Cleartext logocleartext_
daily briefing

Cleartext – September 18, 2026

Friday, September 18, 2026·9:57

Cleartext – September 18, 2026
9:57·6.0 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – September 18, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 10 stories across 4 topic areas, including: China’s FamousSparrow hackers target Latin America with new backdoor; Hackers claim breach of Russian election systems days before parliamentary vote; FBI, Coast Guard probe suspected cyberattacks on ships entering US waters.

Stories Covered

🌍 Geopolitical

China’s FamousSparrow hackers target Latin America with new backdoor

The Record (Recorded Future) · Sep 17 · Relevance: ████████░░ 8/10

Why it matters to CISOs: FamousSparrow's expansion into Latin American government agencies with a new custom backdoor (SparroWocky) signals broadening Chinese APT targeting that enterprises with regional operations or government partnerships in Latin America must account for in their threat models.

  • China-linked APT FamousSparrow is deploying a new backdoor called SparroWocky against Latin American government agencies
  • Campaign is framed in the context of US-China geopolitical competition for regional influence
  • The group's retooling with new malware suggests active capability development and evasion of existing detections

📖 Read full article

Hackers claim breach of Russian election systems days before parliamentary vote

The Record (Recorded Future) · Sep 17 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Election infrastructure breaches immediately before a major vote elevate the risk of retaliatory or escalatory cyber operations against Western targets; CISOs at critical infrastructure and financial sector firms should heighten monitoring posture during the voting window.

  • Anonymous hackers claim to have compromised computer systems connected to Russia's election infrastructure
  • The claimed breach occurred days before Russia begins voting for a new parliament
  • Timing raises risk of retaliatory Russian state-sponsored cyber activity against Western organizations

📖 Read full article

FBI, Coast Guard probe suspected cyberattacks on ships entering US waters

Cybersecurity Dive · Sep 17 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Active federal investigations into maritime cyberattacks signal that OT/ICS threats are now reaching critical infrastructure in US territorial waters, with direct implications for energy, logistics, and manufacturing CISOs managing port-adjacent supply chains.

  • FBI and US Coast Guard are actively investigating suspected cyberattacks on vessels entering US waters
  • Investigation comes amid heightened vigilance over US port facilities and maritime security
  • No specific attribution or attack vector disclosed publicly yet

📖 Read full article

🔓 Data Breach

Brevo supply-chain attack injected ClickFix scripts on customer sites

BleepingComputer · Sep 17 · Relevance: ████████░░ 8/10

Why it matters to CISOs: This SaaS supply chain attack—where a stolen Cloudflare API key allowed malicious script injection into Brevo's customer-facing JavaScript—illustrates how a single compromised vendor credential becomes a vector to attack thousands of downstream enterprise websites simultaneously.

  • Attackers stole a Cloudflare API key from email/CRM platform Brevo and used it to inject ClickFix malware distribution scripts
  • Malicious JavaScript was embedded in files served to Brevo's customer websites, extending the blast radius to all site visitors
  • Attack exemplifies third-party SaaS risk where vendor credential compromise cascades to enterprise customers

📖 Read full article

Researchers used Anthropic’s Claude to hack into OpenAI

TechCrunch Security · Sep 18 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The successful use of one AI system to autonomously exploit vulnerabilities in a rival AI provider's infrastructure—taking over employee accounts and accessing internal code—establishes a concrete precedent that AI agents are now viable offensive tools, reshaping enterprise threat modeling for AI-adjacent infrastructure.

  • Security researchers used Anthropic's Claude AI to exploit vulnerabilities in OpenAI's systems
  • Attackers achieved employee account takeover and gained access to an internal OpenAI code repository
  • Vulnerabilities were responsibly disclosed; both companies confirmed the findings

📖 Read full article

98% of fraudulent hires have company credentials by the time they’re caught

Help Net Security · Sep 18 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: The HYPR report quantifies the insider threat gap in the hiring-to-onboarding pipeline: North Korean IT worker infiltration campaigns and similar fraud schemes result in attackers holding authenticated enterprise credentials before HR or security detects them, requiring CISOs to implement identity verification controls pre-onboarding.

  • 98% of fraudulent hires already possess company credentials before they are detected, per HYPR research
  • A 90-day gap between hiring and onboarding creates a blind spot where adversaries receive legitimate credentials directly from IT
  • HYPR CEO warns that human intuition is not a security control and purpose-built pre-onboarding identity verification is required

📖 Read full article

⚖️ Governance & Policy

CISA ends weekly vulnerability roundups as part of shift to prioritization approach

Cybersecurity Dive · Sep 18 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: CISA sunsetting its weekly vulnerability roundups in favor of risk-based prioritization signals a formal shift in how the federal government expects enterprises to manage vulnerability programs—CISOs should realign their patch governance frameworks to emphasize exploitability and business impact over raw CVE volume.

  • CISA is discontinuing its longstanding weekly vulnerability bulletin roundups
  • The shift is driven by an AI-fueled surge in bug reports that makes volume-based approaches unsustainable
  • CISA is moving to a prioritization-first model, consistent with its SSVC (Stakeholder-Specific Vulnerability Categorization) framework

📖 Read full article

CISA Urges Critical Infrastructure to Plant Decoys Inside Networks

Infosecurity Magazine · Sep 17 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: CISA's formal guidance endorsing cyber deception—honeypots, decoy credentials, fake assets—as a detection control for critical infrastructure gives CISOs regulatory backing and a strategic framework to justify deception technology investments to boards and budget committees.

  • CISA released new official guidance recommending cyber decoys as an active detection and disruption mechanism for critical infrastructure
  • Guidance covers deployment of decoy credentials, systems, and data to identify and slow adversaries post-intrusion
  • Represents a shift from purely preventive controls toward assume-breach detection strategy at a federal policy level

📖 Read full article

🚨 Critical Vulnerability

Cisco alerts customers to second actively exploited zero-day in as many days

CyberScoop · Sep 17 · Relevance: ██████████ 10/10

Why it matters to CISOs: Cisco Identity Services Engine is a core NAC/AAA component in most large enterprise networks; a maximum-severity actively exploited zero-day here means attackers can bypass network access controls enterprise-wide, demanding emergency patching or compensating controls immediately.

  • Maximum-severity zero-day CVE-2026-76460 actively exploited in Cisco Identity Services Engine
  • This is the second actively exploited ISE zero-day disclosed within 24 hours
  • ISE has now suffered three actively exploited vulnerabilities since June 2025, indicating sustained attacker focus on the product

📖 Read full article

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Help Net Security · Sep 18 · Relevance: █████████░ 9/10

Why it matters to CISOs: Enterprises that have deployed AI coding agents (Claude Code, Codex, GitHub Copilot, Gemini CLI) to engineering teams face a zero-click supply chain RCE that can grant an attacker full access to developer workstations and connected systems; two agents remain unpatched, requiring urgent use-restriction decisions.

  • Plugin4Shell is a zero-click RCE affecting all four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI
  • Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0; GitHub Copilot and Gemini CLI remain unpatched
  • Researchers describe it as 'the first supply chain vulnerability of the AI agent ecosystem,' exploitable by any malicious plugin repository owner

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: Good morning. It's Friday, September 18th, 2026. You're listening to Cleartext. I'm Alex Chen.

Jordan: And I'm Jordan Reeves.

Alex: Jordan, I know where you want to start.

Jordan: Yeah. Cisco ISE. Two actively exploited zero-days in two days, the latest one rated maximum severity. If you run Cisco Identity Services Engine, and most large enterprises do, your network access controls are potentially compromised right now. That's not a Tuesday problem. That's a right-now problem. We'll get into it.

Alex: We will. We've also got a SaaS supply chain attack that turned a single stolen API key into a vector hitting thousands of downstream websites, CISA making two significant moves that will change how you run your vulnerability and detection programs, Chinese APT expansion into Latin America, a claimed breach of Russian election infrastructure right before a parliamentary vote, the FBI investigating cyberattacks on ships in US waters, and researchers who used one AI company's model to hack into another AI company's systems. Plus a zero-click RCE that hits the four major AI coding agents your developers are probably running right now. It's a full show. Let's get to it.

Jordan: Let's start with Cisco because this demands action. CVE-2026-76460, maximum severity, actively exploited in the wild, affecting Cisco Identity Services Engine. ISE is the backbone of network access control and authentication for a huge swath of enterprise networks. This is the third actively exploited vulnerability in this product since June of last year. That's not a pattern, that's a campaign. Someone is systematically going after this product.

Alex: And the implications are profound. ISE is your gatekeeper. It decides who gets on the network, what they can access, how they're authenticated. If an attacker owns ISE, they don't need to move laterally in the traditional sense. They can rewrite the rules. If you haven't already initiated emergency patching or stood up compensating controls, this is a drop-everything moment. And for the board conversation, this is a good case study in concentration risk. When a single vendor product is this central to your security architecture and it gets hit three times in fifteen months, you need to be asking hard questions about architectural resilience.

Jordan: Agreed. And frankly, if your NAC vendor is becoming your primary attack surface, something is structurally wrong.

Alex: Let's stay on vulnerabilities because the second one is equally urgent for a different reason. Plugin4Shell. Zero-click remote code execution affecting all four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. Researchers are calling it the first supply chain vulnerability of the AI agent ecosystem. Two are patched, Anthropic's Claude Code and OpenAI's Codex. Two are not. GitHub Copilot and Gemini CLI remain vulnerable.

Jordan: And zero-click is the critical word here. A malicious plugin repository owner can exploit this without any interaction from the developer. The attacker gets the same access as the employee running the agent. Think about what that means. Your senior engineers, the ones with access to production repos, CI/CD pipelines, cloud infrastructure, their workstations become the beachhead. No phishing required.

Alex: If you've deployed these tools to engineering teams, and at this point most enterprises have at least piloted them, you need to verify versions immediately. Claude Code 2.1.179 and Codex 0.146.0 are patched. For Copilot and Gemini CLI, you need to make a risk decision right now about whether to restrict use until patches land. I know that's painful. I know engineering leadership will push back. But this is a zero-click RCE with full workstation access. The risk math is clear.

Jordan: And this connects to our next story in an interesting way. Researchers used Anthropic's Claude to autonomously exploit vulnerabilities in OpenAI's infrastructure. They achieved employee account takeover and accessed an internal code repository. This was responsible disclosure, both companies confirmed it, but the precedent matters enormously.

Alex: It does. We've been talking about AI-augmented offensive operations as a future threat for what, two years now? This isn't future anymore. An AI agent autonomously identified and exploited vulnerabilities in a sophisticated target. The defenders at OpenAI are not amateurs. This worked anyway. For threat modeling purposes, you now have to assume that AI agents are viable autonomous attack tools. That changes the speed calculus. It changes the scale calculus.

Jordan: And it creates an uncomfortable recursive loop. AI tools with vulnerabilities being exploited by AI tools. We're going to be living in that loop for a while.

Alex: Let's move to the Brevo supply chain attack because this is a masterclass in how third-party SaaS risk materializes. Attackers stole a Cloudflare API key from Brevo, the email and CRM platform, and used it to inject ClickFix malware distribution scripts into JavaScript files that Brevo serves to its customers' websites. One compromised credential, thousands of affected sites, millions of potential victims visiting those sites.

Jordan: The blast radius here is what matters. Brevo's customers embed Brevo's JavaScript on their own websites. So an attacker who compromises Brevo doesn't need to target each customer individually. They modify the source and the malware propagates through the trust chain automatically. It's the same structural problem we saw with the Magecart campaigns years ago, but now it's SaaS-to-SaaS.

Alex: For CISOs, this is a concrete example of why your third-party risk program needs to go beyond questionnaires. You need to understand what code your vendors are injecting into your web properties, how those assets are secured, and what happens when a vendor's cloud credentials are compromised. Subresource integrity, content security policies, runtime script monitoring, these aren't nice-to-haves. They're your blast shield.

Jordan: Now let's shift to the geopolitical landscape because it's busy. Start with FamousSparrow, a China-linked APT group that's deploying a new custom backdoor called SparroWocky against Latin American government agencies. This matters for two reasons. One, it represents a geographic expansion of Chinese cyber espionage operations into a region that many Western enterprises treat as lower-risk. Two, the retooling with new malware means existing detections are likely blind to it.

Alex: If your organization has operations in Latin America, government partnerships, or supply chain dependencies in the region, you need to update your threat model. Chinese APT targeting has historically concentrated on the Five Eyes nations, Southeast Asia, and Taiwan. Latin America was considered peripheral. That's clearly no longer the case. And the geopolitical context matters. This is happening against the backdrop of intensifying US-China competition for regional influence in Latin America. Cyber operations are a tool of that competition.

Jordan: Moving north to Russia. An anonymous hacking group claims to have breached systems connected to Russia's election infrastructure days before parliamentary voting begins. I want to be careful here because claims aren't confirmed breaches. But the timing is what matters for our audience.

Alex: It is. Whether the breach is real or overstated, the Russian government will use it to justify retaliatory operations. We've seen this playbook before. CISOs at critical infrastructure organizations, financial services, energy, anyone Russia considers a legitimate target for proportional response, should be elevating their monitoring posture through the voting window and for several weeks after.

Jordan: And the third geopolitical thread ties into this nicely. FBI and Coast Guard are actively investigating suspected cyberattacks on ships entering US waters. No attribution yet, no specific vector disclosed, but the fact that there's a joint federal investigation tells you the severity is real.

Alex: Maritime OT security has been a known gap for years. Vessels operate with outdated systems, limited segmentation, and they're connected to port infrastructure that supports critical supply chains. If you're in energy, logistics, or manufacturing with port-adjacent supply chain dependencies, this investigation should prompt a review of your maritime exposure. Don't wait for attribution to assess your risk.

Jordan: Let's pivot to two CISA moves that are going to reshape operational security programs. First, CISA is sunsetting its weekly vulnerability bulletin roundups. The reason is the AI-fueled avalanche of bug reports has made volume-based approaches unsustainable. They're moving to a prioritization-first model aligned with their SSVC framework.

Alex: This is a significant signal. The federal government is formally saying that tracking every CVE is no longer viable and they're not going to pretend otherwise. CISOs who haven't already shifted to exploitability-based and business-impact-based prioritization need to accelerate that transition. Your patch governance framework should be built around SSVC or something equivalent, not raw CVE counts in a weekly report.

Jordan: Second CISA move. They've released formal guidance recommending cyber deception, honeypots, decoy credentials, fake assets, as a detection and disruption mechanism for critical infrastructure. This is assume-breach doctrine formalized at the federal policy level.

Alex: And this is significant for the budget conversation. If you've been trying to justify deception technology investments to your board and getting pushback, you now have CISA guidance explicitly endorsing it. That's a regulatory tailwind. Deception technologies are force multipliers for detection. They don't replace your existing stack, but they give you high-fidelity signals that are extremely hard for attackers to distinguish from real assets.

Jordan: Last story. The HYPR report on fraudulent hires. Ninety-eight percent of fraudulent hires already possess company credentials before they're detected. There's a ninety-day gap between hiring and onboarding that creates a window where adversaries receive legitimate credentials directly from IT.

Alex: This is the North Korean IT worker problem quantified. We've been tracking these infiltration campaigns, and this data confirms what we suspected. The hiring-to-onboarding pipeline is a security gap that most organizations haven't instrumented. Pre-onboarding identity verification is now a security control, not just an HR process. Human intuition at the interview stage is not sufficient.

Jordan: The HYPR CEO put it well. Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT.

Alex: So, Jordan, as we close out the week, what's the thread here?

Jordan: Trust chain compromise. Every direction you look this week, the story is the same. Cisco ISE, the thing you trust to enforce access, is the attack surface. Brevo, a vendor you trust to serve JavaScript on your site, becomes the malware vector. AI coding agents you trust to help developers become zero-click attack paths. Employees you trust enough to hire receive credentials before you realize they're adversaries. The entire week is about the infrastructure of trust being weaponized.

Alex: And the response can't be to trust nothing, because that's not operationally viable. The response is to verify continuously, instrument your trust boundaries, and assume that any trust chain can be compromised. The organizations that are doing that, assume-breach architecture, continuous identity verification, runtime monitoring of third-party code, deception for post-intrusion detection, they're the ones who will weather weeks like this. The ones still relying on perimeter defense and periodic audits will not.

Jordan: Patch Cisco ISE today. Check your AI coding agent versions today. Review your Brevo exposure today. Everything else can wait until Monday. Almost everything.

Alex: That's our show for Friday, September 18th. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend. Stay sharp. We'll see you Monday.

Jordan: See you Monday.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-18.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.