Cleartext logocleartext_
daily briefing

Cleartext – September 03, 2026

Thursday, September 3, 2026·9:56

Cleartext – September 03, 2026
9:56·6.2 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – September 03, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: Srsly Risky Biz: China's botnets are worth disrupting; Pegasus, NoviSpy variant spyware found on devices of Serbian activists; Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke.

Stories Covered

🌍 Geopolitical

Srsly Risky Biz: China's botnets are worth disrupting

Risky Business News · Sep 03 · Relevance: █████████░ 9/10

Why it matters to CISOs: The Qilin ransomware group's apparent breach of the ATF's CALEA lawful intercept system is a critical development—compromise of lawful intercept infrastructure has direct implications for enterprise legal obligations and government coordination. The China botnet disruption signals ongoing threat actor adaptation that enterprise security teams must anticipate.

  • Qilin ransomware group may have stolen data from the ATF's CALEA lawful intercept system
  • US conducted a disruption operation against China-linked botnets, but China has used these private-sector-built networks for years and will rebuild
  • Discussion includes US water sector security limitations and the inadequacy of simply providing free tools

📖 Read full article

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

CyberScoop · Sep 02 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The first forensically confirmed Pegasus infection of 2026, combined with a new NoviSpy variant, signals that commercial spyware operators remain operationally active and are expanding targeting; CISOs at organizations with executives operating in politically sensitive regions should reassess mobile device threat models.

  • Citizen Lab confirmed a Pegasus zero-click iMessage exploit infected a Serbian student protest movement member's iPhone in 2026
  • A NoviSpy variant was also found on devices of Serbian activists, marking the largest wave of spyware surveillance in Serbia to date
  • The SHARE Foundation collaborated with Citizen Lab; this is the first forensically confirmed Pegasus infection of 2026

📖 Read full article

📡 Macro Trends

Stolen Claude session cookies can reach corporate Gmail through grants no IT admin can revoke

VentureBeat Security · Sep 02 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Session-cookie replay attacks on self-serve AI accounts bypass both SSO and 2FA, creating an enterprise blind spot where employees' personally billed AI subscriptions can be weaponized to access corporate Gmail and other corporate data through OAuth grants that IT cannot see or revoke.

  • Infostealers replayed stolen Claude session cookies to gain access to paid accounts without triggering 2FA or SSO controls
  • Affected accounts were self-serve, card-billed subscriptions outside corporate identity provider governance—meaning admins had no visibility or revocation capability
  • The sessions had OAuth grants allowing access to corporate Gmail and potentially other corporate resources with no admin-controllable off switch

📖 Read full article

🔓 Data Breach

Health data of more than 9.5 million people leaked from Aesto record system

The Record (Recorded Future) · Sep 02 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A breach affecting 9.5 million individuals' sensitive healthcare data—disclosed to federal regulators nine months after the December attack—raises significant HIPAA notification timeline and third-party vendor risk questions relevant to any enterprise with healthcare data or healthcare vendor relationships.

  • Healthcare data company Aesto reported the breach to federal regulators this week, roughly nine months after the December 2025 cyberattack
  • More than 9.5 million individuals had sensitive information leaked
  • Delayed disclosure timeline will draw regulatory scrutiny and sets a cautionary example for breach response planning

📖 Read full article

US and Canadian court data exposed in Thomson Reuters breach

The Record (Recorded Future) · Sep 03 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Thomson Reuters' breach of its C-Track court management platform—exposing sealed court records and sensitive personal data across at least 12 US states and Canada—underscores supply chain and SaaS vendor risk, especially for legal, compliance, and government-adjacent enterprises.

  • Breach affected C-Track, a court case management platform run by Thomson Reuters subsidiaries
  • Exposed data includes sealed court records and sensitive personal information across at least 12 US states, the US Virgin Islands, and Canada
  • Thomson Reuters published public disclosure and separate notification pages for US and Canadian affected individuals

📖 Read full article

FBI Probes Possible Breach of 153 Million Driver’s Licenses

Infosecurity Magazine · Sep 03 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A breach of this scale from a major ID verification service has direct implications for enterprises relying on third-party identity verification vendors—CISOs should immediately assess their KYC/identity verification vendor inventory and associated data sharing agreements.

  • Over 153 million driver's license scans are reportedly being sold on the dark web
  • The FBI is actively investigating the breach, which appears to have originated from a major ID card verification service
  • The crime site hosting the stolen data has since shut down, but exposure risk remains

📖 Read full article

🚀 Startup Ecosystem

HiddenLayer nabs $100M as enterprises rush to secure their AI deployments

TechCrunch Security · Sep 02 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: HiddenLayer's $100M raise reflects accelerating enterprise demand for AI security tooling focused on monitoring models, agents, and their integrations—CISOs evaluating AI security program gaps should track this market segment as a bellwether for where budget is flowing.

  • HiddenLayer raised $100M to expand AI security capabilities for enterprise deployments
  • The company focuses on monitoring AI agents, models, and the tools and plugins they connect to
  • The funding round signals strong investor and enterprise conviction that AI-specific security tooling is now a distinct and urgent category

📖 Read full article

🚨 Critical Vulnerability

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

Dark Reading · Sep 02 · Relevance: █████████░ 9/10

Why it matters to CISOs: Unauthenticated RCE on SonicWall edge appliances—confirmed in CISA's KEV catalog with a CVSS 10.0 SSRF flaw—demands immediate remediation action; SonicWall edge devices have been a persistent target this year and represent a perimeter exposure point at many enterprises.

  • CISA added CVE-2026-83548 (CVSS 10.0), an unauthenticated SSRF vulnerability in SonicWall SMA 1000, to its KEV catalog
  • The zero-days enable unauthenticated remote code execution on widely-deployed enterprise edge appliances
  • Exploitation follows earlier summer attacks on two other SonicWall edge device zero-days, indicating sustained threat actor focus on this platform

📖 Read full article

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

BleepingComputer · Sep 02 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Active exploitation of an authentication bypass in JFrog Artifactory—a core component of enterprise software supply chains—allowing admin token forgery represents a critical supply chain integrity risk for any organization using Artifactory to manage software artifacts.

  • CVE-2026-82329 is a critical authentication bypass vulnerability in JFrog Artifactory being actively exploited
  • Attackers can forge tokens granting full administrative access to the repository manager
  • JFrog Artifactory is widely used in enterprise DevSecOps pipelines, making compromise a potential software supply chain entry point

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Welcome to Cleartext. It's Thursday, September 3rd, 2026. I'm Alex Chen, alongside Jordan Reeves, and we have a packed show today. We're going to dig into China's botnet ecosystem and why disruption is necessary but insufficient, a lawful intercept system compromise that should make every CISO uncomfortable, the AI session cookie problem that's creating a shadow access layer your identity team can't touch, a trio of massive breaches including one that may have exposed 153 million driver's licenses, and critical zero-days in SonicWall and JFrog Artifactory that need your attention today. Jordan, let's get into it.

Jordan: So let's start with the big geopolitical picture. The US conducted a disruption operation this week against China-linked botnets, and look, that's good. But anyone who thinks this is a win needs to understand the structural reality here. China made a strategic decision years ago to outsource botnet construction to private companies. These aren't ad hoc operations. They're industrialized. The infrastructure will be rebuilt, probably within weeks. Tom Uren and James Wilson over at Risky Business laid this out well. The private sector supply chain feeding Chinese cyber espionage is mature and resilient.

Alex: And the takeaway for CISOs isn't just "China is persistent," which everyone already knows. It's that the nature of the infrastructure has changed. When botnets are built as a service by private contractors, they're more standardized, more scalable, and frankly more disposable. Your threat models need to account for adversary infrastructure that regenerates faster than you can update your blocklists. This is why behavioral detection and anomaly-based approaches at the network edge matter more than ever. You cannot play whack-a-mole with IP addresses when the other side has a factory producing new moles.

Jordan: Now buried in that same Risky Business discussion was something that honestly deserves its own episode. The Qilin ransomware group appears to have breached the ATF's CALEA lawful intercept system. Let that sink in. CALEA is the framework that enables court-authorized wiretapping across US telecommunications. If Qilin actually exfiltrated data from that system, we're talking about the compromise of one of the most sensitive law enforcement capabilities in the country.

Alex: This is a different category of breach. For CISOs, the immediate question is: what does this mean for your legal intercept obligations? If you're a telecom, an ISP, or any communications provider subject to CALEA, the integrity of those systems just became a board-level conversation. And even if you're not directly subject to CALEA, consider the second-order effects. If threat actors have visibility into how lawful intercept works, into the targets, the methods, the infrastructure, that changes the threat landscape for anyone cooperating with law enforcement on cybercrime investigations.

Jordan: It also raises a deeply uncomfortable question about whether ransomware groups are operating with state awareness or tolerance. Qilin has historically been linked to Russian-speaking actors. Hitting a US law enforcement intercept system is either extraordinarily reckless or extraordinarily deliberate. Neither interpretation is comforting.

Alex: Let's pivot to something that's going to be immediately actionable for a lot of our listeners. VentureBeat reported that stolen Claude session cookies are being used to access corporate Gmail through OAuth grants that no IT admin can revoke. And this is a problem that exists entirely in the gap between personal and corporate identity.

Jordan: Here's what's happening mechanically. An employee signs up for a personal Claude account, pays with their credit card. It's self-serve, completely outside your corporate identity provider. They grant that account OAuth access to their corporate Gmail, maybe to help draft emails, maybe to analyze threads. Now an infostealer grabs their session cookie. The attacker replays that cookie, never hits the login page, never triggers MFA, never touches SSO. They're in. And they have whatever OAuth scopes the employee granted, which can include full read access to corporate email.

Alex: And here's the part that should really concern you. Your admin console cannot see these sessions. You cannot revoke them. The account doesn't exist in your identity provider. This is shadow IT on steroids because it's not just an unsanctioned application, it's an unsanctioned identity with sanctioned access to your data. The remediation path here is not simple. You need to audit OAuth grants into your Google Workspace or Microsoft 365 environment, restrict which third-party applications can receive OAuth tokens from corporate accounts, and frankly, have a conversation with your workforce about the risk of connecting personal AI tools to corporate resources.

Jordan: And this is only going to get worse as AI tools proliferate. Every new agent, every new assistant that asks for email access or calendar access is a potential lateral movement path. The identity perimeter now extends to every SaaS tool your employees independently subscribe to.

Alex: Let's move to breaches, and we have three significant ones to cover. First, Aesto, a healthcare data company, finally disclosed to federal regulators this week that 9.5 million individuals had sensitive information leaked in an attack last December. That's a nine-month gap between incident and disclosure.

Jordan: Nine months. Under HIPAA, covered entities have 60 days from discovery to notify affected individuals. Now, Aesto may argue about when they confirmed the scope, but regulators are going to pick this apart. For CISOs in healthcare or anyone with healthcare vendor relationships, this is a case study in what not to do. Your incident response plan needs clear triggers for regulatory notification, and those triggers need to be decoupled from your forensic investigation timeline. You notify based on what you know, not based on having a complete picture.

Alex: Second breach: Thomson Reuters disclosed a compromise of its C-Track court case management platform. Sealed court records and sensitive personal data exposed across at least 12 US states, the US Virgin Islands, and Canada. This is a SaaS vendor risk story. Courts trusted Thomson Reuters with some of the most sensitive information in the judicial system, and that trust was violated. If you're in legal, compliance, or government-adjacent work, review what data you're sharing with Thomson Reuters platforms.

Jordan: And third, the FBI is investigating what could be the breach of the year. Over 153 million driver's license scans reportedly being sold on the dark web, apparently sourced from a major ID verification service. The crime forum hosting the data has since gone dark, but the exposure is already out there.

Alex: This one has cascading implications. If you're using a third-party identity verification vendor for KYC, for employee onboarding, for customer authentication, you need to understand right now what data those vendors hold, how long they retain it, and what their breach notification obligations are to you. 153 million driver's licenses is essentially half the US adult population. That's not a breach, that's a foundational identity crisis.

Jordan: And it renders driver's license-based identity verification substantially less trustworthy overnight. Any organization still relying on license scans as a primary verification factor needs to rethink that immediately.

Alex: Quick hit on the funding side. HiddenLayer raised $100 million to expand AI security capabilities. They focus on monitoring AI agents, models, and the tools and plugins those models connect to. This is a bellwether.

Jordan: The market is telling us that AI security is now a distinct budget category, not a line item under application security or data protection. If you're building out your AI security program, watch what HiddenLayer and its competitors are actually shipping. The problem space, monitoring agent behavior, detecting prompt injection, securing tool integrations, that's real and it's urgent. But the tooling is still maturing, so evaluate carefully.

Alex: Now let's talk about two vulnerabilities that need immediate attention. SonicWall SMA 1000 has a CVSS 10.0 SSRF vulnerability, CVE-2026-83548, now in CISA's Known Exploited Vulnerabilities catalog. It enables unauthenticated remote code execution. This follows attacks earlier this summer on two other SonicWall edge device zero-days.

Jordan: Three zero-days in one summer on the same vendor's edge platform. If you're still running SonicWall SMA appliances, you need to be patching today, not tomorrow, today. And honestly, if you're seeing this pattern of repeated zero-day exploitation on a specific vendor's edge devices, it's time to have the harder conversation about whether that vendor belongs in your architecture at all.

Alex: Second, JFrog Artifactory. CVE-2026-82329 is a critical authentication bypass being actively exploited in the wild. Attackers are forging admin tokens to gain full control of Artifactory instances. If you're using Artifactory in your DevSecOps pipeline, and most large enterprises are, a compromised instance means an attacker can tamper with every software artifact flowing through your build process.

Jordan: This is supply chain integrity at its most fundamental. Artifactory is the repository manager. It's where your binaries live. Admin access means an attacker can substitute, modify, or poison any artifact. Patch immediately, audit your access logs, and verify the integrity of any artifacts published since the vulnerability window opened.

Alex: Before we wrap, let's talk about the theme emerging this week. Jordan, I keep coming back to the same idea: the identity perimeter is fragmenting in ways we haven't fully internalized.

Jordan: Exactly right. You've got personal AI accounts with OAuth grants into corporate systems. You've got 153 million driver's licenses compromised, undermining document-based identity verification. You've got Artifactory tokens being forged, which is machine identity compromise. You've got CALEA intercept systems breached, which compromises the identity of surveillance targets. Every one of these stories is, at its core, about the failure of an identity assumption.

Alex: And the common thread for CISOs is that your identity surface area is much larger than what your IdP manages. It includes personal accounts your employees connect to corporate resources, it includes third-party vendors who hold identity documents, it includes machine identities in your CI/CD pipeline, and it includes government systems that intersect with your compliance obligations. If your identity strategy starts and ends with SSO and MFA, you have gaps that are being actively exploited right now.

Jordan: The adversaries understand this. They're not brute-forcing passwords. They're replaying cookies, forging tokens, and compromising the systems that identity depends on. The perimeter isn't the network anymore, and increasingly, it isn't even the identity provider. It's the trust relationships between systems, and those relationships are far more numerous and far less visible than most security programs account for.

Alex: Well said. That's our show for today. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow. Stay sharp.

Jordan: See you then.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-03.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.