Cleartext – September 15, 2026
Tuesday, September 15, 2026·9:59
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – September 15, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 10 stories across 6 topic areas, including: 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink; China spy chief points at US AI models in cyber threat warning; China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE.
Stories Covered
🌍 Geopolitical
'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
Dark Reading · Sep 14 · Relevance: █████████░ 9/10
Why it matters to CISOs: Russia's Sandworm is actively chaining Cisco vulnerabilities—including the newly disclosed email gateway zero-day—to deploy an upgraded Cyclops Blink botnet, representing a compounded threat to enterprise network infrastructure from a top-tier nation-state actor.
- Sandworm, a Russian GRU-linked threat group, is chaining Cisco vulnerabilities to spread an upgraded version of the Cyclops Blink botnet malware
- The FBI previously disrupted the original Cyclops Blink infrastructure in 2022; this represents a reconstituted and evolved capability
- The campaign intersects with the actively exploited Cisco Secure Email Gateway zero-day (CVE-2026-76461), compounding urgency for Cisco customers
China spy chief points at US AI models in cyber threat warning
The Record (Recorded Future) · Sep 15 · Relevance: ████████░░ 8/10
Why it matters to CISOs: China's top intelligence official publicly naming specific US AI models as enabling a 'disruptive upgrade' in offensive cyber capability signals an escalating AI-enabled threat environment that CISOs must factor into threat modeling and defensive investment decisions.
- China's spy chief specifically named Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber as accelerating adversary vulnerability discovery and malware development
- The statement represents a rare official Chinese government acknowledgment of AI's role in cyber offense, carrying strategic signaling implications
- Accelerated AI-driven exploitation windows are shrinking defender response time, requiring CISOs to re-evaluate detection and patching SLAs
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
The Hacker News · Sep 15 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A Chinese threat actor chaining Chrome and Windows zero-days in spear-phishing campaigns demonstrates sophisticated multi-stage exploitation capability that enterprise security teams must account for in endpoint and browser security controls.
- Threat cluster UTA0560 chained recently patched Chrome and Windows zero-days to deliver GRIMWEDGE, a JavaScript backdoor
- Initial targeting focused on NGOs as of September 1, 2026, consistent with Chinese espionage collection priorities that often pivot to corporate and government targets
- Volexity attribution and the use of patched-but-likely-unmitigated vulnerabilities highlights the lag between patch availability and enterprise deployment
📡 Macro Trends
AI the Top Priority for New Spend as Cyber Budgets Flatline
Infosecurity Magazine · Sep 15 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: IANS research confirming flat overall cyber budgets with AI dominating net-new investment has direct implications for CISOs justifying budget allocation to boards—existing programs will face pressure as AI security tools compete for finite resources.
- Overall cybersecurity budgets are flatlining according to IANS research, creating zero-sum tradeoffs between existing programs and AI investments
- AI security tooling and AI risk management are capturing the majority of net-new spending approvals
- CISOs face the dual challenge of funding AI defense while simultaneously managing AI-amplified threats with constrained budgets
🔓 Data Breach
Electric and gas utility CenterPoint Energy warns of data breach after dark web post
The Record (Recorded Future) · Sep 15 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A data breach at a major US electric and gas utility resulting in customer data appearing on the dark web highlights the continued targeting of critical infrastructure operators and reinforces regulatory notification obligations under NERC CIP and federal reporting rules.
- Houston-based CenterPoint Energy notified federal regulators of a breach that exposed customer data on the dark web
- CenterPoint serves millions of customers across multiple US states as a major electric and gas utility
- The incident underscores the intersection of OT/IT security risk and regulatory disclosure obligations in the energy sector
⚖️ Governance & Policy
Security teams increasingly outflanked by AI agents
Cybersecurity Dive · Sep 14 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: The rapid proliferation of non-human identities (NHIs) tied to AI agents is outpacing enterprise identity governance programs, creating a visibility and control gap that CISOs must address through updated IAM policies and NHI lifecycle management.
- Non-human identities associated with AI agents are growing faster than existing IAM and identity governance systems can track or manage
- The report warns that traditional identity security frameworks were not designed for the scale or behavior patterns of autonomous AI agents
- Enterprises face compounding risk as AI agents are granted elevated permissions without adequate oversight or revocation controls
🚀 Startup Ecosystem
New Italian unicorn Exein rides the physical AI wave
TechCrunch Security · Sep 15 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Exein's $270M raise at a $1.7B valuation signals major investor conviction in embedded and physical AI security—CISOs managing OT, IoT, or connected device environments should track this as an emerging vendor in a historically underserved security segment.
- Italian security startup Exein raised $270 million led by Headline at a $1.7 billion valuation, achieving unicorn status
- Exein focuses on security for physical AI and embedded systems, addressing the intersection of OT/IoT and AI deployment
- The funding round is one of the largest European cybersecurity raises of 2026, indicating institutional confidence in physical AI security as a distinct market
🚨 Critical Vulnerability
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
The Hacker News · Sep 15 · Relevance: █████████░ 9/10
Why it matters to CISOs: A CVSS 9.8 unauthenticated RCE zero-day in Cisco Secure Email Gateway—widely deployed enterprise infrastructure—is actively exploited in the wild, requiring immediate patching and IOC review across all on-premises AsyncOS deployments.
- CVE-2026-76461 carries a CVSS score of 9.8 and allows unauthenticated remote attackers to execute commands as root via insufficient validation in email parsing logic
- Affects Cisco AsyncOS versions 16.5, 16.0, 15.5 and earlier on on-premises physical appliances
- Cisco PSIRT confirmed active exploitation began as early as September 2025; IOCs have been published
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
BleepingComputer · Sep 15 · Relevance: █████████░ 9/10
Why it matters to CISOs: Ransomware operators are now actively exploiting the critical VMware vCenter RCE flaw patched in July, significantly elevating risk for enterprises running virtualized infrastructure—immediate patching verification and network segmentation review are warranted.
- CISA has confirmed ransomware gangs have joined ongoing exploitation of a critical VMware vCenter RCE vulnerability
- The vulnerability was patched in July 2026 but unpatched systems remain widely exposed
- Ransomware involvement signals a shift from targeted espionage-style exploitation to broad opportunistic attacks with destructive impact
Malicious actors already using critical GitLab flaw, CISA and others warn
Cybersecurity Dive · Sep 14 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A maximum-severity path traversal flaw in GitLab CE and EE is already being actively exploited, threatening software supply chain integrity for any enterprise using GitLab for source code management or CI/CD pipelines.
- CVE-2026-85706 is a CVSS 10.0 path traversal vulnerability affecting both GitLab Community Edition and Enterprise Edition
- CISA has added it to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation
- Unauthenticated access to sensitive files in development environments poses direct supply chain compromise risk
Further Reading
- 🌍 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink — Dark Reading
- 🌍 China spy chief points at US AI models in cyber threat warning — The Record (Recorded Future)
- 🌍 China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE — The Hacker News
- 📡 AI the Top Priority for New Spend as Cyber Budgets Flatline — Infosecurity Magazine
- 🔓 Electric and gas utility CenterPoint Energy warns of data breach after dark web post — The Record (Recorded Future)
- ⚖️ Security teams increasingly outflanked by AI agents — Cybersecurity Dive
- 🚀 New Italian unicorn Exein rides the physical AI wave — TechCrunch Security
- 🚨 Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution — The Hacker News
- 🚨 CISA: Critical VMware RCE flaw now exploited by ransomware gangs — BleepingComputer
- 🚨 Malicious actors already using critical GitLab flaw, CISA and others warn — Cybersecurity Dive
Full Transcript
Click to expand full episode transcript
Jordan: Sandworm is back. The same GRU unit the FBI thought it neutered in 2022 has reconstituted Cyclops Blink, and this time they're chaining Cisco vulnerabilities—including a fresh zero-day with a 9.8 CVSS score—to rebuild their botnet infrastructure. If you're running Cisco Secure Email Gateway on-prem, this is your five-alarm morning.
Alex: Welcome to Cleartext for Tuesday, September 15th, 2026. I'm Alex Chen, alongside Jordan Reeves. We have a dense one today. Nation-state campaigns from both Russia and China exploiting zero-days in the wild. A CVSS 10 in GitLab that's already being weaponized. Ransomware gangs piling onto VMware vCenter. China's spy chief publicly calling out specific American AI models by name. And a budget reality check that every CISO needs to hear. Let's get into it.
Jordan: So let's start where I opened, because this Sandworm story is actually the convergence of two stories that individually would each demand attention. You've got CVE-2026-76461, which is the Cisco Secure Email Gateway zero-day. On its own, it's a critical. Unauthenticated remote code execution as root through insufficient validation in the email parsing logic. Affects AsyncOS versions 16.5, 16.0, 15.5, and earlier on physical appliances. Cisco PSIRT says active exploitation traces back to at least September of last year, which means adversaries had this for a long time before it surfaced.
Alex: And what makes this particularly urgent is the overlay. Sandworm isn't just exploiting this one flaw. They're chaining multiple Cisco vulnerabilities together to deploy what researchers are calling an upgraded Cyclops Blink. For anyone who remembers, the original Cyclops Blink was a modular botnet framework targeting network devices. The FBI coordinated a takedown in 2022. The fact that Sandworm rebuilt it, improved it, and found new delivery chains tells you everything about nation-state persistence. These programs don't end. They iterate.
Jordan: Right. And the operational concern here is that Cyclops Blink targets network infrastructure, not endpoints. Your EDR isn't going to catch this. Your SOC playbooks for endpoint compromise don't apply. You need to be looking at your network appliance inventory, specifically Cisco, and verifying firmware versions, checking for IOCs that Cisco has published, and honestly, if you haven't patched that email gateway yet, stop listening and go do that. Come back later.
Alex: I'm half serious when I say that. The combination of a GRU-linked actor plus a 9.8 zero-day plus an established botnet framework is about as high on the threat matrix as it gets for enterprise infrastructure. If you have board reporting this week, this is the one you lead with.
Jordan: Now, let's stay on the nation-state thread because China had a busy week too. Two stories here that are related in important ways. First, a threat cluster that Volexity is tracking as UTA0560 chained recently patched Chrome and Windows zero-days in spear-phishing campaigns to deliver a JavaScript backdoor called GRIMWEDGE. Initial targets were NGOs, which is textbook Chinese espionage collection. Start with soft targets, refine the toolchain, then pivot to government and corporate networks.
Alex: The key detail for enterprise defenders is that these Chrome and Windows vulnerabilities were patched. They were available. But UTA0560 is betting, correctly in many cases, that the gap between patch availability and enterprise deployment is still weeks or months long. This is the exploitation window problem, and it's getting shorter on the attacker side and not getting shorter fast enough on the defender side.
Jordan: Which brings us to the second China story, and this one is genuinely unusual. China's spy chief, publicly and on the record, named specific American AI models. Anthropic's Claude Mythos and OpenAI's GPT-5.5-Cyber. He called them a "disruptive upgrade" in offensive cyber capability, specifically citing accelerated vulnerability discovery and malware development.
Alex: Let's unpack why this matters beyond the headline. Chinese intelligence officials almost never name specific technologies this way. This is strategic signaling. Part of it is domestic—justifying increased investment in Chinese AI and cyber capabilities. But part of it is international. It's a message to Washington that says, we see what your tools can do and we're building our response.
Jordan: And for CISOs, the operational takeaway is concrete. If AI is genuinely compressing the time from vulnerability disclosure to weaponized exploit, and there's increasing evidence that it is, then your patching SLAs need to reflect that reality. A 30-day patch window was already aggressive. In an AI-accelerated threat environment, it might be obsolete.
Alex: It also changes how you think about threat modeling. You can't model adversary capability as static anymore. The tooling available to sophisticated actors is improving on a curve, not a line. That has implications for everything from red team assumptions to insurance underwriting.
Jordan: Now, sticking with actively exploited vulnerabilities, because we have two more that require action. CISA confirmed that ransomware gangs are now exploiting the critical VMware vCenter RCE vulnerability that was patched back in July. This is the lifecycle we keep seeing. A vulnerability gets patched, nation-state actors exploit it quietly, and then ransomware operators pick it up for mass exploitation.
Alex: If you patched vCenter in July, verify it. If you didn't, this is now a ransomware-grade exposure, which means the risk calculation changes dramatically. You're not just worried about data theft. You're worried about encryption of your virtualized infrastructure, which for most enterprises is everything.
Jordan: And the second one is GitLab. CVE-2026-85706. This is a CVSS 10. Perfect score. Path traversal vulnerability in both Community Edition and Enterprise Edition. Unauthenticated access to sensitive files in development environments. CISA added it to the Known Exploited Vulnerabilities catalog, meaning it's confirmed in-the-wild.
Alex: This is a supply chain story. If your organization uses GitLab for source code management or CI/CD pipelines, an attacker with unauthenticated access to your development environment can access source code, secrets, credentials, pipeline configurations. The blast radius is not the GitLab server itself. It's everything that GitLab touches downstream.
Jordan: Patch immediately. Audit access logs. And honestly, if you're running GitLab CE or EE, assume you need to do a secrets rotation as a precaution until you can confirm you weren't exposed.
Alex: Let's shift to the CenterPoint Energy breach, because it illustrates a pattern we keep seeing in critical infrastructure. Houston-based CenterPoint, which serves millions of customers across multiple states, notified federal regulators about a breach that put customer data on the dark web.
Jordan: Details are still thin on the attack vector, but the significance is the sector. Energy utilities sit at the intersection of IT and OT risk, and they face a layered regulatory environment. NERC CIP, federal incident reporting requirements, state notification laws. For CISOs in the energy sector or any critical infrastructure vertical, this is a reminder that your incident response plan needs to account for multi-regulator notification timelines that don't always align.
Alex: And the dark web component means the data is already circulating. This isn't a contained incident. It's a customer trust and regulatory compliance event now.
Jordan: Alright, let's talk about budgets and the AI governance problem, because these two stories are really two sides of the same coin. IANS research out today confirms what most CISOs already feel. Overall cybersecurity budgets are flat. But AI security tooling and AI risk management are capturing the majority of net-new spending. That creates a zero-sum dynamic.
Alex: This is the conversation I'm having with every peer right now. Boards are enthusiastic about AI. They want AI security tools. They want AI risk governance. But they're not increasing the overall security envelope. So where does the money come from? It comes from existing programs. And that means CISOs are making tradeoffs that increase risk in some areas to fund AI initiatives in others.
Jordan: And the companion story makes that tradeoff even more uncomfortable. Cybersecurity Dive is reporting that non-human identities tied to AI agents are growing faster than enterprise IAM systems can track. Traditional identity governance wasn't designed for autonomous agents that spin up, act on elevated permissions, and may never get revoked. This is a control gap that's expanding in real time.
Alex: If you're investing in AI tooling but haven't updated your IAM policies to account for non-human identity lifecycle management, you're building capability on a foundation that has a growing crack in it. This needs to be a 2027 planning priority if it isn't already.
Jordan: Quick hit on the funding front. Italian security startup Exein raised 270 million dollars at a 1.7 billion valuation, making it a unicorn. They focus on security for physical AI and embedded systems. OT, IoT, connected devices. If you're managing a large embedded device footprint or deploying AI at the edge, this is a vendor to watch. It's one of the largest European cybersecurity raises this year, and it signals that investors see physical AI security as a distinct and underserved market.
Alex: Agreed. The embedded security space has been chronically underfunded relative to the risk it represents. Whether Exein specifically delivers remains to be seen, but the capital flowing into this segment is a positive signal.
Jordan: So, Alex, looking at everything on the board today, what's the emerging theme?
Alex: It's convergence under constraint. The threat environment is converging. Nation-states from Russia and China are chaining vulnerabilities, exploiting zero-days, and leveraging AI to accelerate their operations. Meanwhile, defenders are operating under flat budgets, making zero-sum tradeoffs, and struggling to keep up with an expanding identity surface they didn't design for. The gap between attacker capability acceleration and defender resource growth is widening. That's the structural risk CISOs need to articulate to their boards right now.
Jordan: I'd add that the AI thread runs through almost every story today. AI is accelerating attacker timelines. AI is consuming defender budgets. AI agents are creating new identity risks. And a major nation-state intelligence chief is publicly naming specific AI models as game-changers. We're past the point of debating whether AI changes the security calculus. It already has. The question now is whether organizations are adapting their operating models fast enough to match.
Alex: Watch this week for additional IOCs on the Sandworm campaign. Cisco will likely update its advisory. And if you haven't validated your VMware and GitLab patching status, today is the day.
Jordan: That's our show for Tuesday, September 15th. Show notes and links to every story we covered are at cleartext.fm.
Alex: Thanks for listening. We'll see you tomorrow.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-15.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.