today.

Jordan: The Spring Ring vishing campaign is worth sixty seconds of everyone's attention. Unit 42 documented a campaign running January through April this year where attackers registered external Microsoft Teams tenants designed to look like internal IT support, then used those to vish employees into installing malware or granting remote access. Over 150 employees targeted across more than ten companies in multiple industries.

Alex: The fix is straightforward but often overlooked: review your external tenant access policies in Teams. The default configuration allows external tenants to communicate with your internal users. If you haven't restricted that, do it. And reinforce your helpdesk impersonation training because this attack vector preys on the trust employees place in internal communications platforms.

Jordan: Quick hit on Berlin. The city's state government got hit by Rhysida, confirmed data theft from administrative networks, and Governing Mayor Wegner went public saying Berlin will not pay. Full stop. Emergency Senate session, state criminal police engaged.

Alex: Good case study in crisis communication and institutional resolve. Berlin is doing what we advise boards to prepare for: have the ransom payment policy decided before the incident, not during it. The public refusal to pay is a posture decision that should be made in peacetime.

Jordan: The Virtualizor BGP hijack is the last technical item and it's important. Attackers hijacked BGP routing for Virtualizor's update infrastructure, redirecting update requests to malicious servers that delivered compromised updates directly to users. This is a supply chain attack that bypasses everything you'd normally rely on at the endpoint level.

Alex: BGP-level manipulation for supply chain compromise is not new conceptually, but seeing it weaponized against a specific vendor's update infrastructure is a reminder that software update integrity cannot rely solely on TLS and code signing. You need to be monitoring for BGP anomalies affecting your critical vendors and validating that your update verification mechanisms would actually catch a redirected, malicious payload.

Jordan: And finally, NIS2. October enforcement deadlines are arriving across EU member states. Austria, Poland, and others are moving from transposition to active enforcement. Essential entities face fines up to ten million euros for non-compliance across IAM, supply chain risk management, incident reporting, and board-level accountability.

Alex: If you're an essential entity under NIS2 and your IAM remediation isn't complete, this is now a board-level financial risk conversation. Ten million euros in potential fines focuses the mind.

Jordan: So stepping back, the theme this week is the expansion of attack surfaces into domains that security teams historically haven't owned. Network backbone infrastructure with invisible implants. HR and hiring pipelines infiltrated by nation-state operatives. AI analysis tools blinded by adversarial content. BGP routing exploited for supply chain compromise. The perimeter of what a CISO is responsible for keeps expanding.

Alex: And the governance frameworks haven't kept pace. NIS2 is trying. The FSB warning is trying. But the gap between where adversaries are operating and where our controls are deployed is widening, not narrowing. The CISOs who will navigate this well are the ones building cross-functional partnerships—with network engineering, with HR, with legal, with the board—because none of these problems are solvable within the security team alone.

Jordan: Agreed. Watch for more GuardBreaker-style techniques. Once adversaries realize they can weaponize AI safety features, that playbook will proliferate fast. Test your AI tooling now.

Alex: That's our show for today. Show notes, links to every story we covered, and our analysis are at cleartext.fm. We'll be back tomorrow. Stay sharp.

Jordan: See you then.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-01.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.