Cleartext logocleartext_
daily briefing

Cleartext – September 11, 2026

Friday, September 11, 2026·9:23

Cleartext – September 11, 2026
9:23·5.7 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – September 11, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: AI lets small actors run state-level hacking campaigns, Anthropic report finds; Governments ‘buying time’ in race between innovation, security, national cyber director says; AI agents exploited PaperCut flaws to breach 395 organizations.

Stories Covered

🌍 Geopolitical

AI lets small actors run state-level hacking campaigns, Anthropic report finds

CyberScoop · Sep 10 · Relevance: █████████░ 9/10

Why it matters to CISOs: Anthropic's report documents AI-enabled espionage campaigns hitting 20+ government and defense organizations, with Chinese and Russian-linked actors using AI to democratize sophisticated attack capabilities — directly reshaping enterprise threat models and board-level risk conversations.

  • Russian-aligned espionage group targeted more than 20 government, intelligence, diplomatic, and defense organizations using Claude
  • Chinese undergraduate-run exploit foundry and ShinyHunters-affiliated breaches also documented in Anthropic's disruption report
  • AI is enabling smaller, less-resourced actors to execute attacks previously only possible by nation-state teams

📖 Read full article

📡 Macro Trends

Governments ‘buying time’ in race between innovation, security, national cyber director says

CyberScoop · Sep 10 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The National Cyber Director's public framing that governments are merely 'buying time' against AI-accelerated threats — and that AI exposes long-standing security failures rather than creating new ones — gives CISOs credible external validation for board-level arguments about foundational security investment.

  • National Cyber Director Sean Cairncross stated governments are 'buying time' in the race between AI innovation and security capability
  • Cairncross argued AI is surfacing and amplifying pre-existing security weaknesses rather than generating entirely novel threat categories
  • The statement came alongside White House promotion of a Texas water sector cybersecurity partnership as a national critical infrastructure model

📖 Read full article

🔓 Data Breach

AI agents exploited PaperCut flaws to breach 395 organizations

Help Net Security · Sep 11 · Relevance: ████████░░ 8/10

Why it matters to CISOs: This is a landmark case of AI-autonomous attack execution at scale — a likely Russian-speaking actor delegated end-to-end exploitation of 440 PaperCut instances across 395 organizations in 48 countries to AI agents, signaling a new operational tempo that human-speed defenses cannot match.

  • Threat actor built a private lab environment, developed a working exploit for PaperCut NG/MF, then deployed AI agents to autonomously execute the campaign
  • At least 440 PaperCut instances across 395 organizations in 48 countries were compromised
  • PaperCut has released patched versions (26.0.5, 25.0.13, 24.1.10); unpatched servers remain exposed

📖 Read full article

IDScan confirms breach after 153 million driver’s licenses leak on dark web

Help Net Security · Sep 11 · Relevance: ████████░░ 8/10

Why it matters to CISOs: 153 million driver's license scans from an identity verification vendor now circulating on the dark web represents a systemic third-party risk failure with downstream liability exposure for every enterprise that relied on IDScan for KYC and identity workflows.

  • IDScan.net confirmed unauthorized access to customer data stored on its cloud platform, discovered around September 1, 2026
  • More than 153 million driver's license scans were offered for sale on the dark web before the confirmation
  • IDScan serves car rental companies, retailers, and cannabis dispensaries, expanding the blast radius to their customer populations

📖 Read full article

⚖️ Governance & Policy

CISA is on the verge of filling hundreds of critical vacancies

Cybersecurity Dive · Sep 10 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: CISA filling 250 critical vacancies while simultaneously finalizing CIRCIA incident-reporting rules means enterprise security teams should expect accelerated regulatory enforcement timelines and increased government engagement capacity — both board-reportable developments.

  • CISA is preparing to hire approximately 250 staff to fill critical vacancies
  • The agency is simultaneously finalizing the CIRCIA incident-reporting regulation affecting critical infrastructure operators
  • A new industry coordination structure is also being established, signaling a more assertive federal posture on incident response

📖 Read full article

Hawley probes OpenAI over Hugging Face breach

CyberScoop · Sep 10 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A Senate inquiry framing AI lab security failures as 'reckless' leadership decisions signals that Congress is moving toward holding AI vendors to security accountability standards — a regulatory trajectory CISOs adopting AI platforms must brief to their boards.

  • Senator Hawley launched a probe into OpenAI over its handling of the Hugging Face breach, describing leadership decisions as 'reckless'
  • The inquiry invokes existential AI risk arguments to underpin security accountability demands
  • This represents an escalation of congressional scrutiny of AI vendor security practices beyond standard data breach oversight

📖 Read full article

Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

The Record (Recorded Future) · Sep 10 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Treasury's push for mandatory cyber scam reporting from financial institutions — backed by $13 billion in documented losses — signals an imminent expansion of financial sector cyber reporting obligations that CISOs at banks and their enterprise partners must prepare compliance programs for.

  • U.S. Treasury documented nearly $13 billion in cyber scam losses since 2023 and is urging banks to file reports on these incidents
  • The guidance targets the globally expanding cyber scam industry, including fraud operations linked to Southeast Asian crime syndicates
  • Increased mandatory reporting expectations for financial institutions are signaled, with cross-sector supply chain implications

📖 Read full article

🚨 Critical Vulnerability

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

The Hacker News · Sep 11 · Relevance: █████████░ 9/10

Why it matters to CISOs: A CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center is being actively exploited by three distinct threat clusters including ransomware operators and state-sponsored actors — any enterprise running unpatched FMC is at immediate, existential risk.

  • CVE-2026-20079 carries a CVSS score of 10.0 and allows unauthenticated remote attackers to bypass authentication in Cisco FMC
  • Three separate threat clusters — including Qilin ransomware and state-sponsored actors — have been observed exploiting the flaws
  • Cisco Talos confirmed active exploitation; patching is urgent for all organizations running Secure Firewall Management Center

📖 Read full article

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

BleepingComputer · Sep 10 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A sophisticated exploit kit chaining Windows and Chrome zero-days — deployed by multiple cyber-espionage groups — represents an active, cross-platform threat to enterprise endpoints that requires immediate patch verification and endpoint detection review.

  • The 'BlueMoon' exploit kit chains zero-day vulnerabilities in both Microsoft Windows and Google Chrome
  • Multiple cyber-espionage groups have deployed the kit, indicating broad threat actor access or a shared toolset
  • Both Windows and Chrome patches should be validated as deployed across enterprise fleets immediately

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: It's Friday, September 11th, 2026. This is Cleartext. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Jordan: So here's the sentence I want every CISO to sit with this morning. A threat actor built a working exploit for PaperCut print management software, then handed the entire operation — reconnaissance, exploitation, persistence — to AI agents that did the work autonomously across 395 organizations in 48 countries. Not assisted. Not augmented. Delegated. We're not talking about the future anymore. This is September 2026.

Alex: And that story sits inside a week where Anthropic published a report documenting how AI is fundamentally reshaping who can run a state-level hacking campaign, where the National Cyber Director publicly admitted governments are just buying time, and where a CVSS 10.0 in Cisco's firewall management console is being actively exploited by ransomware operators and state-sponsored groups simultaneously. We've also got 153 million driver's licenses on the dark web from a third-party identity vendor, Congress going after AI lab security practices, and CISA staffing up in ways that should change your regulatory planning. It's a full show. Let's dig in.

Jordan: I want to start by connecting the Anthropic report and the PaperCut campaign because they're really two sides of the same coin. Anthropic disclosed that they disrupted a Russian-aligned espionage group that used Claude to target more than 20 government, intelligence, diplomatic, and defense organizations. They also found an exploit foundry run by Chinese undergraduates — undergraduates, Alex — and ShinyHunters-affiliated breaches leveraging their platform. The through line is democratization. The barriers to entry for sophisticated offensive operations have collapsed.

Alex: And the PaperCut case, reported by GreyNoise, is the operational proof of that thesis. A likely Russian-speaking actor built the exploit in a private lab, validated it, then turned AI agents loose to execute at scale. 440 compromised instances. 395 organizations. 48 countries. The human set the objective, the machines executed. That's a fundamentally different operational tempo than anything we've defended against.

Jordan: What's critical here for CISOs is understanding what this means for your threat model. You can no longer assume that a campaign of this breadth requires a large, well-funded team. The labor constraint that used to be your implicit defense — the idea that attackers had to choose their targets because they had limited human operators — that constraint is gone. AI agents scale horizontally in ways human operators never could.

Alex: And if you're running PaperCut NG or MF, the patches are out — versions 26.0.5, 25.0.13, and 24.1.10. This is not a drill. Unpatched servers are being found and compromised automatically. But the bigger board conversation here isn't about PaperCut specifically. It's about what your exposure surface looks like when every unpatched system is a target for autonomous exploitation, not opportunistic scanning by a human.

Jordan: Which brings us neatly to what the National Cyber Director said this week. Sean Cairncross used the phrase "buying time" to describe where governments are in the race between AI innovation and security capability. That's a remarkably candid framing from the White House. He also made a point I think is underappreciated: AI is surfacing and amplifying pre-existing security weaknesses, not generating entirely novel threat categories.

Alex: I actually think that's one of the most useful things a government official has said about AI and security. Because it reframes the board conversation away from "AI creates scary new attacks we can't understand" toward "AI makes all the technical debt we've been accumulating for years suddenly exploitable at scale." That's a message that resonates in a budget conversation. You're not asking for money to defend against science fiction. You're asking for money to fix the foundations you've been underfunding for a decade, because the consequences of not fixing them just accelerated dramatically.

Jordan: And the PaperCut case is exhibit A. These weren't zero-days. These were known vulnerabilities with patches available. The AI agents didn't need novel exploits. They needed unpatched targets, and they found hundreds of them.

Alex: Let's pivot to the Cisco FMC vulnerability because this one requires immediate action. CVE-2026-20079, CVSS 10.0 — which, for anyone who needs reminding, is the maximum severity score. It's an authentication bypass in the web interface of Cisco Secure Firewall Management Center. Unauthenticated remote attackers can bypass authentication entirely.

Jordan: And here's what makes this particularly dangerous: Cisco Talos has confirmed active exploitation by three separate threat clusters. One is deploying Qilin ransomware. At least one is state-sponsored. When you have three distinct groups converging on the same vulnerability, you're looking at a very short window before exploitation becomes industrialized, if it isn't already. If you run FMC and you haven't patched, stop listening to this podcast and go patch. Then come back.

Alex: I'll also flag the BlueMoon exploit kit, which chains zero-days in both Windows and Chrome. Multiple cyber-espionage groups have deployed it, which suggests either a shared developer, a commercial exploit broker, or a compromised toolset that's proliferating. Either way, the action item is the same: validate that your latest Windows and Chrome patches are deployed across your entire fleet. Endpoint teams should be confirming coverage, not assuming it.

Jordan: Now let's talk about the IDScan breach, because this is a third-party risk story that should make every CISO uncomfortable. IDScan.net is a Louisiana-based identity verification company. They process ID checks for car rental companies, retailers, cannabis dispensaries. Someone got into their cloud platform, and more than 153 million driver's license scans are now for sale on the dark web. The data was being offered before IDScan even confirmed the breach publicly.

Alex: This is a systemic failure in the vendor risk ecosystem. Every organization that used IDScan for KYC, age verification, or identity workflows now has downstream liability exposure. Their customers' data was in IDScan's hands, and those customers probably had no idea who IDScan was. That's the nature of the identity verification supply chain — it's invisible until it breaks.

Jordan: And 153 million driver's licenses is not an abstract number. That's roughly half the licensed drivers in the United States. This data enables identity fraud at an industrial scale. For CISOs, the immediate action is to audit whether IDScan touches any of your workflows, directly or through vendors. But the strategic action is harder: how do you evaluate the security posture of identity verification vendors who handle your most sensitive customer data?

Alex: It's a question that comes up in every board meeting I've ever been in about third-party risk, and the honest answer is that most organizations still don't have good visibility into their fourth-party exposure. This breach is going to be a case study in that gap.

Jordan: Let's shift to governance. Three stories this week that together paint a picture of where regulation is heading. First, CISA is preparing to hire roughly 250 people to fill critical vacancies while simultaneously finalizing the CIRCIA incident-reporting rules. Second, Senator Hawley is probing OpenAI over the Hugging Face breach, using language like "reckless" to describe leadership decisions. Third, Treasury is pushing banks to file cyber scam reports, citing nearly $13 billion in losses since 2023.

Alex: The CISA story is significant because it's not just hiring — it's hiring in the context of CIRCIA finalization. When you have a regulator simultaneously expanding its enforcement capacity and finalizing the rules it will enforce, you should expect shorter timelines and more assertive engagement. If you're in critical infrastructure, your incident response playbooks need to account for CIRCIA reporting obligations now, not when the final rule drops.

Jordan: The Hawley probe is interesting because of the framing. He's not just asking about a data breach. He's invoking existential AI risk arguments to underpin security accountability demands. That's a political strategy that creates bipartisan space for AI vendor regulation. Whether you think the existential risk framing is warranted or not, the practical effect is the same: Congress is signaling that AI vendors will be held to security standards, and CISOs adopting AI platforms need to factor that regulatory trajectory into their procurement decisions.

Alex: And the Treasury guidance on cyber scam reporting is the financial sector version of the same trend. $13 billion in documented losses gives Treasury the political ammunition to push for mandatory reporting expansion. If you're a CISO at a financial institution, or at a company that partners closely with banks, this is coming. Build the compliance infrastructure now.

Jordan: So looking at the week as a whole, the theme is unmistakable. The AI acceleration curve has hit the threat landscape in a way that's no longer theoretical. Autonomous exploitation at scale. Democratized state-level capabilities. And the policy and regulatory apparatus is scrambling to respond — hiring, legislating, probing — but openly admitting it's buying time.

Alex: For CISOs, the strategic implication is that your threat model needs to account for a world where the limiting factor on attacks is no longer human labor. The things that used to protect you implicitly — being a less interesting target, having obscure systems, relying on attacker fatigue — those assumptions are breaking down. The board conversation has to evolve from "are we a target" to "everything is a target now, and our defense has to be faster than autonomous offense."

Jordan: And the regulatory side is going to compress timelines. CIRCIA, Treasury reporting, congressional scrutiny of AI vendors — these are all converging in 2026 and 2027. If you're not building compliance readiness in parallel with your security architecture, you're going to be caught flat-footed.

Alex: That's the show for today. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, everyone. We'll see you Monday.

Jordan: Stay sharp.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-11.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.