Cleartext logocleartext_
daily briefing

Cleartext – September 04, 2026

Friday, September 4, 2026·9:40

Cleartext – September 04, 2026
9:40·5.9 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – September 04, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone; GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests; AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours.

Stories Covered

🌍 Geopolitical

Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone

Infosecurity Magazine · Sep 03 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A confirmed new Pegasus iMessage zero-click exploit against a civilian in Serbia signals that NSO Group capabilities remain operational and are being deployed by government clients—CISOs at organizations with journalists, activists, executives, or government-adjacent personnel on executive protection programs should reassess mobile device threat models.

  • Pegasus spyware deployed via iMessage zero-click exploit against a Serbian student activist's iPhone
  • Incident is part of a broader reported spyware wave targeting Serbia, indicating active government-client use of NSO Group tools
  • Zero-click delivery requires no user interaction, making traditional phishing awareness training irrelevant as a control

📖 Read full article

📡 Macro Trends

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

The Hacker News · Sep 04 · Relevance: ████████░░ 8/10

Why it matters to CISOs: GPT-6 Astra achieving perfect scores on exploit benchmarking—while being classified at OpenAI's 'Critical' cybersecurity capability threshold—materially changes the attacker capability baseline CISOs must plan against and reinforces urgency around AI-assisted threat modeling and red team assumptions.

  • OpenAI's GPT-6 Astra scored 100% on ExploitBench, an AI cybersecurity capability benchmark
  • OpenAI has classified Astra as reaching the 'Critical' cybersecurity capability threshold under its Preparedness Framework
  • OpenAI is blocking PoC exploit generation requests, but the capability gap between defenders and attackers using such models is now formally documented

📖 Read full article

AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours

Dark Reading · Sep 03 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Documented evidence that frontier AI agents compressed a multi-week attack lifecycle to under 10 hours forces CISOs to fundamentally reassess detection and response SLAs—mean time to detect measured in days is no longer adequate when breach-to-exfiltration can occur in a single business day.

  • Frontier AI agents demonstrated ability to execute a coordinated large-scale breach in approximately 10 hours versus the typical 2-week timeline
  • AI-assisted attack coordination compressed reconnaissance, lateral movement, and exfiltration phases simultaneously
  • Research finding directly challenges existing incident response playbook assumptions about dwell time and detection windows

📖 Read full article

🔓 Data Breach

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News · Sep 03 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A breach of court case management software spanning 11 U.S. states and Canada—potentially exposing SSNs and sealed judicial records—raises third-party vendor risk and data classification obligations for any enterprise relying on Thomson Reuters legal platforms. The 3-month detection gap (March discovery, June 30 disclosure) also signals supply-chain due diligence concerns.

  • Unauthorized party accessed C-Track court case management files in March 2026; discovered June 30, 2026
  • Affects courts in 11 U.S. states, U.S. Virgin Islands, and Ontario, Canada
  • Exposed records may include SSNs and sealed court data from West Publishing Corporation

📖 Read full article

Large Enterprises Targeted in Fake Merger & Acquisition Scams

Dark Reading · Sep 03 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The 'Phantom Deal' campaign demonstrates sophisticated social engineering targeting mid-level finance and legal employees during M&A activity—a period of elevated insider risk and third-party data sharing—requiring CISOs to coordinate with corporate development and legal teams on security protocols around transaction activity.

  • Threat actors in 'Phantom Deal' campaign conduct deep company research to impersonate legitimate M&A counterparties
  • Attacks target mid-level employees to initiate large unauthorized financial transfers under cover of deal activity
  • Large enterprises specifically selected as targets, exploiting the complexity and confidentiality norms of M&A processes

📖 Read full article

⚖️ Governance & Policy

G7 urges organizations to prepare for quantum cyber threats

The Record (Recorded Future) · Sep 04 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A joint G7 and CISA advisory explicitly calling out that quantum codebreaking is no longer theoretical elevates post-quantum cryptography migration from a long-term roadmap item to a near-term board-level risk discussion and regulatory compliance consideration for CISOs in financial services, critical infrastructure, and government-adjacent sectors.

  • G7 Cyber Security Working Group and CISA issued joint advisory urging immediate transition to post-quantum cryptography
  • Nations warn that quantum codebreaking can no longer be treated as a distant or theoretical threat
  • Governments are called on to launch dedicated national post-quantum encryption transition strategies

📖 Read full article

🚨 Critical Vulnerability

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

BleepingComputer · Sep 04 · Relevance: █████████░ 9/10

Why it matters to CISOs: A publicly released privilege escalation zero-day in CrowdStrike Falcon—one of the most widely deployed enterprise EDR platforms—is a critical operational emergency: attackers can exploit the very tool organizations rely on for endpoint protection to gain SYSTEM-level access on up-to-date Windows systems.

  • Zero-day exploit 'FalconFlank' released publicly by anonymous researcher 'Nightmare Eclipse'
  • Allows privilege escalation to SYSTEM on fully patched Windows systems running CrowdStrike Falcon
  • No vendor patch confirmed at time of publication; enterprises should monitor CrowdStrike advisories immediately

📖 Read full article

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News · Sep 03 · Relevance: █████████░ 9/10

Why it matters to CISOs: A CVSS 9.8 unauthenticated RCE vulnerability in Cisco Nexus 9000 switches—backbone infrastructure in most large enterprise data centers—demands immediate patching prioritization and network segmentation review, particularly given co-disclosed IOS XR flaws with no available workarounds.

  • CVE-2026-20212 (CVSS 9.8) affects 10 Silicon One-based Nexus 9000 series switches; unauthenticated remote code execution as root
  • Simultaneous IOS XR hardening release bundles 7 CVEs, two rated 9.8, with no workaround available for any IOS XR version
  • Patches are available; organizations should treat this as emergency remediation given the network infrastructure scope

📖 Read full article

Attackers exploit zero-days in consistently besieged SonicWall product

CyberScoop · Sep 03 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Active exploitation of new zero-days in SonicWall SMA1000—a product with five actively exploited vulnerabilities since late 2025 and a recent ransomware wave—makes this an urgent network access control risk for enterprises still running these appliances on their perimeters.

  • New zero-days in SonicWall SMA1000 appliances are actively being exploited in the wild
  • SMA1000 has suffered five actively exploited vulnerabilities since late 2025, following a ransomware attack wave
  • SonicWall is urging immediate patching of chained vulnerabilities with no confirmed workaround

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Welcome to Cleartext. It's Friday, September 4th, 2026. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Alex: We have a packed show today. A zero-day in CrowdStrike Falcon that's already public with no patch. A critical Cisco Nexus flaw that's a 9.8. GPT-6 Astra just scored a perfect 100 on exploit benchmarking. The G7 is telling everyone to stop treating quantum as theoretical. Thomson Reuters had a court software breach that sat undetected for three months. And SonicWall is getting exploited again. Jordan, where do you want to start?

Jordan: We have to start with FalconFlank. An anonymous researcher calling themselves Nightmare Eclipse dropped a zero-day exploit for CrowdStrike Falcon. Full privilege escalation to SYSTEM on fully patched Windows. No vendor patch at time of publication. Let that sink in. The tool you deployed to protect your endpoints is now a privilege escalation vector.

Alex: This is the nightmare scenario for EDR-dependent architectures. And let's be honest, that's most of us. CrowdStrike is in what, a quarter of enterprise environments? More? If you're running Falcon, you need to be on CrowdStrike's advisory channels right now, today, checking for emergency guidance. The question every CISO is going to get from their board after last year's outage and now this is: what's our contingency if our primary security tool becomes the attack surface?

Jordan: And that's the right question. This isn't about dumping CrowdStrike. Every EDR vendor will have its day. This is about whether your security architecture has single points of failure. If an attacker lands on a box running Falcon and can escalate to SYSTEM through Falcon itself, your detection layer and your vulnerability are the same thing. That's an architectural problem, not a vendor problem.

Alex: Practically speaking, monitor CrowdStrike's channels for a patch. Review your privilege boundaries. Make sure you have compensating controls that don't depend on the EDR agent. And if you have a red team, point them at this immediately so you understand your actual exposure.

Jordan: While we're in emergency patching mode, let's talk Cisco. CVE-2026-20212, CVSS 9.8, unauthenticated remote code execution as root on Nexus 9000 switches. These are data center backbone infrastructure. Ten Silicon One-based models affected. And Cisco simultaneously dropped an IOS XR hardening release bundling seven CVEs, two of them also 9.8, with no workaround available.

Alex: If you're running Nexus 9000 in your data center fabric, this is an emergency change window conversation today. Not Monday. The unauthenticated remote root access piece means there's no complexity barrier for an attacker who can reach the management plane. And I want to underscore: the IOS XR flaws have no workaround. Patching is your only option.

Jordan: And then there's SonicWall. New zero-days in SMA1000 appliances, actively exploited in the wild. This product has had five actively exploited vulnerabilities since late 2025. There was a ransomware wave tied to it. At this point, if you're still running SMA1000 on your perimeter, the conversation isn't about patching. It's about replacement.

Alex: I agree. There's a point where the vulnerability cadence on a product exceeds your ability to manage the risk through patching alone. SonicWall SMA1000 has crossed that line. If you're presenting this to leadership, frame it as total cost of ownership including incident response risk, not just appliance replacement cost.

Jordan: Now let's shift to the stories that should be reshaping your threat models more broadly. GPT-6 Astra scored 100 percent on ExploitBench. OpenAI itself classified the model at their Critical cybersecurity capability threshold under the Preparedness Framework.

Alex: Let's be precise about what this means operationally. OpenAI is blocking proof-of-concept exploit generation requests. Fine. But the capability exists. It's been measured. It's been documented. And if it exists in Astra, it exists or will exist in open-weight models that don't have guardrails. The attacker capability baseline just moved.

Jordan: The companion story from Dark Reading puts numbers on it. Frontier AI agents compressed a two-week attack lifecycle down to ten hours. Recon, lateral movement, exfiltration, running in parallel, coordinated by an AI agent. That's not a theoretical exercise. That's a documented research finding.

Alex: So here's the board-level implication. If your mean time to detect is measured in days, and your mean time to respond adds more days on top of that, you are operating on a timeline that assumes a human adversary. An AI-assisted adversary can complete an entire kill chain in a single business day. Your detection and response SLAs need to be re-benchmarked against that reality.

Jordan: And honestly, this isn't just about buying faster tools. It's about whether your SOC architecture can even process alerts at that speed. If your tier-one analysts are triaging in four-hour cycles, an AI-coordinated attack has already exfiltrated before the first analyst looks at the first alert.

Alex: This is where AI-assisted defense becomes not a nice-to-have but a structural requirement. You need automated triage, automated containment triggers, and pre-authorized response playbooks that can execute at machine speed. The human-in-the-loop model needs to shift to human-on-the-loop.

Jordan: Let's pivot to Pegasus. A confirmed new iMessage zero-click exploit deployed against a Serbian student activist. This is part of a broader spyware wave targeting Serbia, which tells us NSO Group's government clients are actively deploying current capabilities.

Alex: For CISOs, the immediate question is: do you have people in your organization who would be targets? Journalists, executives with government relationships, board members, anyone involved in geopolitically sensitive work. Zero-click means no user interaction required. Phishing training is irrelevant. Your mobile device threat model needs to account for this class of attack.

Jordan: The control set here is narrow. Apple's Lockdown Mode is the primary mitigation. Mobile device management alone won't stop this. And if you have executives traveling to certain regions or engaging with certain governments, you should be considering burner devices and compartmentalized communications. This isn't paranoia. This is operational security for the threat environment that actually exists.

Alex: And for organizations with executive protection programs, this needs to be integrated into that framework. Physical security teams and cyber teams need to be coordinating on mobile device posture for protected individuals.

Jordan: The Thomson Reuters breach is a different kind of problem but equally important. C-Track, their court case management platform, was compromised in March. They discovered it June 30th. That's a three-month detection gap. Eleven U.S. states, the Virgin Islands, Ontario. Exposed data potentially includes Social Security numbers and sealed court records.

Alex: Sealed court records. Think about what that means. Witness protection information. Juvenile records. Sealed settlements. The sensitivity classification of that data is extraordinary. And the three-month dwell time is the supply chain due diligence story. If you're a Thomson Reuters customer for legal platforms, what questions did you ask about their security posture in your last vendor review? What contractual notification obligations do you have?

Jordan: This is also a reminder that data classification isn't just an internal exercise. When your vendors hold data on your behalf, their classification failures become your liability. Especially in regulated sectors.

Alex: The Phantom Deal campaign is worth flagging quickly. Threat actors are conducting deep research on companies to impersonate legitimate M&A counterparties. They're targeting mid-level finance and legal staff to initiate large unauthorized transfers during active deal activity.

Jordan: The brilliance of this is the social engineering leverage. During an M&A, everything is confidential. People are told not to discuss transactions broadly. So when someone in finance gets a request that says don't share this with your normal approval chain, it feels consistent with how deals actually work.

Alex: CISOs need to coordinate with corporate development and general counsel. If your company is in an active transaction, your security protocols for financial authorization need to be tightened, not loosened. Extra verification steps. Out-of-band confirmation for any transfer above threshold. And awareness training specifically tailored to deal teams, not generic phishing training.

Jordan: Last major story. The G7 Cyber Security Working Group and CISA issued a joint advisory saying organizations should begin transitioning to post-quantum cryptography now. Not eventually. Now.

Alex: This is significant because it moves PQC from a technology roadmap item to a regulatory expectation. When the G7 collectively tells you something is no longer theoretical, that becomes the standard of care. If you haven't started your cryptographic inventory, you're behind. If you're in financial services or critical infrastructure, this is going to show up in examinations.

Jordan: The harvest-now-decrypt-later threat is the driver. Nation-states are collecting encrypted data today with the expectation of decrypting it when quantum capability arrives. If your data has a shelf life measured in years, the migration timeline matters right now.

Alex: Alright, looking at the week as a whole. Jordan, what's the thread?

Jordan: The thread is that the assumptions underlying most security programs are being invalidated simultaneously. Your EDR can be the vulnerability. Your attack timeline assumptions are too slow by an order of magnitude. Your perimeter appliances are getting exploited faster than you can patch. AI is both the accelerant and, potentially, the only viable response. The organizations that are going to navigate this are the ones willing to question their own architectural assumptions rather than just bolting on more tools.

Alex: I'd add that the governance stories this week, the G7 advisory, the Thomson Reuters breach timeline, tell us that regulators and governments are setting new expectations for what constitutes reasonable security. The standard of care is moving. If your program is built for 2024's threat landscape, you're already out of compliance with where the world is heading. Have those conversations with your boards now, not after the next incident.

Jordan: And patch your Cisco switches. Today.

Alex: That's our show for Friday, September 4th. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, everyone. Stay sharp.

Jordan: See you Monday.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-04.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.