Cleartext logocleartext_
daily briefing

Cleartext – September 08, 2026

Tuesday, September 8, 2026·10:07

Cleartext – September 08, 2026
10:07·6.1 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – September 08, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack; OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor; Threat actors are giving AI agents a bigger role in cyberattacks.

Stories Covered

🌍 Geopolitical

French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack

The Record (Recorded Future) · Sep 08 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The arrest of a ZeroBytes member behind attacks on France's national tax authority, followed by France establishing a dedicated government cyber incident response unit, signals heightened European state-level response posture and raises the strategic profile of cyber threats to government financial infrastructure.

  • French prosecutors confirmed the arrest of an 18-year-old suspected ZeroBytes hacking group member in connection with cyberattacks on France's national tax authority
  • The attack prompted the French Prime Minister to establish a new dedicated government cyber incident response unit
  • ZeroBytes is linked to attacks on multiple French organizations, indicating a broader campaign against national critical infrastructure

📖 Read full article

📡 Macro Trends

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

BleepingComputer · Sep 08 · Relevance: █████████░ 9/10

Why it matters to CISOs: The first broadly deployed AI model classified at a 'Critical' cybersecurity capability level marks a strategic inflection point: adversaries now have access to a tool that autonomously discovers zero-days, while its reduced monitorability complicates both defensive use and governance.

  • OpenAI confirmed GPT-6 Astra is the first model it has broadly deployed reaching the 'Critical level' for cybersecurity capabilities
  • The model can autonomously identify zero-day vulnerabilities, lowering the bar for sophisticated offensive operations
  • GPT-6 Astra is described as harder to monitor, raising governance and misuse detection challenges for enterprise security programs

📖 Read full article

Threat actors are giving AI agents a bigger role in cyberattacks

Help Net Security · Sep 08 · Relevance: █████████░ 9/10

Why it matters to CISOs: Google's Q3 2026 AI Threat Tracker, backed by Mandiant IR data, documents attackers operationalizing multi-agent frameworks for end-to-end attack automation—a structural shift in threat velocity that demands CISO reassessment of detection timelines and incident response playbooks.

  • Google Threat Intelligence Group's Q3 2026 AI Threat Tracker documents attackers moving from basic AI prompts to multi-agent automated attack workflows
  • A Mandiant-investigated Q2 2026 incident saw a financially motivated group use autonomous AI agents to harvest credentials at scale within six hours
  • AI agents are now handling vulnerability scanning, credential harvesting, and attack troubleshooting with minimal human involvement

📖 Read full article

🔓 Data Breach

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

BleepingComputer · Sep 07 · Relevance: ████████░░ 8/10

Why it matters to CISOs: BigBear 2.0 demonstrates that MFA alone is insufficient against modern adversary-in-the-middle phishing infrastructure, with 258 enterprise organizations already compromised—a direct signal for CISOs to accelerate phishing-resistant MFA (FIDO2) adoption and review M365 conditional access policies.

  • BigBear 2.0 is a phishing-as-a-service platform that successfully bypassed MFA at 258 organizations and harvested over 5,000 Microsoft 365 credentials
  • The framework uses adversary-in-the-middle techniques to intercept session tokens, rendering standard TOTP and push-based MFA ineffective
  • The campaign specifically targets Microsoft 365, the dominant enterprise productivity suite, broadening the blast radius for affected organizations

📖 Read full article

IT help-desk vishing tricks executives into handing over Microsoft 365 access

Help Net Security · Sep 08 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The PREY-0058 campaign's targeting of executives via social engineering over voice channels—bypassing technical controls entirely—underscores the need for CISOs to harden executive help-desk authentication procedures and brief C-suite on this specific extortion tradecraft.

  • Arctic Wolf is tracking PREY-0058, a campaign using IT help-desk vishing calls to trick executives into surrendering Microsoft 365 access and session tokens
  • Attackers route sign-ins through residential proxies to evade geo-based anomaly detection, then conduct data theft and extortion
  • The group shares tradecraft with UNC6671 (tracked by Google), operating under aliases including BlackFile, Pink, and Helix—suggesting an organized, persistent threat actor

📖 Read full article

⚖️ Governance & Policy

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

The Hacker News · Sep 08 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A £26M settlement over unlawful sharing of special-category health data with ad-tech third parties is a landmark UK enforcement precedent that should prompt enterprise CISOs to audit third-party data flows involving sensitive personal attributes and revisit data processing agreements.

  • Grindr agreed to pay £26 million ($35.1M) to settle UK class action claims that it unlawfully shared users' HIV status and other sensitive data with advertising third parties
  • The lawsuit invoked UK privacy law protections on special-category personal data, establishing a significant private litigation precedent beyond regulatory fines
  • The case highlights liability exposure for organizations embedding ad-tech SDKs or analytics tools that access sensitive personal data fields

📖 Read full article

NCSC Warns Shadow AI Creates New Security Risks

Infosecurity Magazine · Sep 07 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: An NCSC advisory on shadow AI gives CISOs authoritative backing to formalize AI tool governance policies and asset discovery programs, particularly as unapproved AI adoption accelerates across business units outside security oversight.

  • The UK's NCSC has issued a formal warning that unapproved AI tools used by employees expose corporate data and create novel attack surfaces
  • Shadow AI mirrors earlier shadow IT risks but with amplified data exfiltration potential due to AI tools ingesting sensitive business context
  • The advisory implies regulatory and liability exposure for organizations that lack enforceable AI usage policies

📖 Read full article

🚨 Critical Vulnerability

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker News · Sep 08 · Relevance: █████████░ 9/10

Why it matters to CISOs: A CVSS 10.0 zero-day actively exploited since September 4 against all versions of Adobe Commerce and Magento Open Source—widely used enterprise e-commerce infrastructure—warrants immediate emergency patching and incident investigation for any organization running these platforms.

  • CVE-2026-75650 (CVSS 10.0), dubbed StyleSmuggler, affects all versions of Adobe Commerce and Magento Open Source
  • Active exploitation began September 4, 2026, deploying a Rust-based Linux backdoor and PHP web shell on compromised servers
  • Adobe released an emergency out-of-band patch; organizations should treat this as an emergency remediation priority

📖 Read full article

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

The Hacker News · Sep 08 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A zero-click worm propagating through WeChat calls—without any user interaction—represents a critical threat to enterprises with operations in China or employees using WeChat for business communications, warranting immediate review of mobile device management policies for this application.

  • Security firm Calif developed and demonstrated 'WeWorm,' a worm that hijacks WeChat accounts via incoming calls with zero user interaction required on iPhone and Android
  • The worm self-propagates through a victim's contact list, with researchers estimating potential reach of millions of devices within hours
  • The flaw was reported to Tencent in July 2026; Tencent has since patched the vulnerability, but enterprise exposure during the disclosure window requires assessment

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Jordan: OpenAI just told us GPT-6 Astra can find zero-days autonomously. And then, almost in the same breath, admitted it's harder to monitor. So we now have the first broadly deployed AI model rated at Critical cybersecurity capability, available to anyone with an API key. If that doesn't reframe your Wednesday board meeting, I don't know what will.

Alex: Welcome to Cleartext for Tuesday, September 8th, 2026. I'm Alex Chen, alongside Jordan Reeves. We have a dense show today. The AI threat landscape just shifted in two major ways, and we're going to spend real time on that. We've also got a CVSS 10.0 Magento zero-day being actively exploited in the wild, a phishing-as-a-service platform that just burned through 258 organizations' MFA, executives getting social-engineered over the phone, a landmark UK privacy settlement, and France standing up a new cyber response unit after arresting a teenage hacker. Let's get into it.

Jordan: So let's start with the two AI stories because they're really one story told from two angles. OpenAI's own safety evaluation confirmed that GPT-6 Astra, their latest broadly deployed model, has reached what they classify internally as the Critical level for cybersecurity capabilities. That means autonomous zero-day discovery. Not assisted. Not prompted with heavy guidance. Autonomous. And here's the kicker: the same architectural changes that made it more capable also made its reasoning chains less transparent. Harder to monitor, harder to audit, harder to build guardrails around.

Alex: And this isn't theoretical. Google's Q3 AI Threat Tracker, which dropped the same day, documents exactly what happens when these capabilities meet real threat actors. Mandiant investigated an incident from Q2 where a financially motivated group used autonomous AI agents to harvest credentials at scale across an enterprise environment in six hours. Six hours from initial access to bulk credential theft. That's not a human-speed operation anymore.

Jordan: Right, and the Google report makes a really important distinction. We've moved past the era of attackers using AI as a glorified autocomplete for phishing emails. What Mandiant is seeing now is multi-agent frameworks. Think of it as an attack team where each agent has a role: one scans for vulnerabilities, one handles credential harvesting, one troubleshoots when something fails. Minimal human involvement. The attacker sets the objective and the agents execute the kill chain.

Alex: So what does this mean practically for a CISO sitting in their chair right now? Two things. First, your detection timelines just compressed dramatically. If adversaries can execute an end-to-end attack workflow in hours with minimal human bottlenecks, your mean time to detect and mean time to respond have to match. If your SOC is still built around the assumption that attackers need days to move laterally, you're operating on obsolete assumptions.

Jordan: Second, and this is the governance angle that I think is actually harder: you now have a tool that your own red team wants to use, your developers want to experiment with, and your adversaries are already deploying. The NCSC advisory that came out this week on shadow AI isn't a coincidence. They're formally warning that unapproved AI tools used by employees create novel attack surfaces and data exfiltration paths. Shadow AI is shadow IT with a turbocharger. Every business unit experimenting with GPT-6 Astra or similar models outside your visibility is potentially feeding sensitive business context into systems you don't control.

Alex: And the NCSC advisory gives CISOs something they've needed: authoritative backing to formalize AI governance. If you've been trying to get budget or executive support for an AI tool discovery and policy program, print that advisory and bring it to your next leadership meeting. The regulatory and liability exposure for organizations without enforceable AI usage policies is real and growing.

Jordan: Let me pivot to something that needs immediate action. Adobe pushed an emergency out-of-band patch Monday for CVE-2026-75650, which the researchers at Sansec have codenamed StyleSmuggler. CVSS 10.0. Affects all versions of Adobe Commerce and Magento Open Source. Active exploitation started September 4th.

Alex: This is a drop-everything patch. Attackers are deploying a Rust-based Linux backdoor and a PHP web shell on compromised servers. If you're running any flavor of Adobe Commerce or Magento, you should already have your teams on this. And if you patched but didn't investigate whether you were compromised before the patch dropped, you're only half done. Four days of active exploitation means you need to assume breach and hunt.

Jordan: Agreed. The Rust-based backdoor is notable too. We're seeing more sophisticated post-exploitation tooling written in Rust specifically because it's harder for traditional EDR to signature and analyze. This isn't a script kiddie operation.

Alex: Alright, let's talk about the MFA problem, because we had two stories today that are really the same strategic lesson. BigBear 2.0 is a phishing-as-a-service platform that successfully bypassed MFA at 258 organizations and harvested over 5,000 Microsoft 365 credentials. It uses adversary-in-the-middle techniques to intercept session tokens in real time. Your TOTP codes, your push notifications, they're useless against this because the attacker is sitting between the user and Microsoft, proxying the entire authentication flow.

Jordan: And then separately, Arctic Wolf published on PREY-0058, a campaign where attackers are calling executives directly, impersonating IT help desk, and social engineering them into surrendering Microsoft 365 access and session tokens. They route sign-ins through residential proxies to evade geo-based anomaly detection, then pivot to data theft and extortion. This group shares tradecraft with UNC6671, tracked by Google under aliases including BlackFile, Pink, and Helix. This is organized, persistent, and specifically targeting C-suite.

Alex: So the lesson for CISOs: MFA as implemented at most organizations is no longer a reliable control against targeted attacks. I've been saying this for two years, but the data is now overwhelming. You need phishing-resistant MFA. That means FIDO2 security keys or passkeys. Period. If your Microsoft 365 deployment is still relying on TOTP or push-based MFA as your primary defense, you are in the blast radius of BigBear and every platform like it.

Jordan: And on the vishing side, this is a people-and-process problem. Your technical controls don't help when an executive picks up the phone and follows instructions from someone they believe is IT support. CISOs need to brief their C-suite directly on this specific tradecraft and harden help-desk authentication procedures. Callback verification, out-of-band identity confirmation, codeword protocols. It sounds old school because it is. But it works.

Alex: Let's shift to the Grindr settlement because it has broader implications than the headline suggests. Grindr agreed to pay 26 million pounds, about 35 million dollars, to settle UK class action claims that it unlawfully shared users' HIV status and other sensitive data with advertising third parties.

Jordan: This is a landmark private litigation precedent. Not a regulatory fine. A class action settlement. That distinction matters because it opens a second front of liability exposure. You can now face enforcement from regulators and class action suits from affected individuals, simultaneously.

Alex: The operational lesson for enterprise CISOs is about third-party data flows. Grindr's exposure came from ad-tech SDKs and analytics tools that had access to special-category personal data fields. How many of your applications embed third-party SDKs or analytics platforms that can access sensitive data? Health information, financial data, location, behavioral data? If you haven't audited those data flows recently, this settlement is your wake-up call. Review your data processing agreements. Map where sensitive attributes flow to third parties. Because the plaintiff's bar is watching this settlement very carefully.

Jordan: Quick hit on France. Prosecutors confirmed the arrest of an 18-year-old suspected ZeroBytes hacking group member behind cyberattacks on France's national tax authority. More significant than the arrest itself is the policy response. The French Prime Minister established a new dedicated government cyber incident response unit in direct response to this campaign. ZeroBytes has been linked to attacks on multiple French organizations, so this wasn't a one-off.

Alex: The signal here is that European governments are escalating their institutional response posture to cyber threats against financial infrastructure. If you operate in the EU, expect more assertive government engagement in incident response and more pressure on private sector organizations to cooperate and report.

Jordan: And one more before we look ahead. Researchers at the security firm Calif demonstrated a zero-click worm for WeChat. They call it WeWorm. It hijacks accounts via incoming calls with zero user interaction on both iPhone and Android. The worm self-propagates through a victim's contact list. Researchers estimated it could reach millions of devices within hours. Tencent patched after responsible disclosure in July, but if your organization has employees using WeChat for business communications, particularly those with operations in China, you need to verify that your mobile device management policies account for this application and that devices are updated.

Alex: Alright, looking ahead. Jordan, what's the thread that ties today together?

Jordan: Speed and autonomy. AI agents compressing attack timelines to hours. Phishing platforms industrializing MFA bypass at scale. Zero-click worms propagating without any human interaction on the victim side. The common thread is that the human is being removed from the attacker's kill chain. And that means our defenses can't depend on humans being in the loop either. Automated detection, automated response, phishing-resistant authentication that doesn't rely on user judgment. The organizations that are still built around the assumption that a human analyst will catch the alert, or a user will spot the phish, are going to have a very bad quarter.

Alex: I'd add the governance dimension. Between the NCSC shadow AI warning, the Grindr settlement on third-party data flows, and OpenAI essentially admitting their most capable model is harder to govern, we're entering a period where the CISO's hardest problems aren't technical. They're policy, liability, and organizational control. The attack surface isn't just your infrastructure anymore. It's every AI tool your employees adopt, every SDK your developers embed, every phone call your CEO answers. That's a fundamentally different risk management challenge.

Jordan: And it requires a fundamentally different conversation with the board.

Alex: That's our show for Tuesday, September 8th. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.

Jordan: I'm Jordan Reeves. Patch Magento today. We'll see you tomorrow.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-08.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.