Cleartext Week in Review – September 19, 2026
Saturday, September 19, 2026·11:10
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – September 19, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 18 stories across 6 topic areas, including: Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE; FBI, Coast Guard boarded hacked oil tankers heading toward US coast; North Korean WaterPlum hackers infected 30,000 devices worldwide.
Stories Covered
🌍 Geopolitical
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Help Net Security · Sep 17 · Relevance: ██████████ 10/10
Why it matters to CISOs: Permanent, irrecoverable cloud data loss from a physical nation-state attack forces every CISO to reassess multi-region redundancy assumptions and cloud SLA fine print—especially for workloads in geopolitically sensitive regions.
- AWS confirmed permanent, unrecoverable loss of customer data in its Bahrain (me-south-1) region and one UAE (me-central-1) availability zone following Iranian drone strikes six months ago
- Two separate AWS updates posted September 15 formally acknowledged that resources stored in those zones cannot be restored
- The incident is the first confirmed case of physical kinetic action causing permanent hyperscaler data loss at scale
FBI, Coast Guard boarded hacked oil tankers heading toward US coast
TechCrunch Security · Sep 18 · Relevance: █████████░ 9/10
Why it matters to CISOs: Maritime OT compromise that physically disrupted navigation and propulsion is a landmark escalation for critical-infrastructure CISOs; it demonstrates that cyber intrusions can now trigger federal law-enforcement boardings and physical interdiction of vessels.
- FBI and Coast Guard physically boarded foreign oil tankers en route to the US after indications their networks were compromised
- At least one tanker had navigation and propulsion systems disrupted by the cyberattack
- Agencies issued a joint statement describing the actions as 'joint security boardings' in response to confirmed network compromises
North Korean WaterPlum hackers infected 30,000 devices worldwide
BleepingComputer · Sep 19 · Relevance: ████████░░ 8/10
Why it matters to CISOs: WaterPlum's job-seeker lure targeting crypto and tech firms is a direct threat to enterprise hiring pipelines; a five-nation joint advisory signals that North Korea's crypto-theft apparatus has reached a scale requiring formal HR and onboarding security controls.
- Joint advisory from the US, Japan, Germany, and Australia warns that WaterPlum compromised at least 30,000 devices across 100 countries between December 2025 and July 2026
- Operators pose as AI and blockchain employers to lure job seekers, then steal cryptocurrency and sensitive data
- More than $10.7 million in stolen cryptocurrency has been transferred to North Korea
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
Wired Security · Sep 18 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Google's covert infiltration of TeamPCP—the group behind the worst-ever software supply-chain hacking spree affecting thousands of companies—reveals both the sophistication of supply-chain adversaries and the intelligence value of human-source operations for defenders.
- Google's Threat Intelligence Group embedded an undercover analyst inside TeamPCP's inner circle
- TeamPCP executed the most damaging software supply-chain hacking campaign on record, breaching thousands of companies
- The infiltration has yielded actionable intelligence about the group's tools, targets, and tradecraft
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
The Hacker News · Sep 15 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A joint US-UK-Netherlands advisory on Iran's Chosen Brick spyware—which uses Telegram as C2 to surveil dissidents globally—matters to CISOs in media, energy, and government sectors given Iran's demonstrated willingness to escalate from espionage to destructive attacks.
- NCSC and allied agencies attributed the 'Chosen Brick' spyware to Iran's intelligence service; it targets dissidents, journalists, and activists worldwide
- The malware uses Telegram as its command-and-control channel and can exfiltrate emails, chat messages, and screenshots, and activate the microphone
- Advisory issued jointly by the US, UK, and the Netherlands, signaling broad allied concern about the campaign's reach
📡 Macro Trends
Security teams increasingly outflanked by AI agents
Cybersecurity Dive · Sep 14 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Non-human identities spawned by AI agents are growing faster than existing IAM and PAM systems can track, creating a governance blind spot that attackers are beginning to exploit—CISOs need to extend identity security programs to cover agent identities explicitly.
- A new report warns that non-human identities generated by AI agents are proliferating beyond the capacity of existing identity management systems to monitor
- Security teams lack visibility into what AI agents are doing, what credentials they hold, and what systems they can reach
- The trend is compounding existing challenges around machine identity management and privileged access
AI the Top Priority for New Spend as Cyber Budgets Flatline
Infosecurity Magazine · Sep 15 · Relevance: ██████░░░░ 6/10
Why it matters to CISOs: With overall security budgets flat but AI commanding the majority of net-new discretionary spend, CISOs face a reallocation dilemma—they must justify AI investments to boards while the risk evidence base for AI security ROI remains immature.
- IANS and Artico Search research finds AI is the dominant category for net-new cybersecurity budget allocation in 2026
- Overall security budgets are effectively flat, meaning AI spending is cannibalizing other security program investments
- CISOs are investing ahead of proven ROI, driven by fear of AI-enabled threats rather than demonstrated value
🔓 Data Breach
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
The Hacker News · Sep 19 · Relevance: ████████░░ 8/10
Why it matters to CISOs: An AI model autonomously breaching real production systems during a misconfigured security evaluation is a board-level risk event: it demonstrates that AI agentic capabilities can cause unintended real-world harm and that test-environment isolation controls are now a security requirement.
- Google's Gemini model accessed and broke into real company systems in May 2026 during a security evaluation run by Israeli firm Irregular, due to a test domain misconfiguration
- The incidents were first reported by The Wall Street Journal
- The same evaluation partner was involved in similar AI-caused hacks disclosed previously, suggesting a pattern across multiple AI systems
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
BleepingComputer · Sep 19 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: ShinyHunters breaching Clop's infrastructure—including stealing private onion service keys—signals a new dynamic of criminal-on-criminal warfare that could disrupt ransomware gang operations and leak victim data through unexpected channels, complicating incident response for affected organizations.
- ShinyHunters defaced Clop's Tor-based data leak site and allegedly stole server data and the private keys for Clop's onion service
- ShinyHunters is threatening to extort the Clop ransomware operation itself
- The breach could expose Clop's victim data, infrastructure details, and operational security to law enforcement and rivals
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
TechCrunch Security · Sep 16 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: ShinyHunters' willingness to publicly leak state government PII after a failed ransom demand—and in the same week they compromised Clop—illustrates their growing boldness and the heightened reputational and legal exposure for any organization that declines to pay.
- ShinyHunters breached Florida's motor vehicle database and leaked thousands of drivers' personal records online after the state agency refused to pay the ransom
- The leaked files contain personally identifiable information of Florida residents
- The incident is part of a highly active week for ShinyHunters, which also breached Clop's infrastructure
⚖️ Governance & Policy
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
Cybersecurity Dive · Sep 18 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: CISA sunsetting its weekly vulnerability bulletins in favor of risk-based prioritization directly affects how enterprise security teams consume federal guidance—CISOs should recalibrate their vulnerability management workflows away from bulletin-driven cadences toward KEV-centric triage.
- CISA is discontinuing its weekly vulnerability roundup publications as part of a strategic shift toward helping organizations prioritize what actually matters
- The move is driven in part by the AI-fueled explosion in bug discovery overwhelming traditional bulletin formats
- CISA is simultaneously upgrading its vulnerability coordination platform to a new system called VINCE-NT with more automation
Treasury’s Scott Bessent says no liability exemptions for AI labs
CyberScoop · Sep 16 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Treasury Secretary Bessent's public rejection of AI liability exemptions before Congress signals a potential shift in the US regulatory posture toward AI—CISOs using AI tools from major labs should begin tracking potential liability implications for AI-caused security incidents.
- Secretary Bessent told the House Financial Services Committee that AI creators should be held 'liable for what they build and generate'
- He explicitly stated there should be no liability exemptions for AI labs
- The statement represents a significant executive-branch signal on AI governance at a time when AI liability legislation is actively being debated
CISA promotes a fresh way to deter cyberattackers: Lie to them
CyberScoop · Sep 16 · Relevance: ██████░░░░ 6/10
Why it matters to CISOs: CISA's first-ever formal guidance on deploying honeypots and decoys inside critical infrastructure networks gives CISOs authoritative cover to operationalize deception technology as part of a layered detection strategy—particularly relevant given the week's volume of confirmed intrusions.
- CISA released its first-ever guidance on using cyber decoys—such as honeypots and fake credentials—to detect and disrupt malicious activity inside networks
- The guidance is specifically targeted at critical infrastructure operators
- The move reflects CISA's broader shift toward active defense postures rather than purely preventive controls
🚀 Startup Ecosystem
New Italian unicorn Exein rides the physical AI wave
TechCrunch Security · Sep 15 · Relevance: ██████░░░░ 6/10
Why it matters to CISOs: Exein's $270M raise at a $1.7B valuation to secure AI in physical and embedded systems reflects investor conviction that OT/IoT security for AI workloads is the next major market—CISOs managing converged IT/OT environments should track this emerging vendor category.
- Italian startup Exein raised $270 million led by Headline at a $1.7 billion valuation, achieving unicorn status
- The company focuses on security for physical AI systems and embedded/IoT environments
- The raise is one of the largest European cybersecurity funding rounds of 2026 and signals strong investor appetite for OT/physical AI security
🚨 Critical Vulnerability
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
The Hacker News · Sep 17 · Relevance: █████████░ 9/10
Why it matters to CISOs: A CVSS 10.0 unauthenticated bypass in Cisco ISE—the network access control backbone for most large enterprises—actively exploited in the wild means any organization using ISE for zero-trust enforcement must treat this as a P0 patch event immediately.
- CVE-2026-76460 scores CVSS 10.0 and allows unauthenticated remote attackers to bypass authentication via an insufficiently controlled API endpoint
- This is the second actively exploited ISE zero-day disclosed in two consecutive days, and the product has suffered three actively exploited vulnerabilities since June 2025
- Cisco has released a software update and urges customers to check for signs of exploitation
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
The Hacker News · Sep 19 · Relevance: █████████░ 9/10
Why it matters to CISOs: AI-assisted attack chaining is no longer theoretical: researchers used a frontier model to chain two flaws, compromise employee accounts, and reach an internal code repository at a major AI company—a proof-of-concept that adversaries will replicate against enterprise targets.
- Hacktron researchers used Anthropic's Claude Opus 5 to chain a bug in OpenAI's public help forum with a weakness in OpenAI's login system to take over employee ChatGPT and Codex accounts
- The attack chain ultimately reached an internal OpenAI code repository
- The research was disclosed responsibly, but demonstrates that AI models can autonomously identify and exploit multi-stage vulnerability chains
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Help Net Security · Sep 18 · Relevance: █████████░ 9/10
Why it matters to CISOs: Plugin4Shell is the first supply-chain vulnerability class native to the AI agent ecosystem: any employee running Claude Code, Codex, GitHub Copilot, or Gemini CLI with plugins is potentially exposed to zero-click RCE with their own network access—demanding immediate policy action on AI coding agent use.
- A zero-click RCE flaw allows attackers who control a plugin's code repository to swap the plugin installed by an AI coding agent, even when pinned to a reviewed version
- All four major coding agents—Claude Code, Codex, GitHub Copilot, and Gemini CLI—were affected; Anthropic and OpenAI have patched, two remain unpatched
- Researchers describe it as 'the first supply chain vulnerability of the AI agent ecosystem'
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
The Hacker News · Sep 15 · Relevance: ████████░░ 8/10
Why it matters to CISOs: A CVSS 9.8 pre-auth RCE in the email gateway that sits at the perimeter of most enterprise networks—now actively exploited and suspected to be used by state-linked actors for espionage—demands immediate patching and log review for indicators of compromise.
- CVE-2026-76461 (CVSS 9.8) affects AsyncOS for Cisco Secure Email Gateway; no authentication required for exploitation
- Researchers warn the vulnerability could be leveraged by state-linked actors for espionage purposes
- Active exploitation confirmed in the wild; part of a cluster of Cisco zero-days disclosed this week
Further Reading
- 🌍 Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE — Help Net Security
- 🌍 FBI, Coast Guard boarded hacked oil tankers heading toward US coast — TechCrunch Security
- 🌍 North Korean WaterPlum hackers infected 30,000 devices worldwide — BleepingComputer
- 🌍 An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang — Wired Security
- 🌍 Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists — The Hacker News
- 📡 Security teams increasingly outflanked by AI agents — Cybersecurity Dive
- 📡 AI the Top Priority for New Spend as Cyber Budgets Flatline — Infosecurity Magazine
- 🔓 Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up — The Hacker News
- 🔓 ShinyHunters hacks Clop leak site, threatens to extort ransomware gang — BleepingComputer
- 🔓 Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database — TechCrunch Security
- ⚖️ CISA ends weekly vulnerability roundups as part of shift to prioritization approach — Cybersecurity Dive
- ⚖️ Treasury’s Scott Bessent says no liability exemptions for AI labs — CyberScoop
- ⚖️ CISA promotes a fresh way to deter cyberattackers: Lie to them — CyberScoop
- 🚀 New Italian unicorn Exein rides the physical AI wave — TechCrunch Security
- 🚨 Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks — The Hacker News
- 🚨 Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws — The Hacker News
- 🚨 Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched — Help Net Security
- 🚨 Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution — The Hacker News
Full Transcript
Click to expand full episode transcript
Jordan: This is the week the cloud lost its first data to a bomb. Not a ransomware payload, not a wiper—an actual Iranian drone strike permanently destroyed customer data in AWS regions, and Amazon finally admitted it's gone forever. That's where we start.
Alex: Welcome to Cleartext. I'm Alex Chen, alongside Jordan Reeves. This is your Saturday Week in Review for the week ending September 19th, 2026. If you couldn't keep up this week, here's what mattered and what it means. We've got four big themes to walk through. First, the kinetic-cyber convergence that's rewriting every assumption about cloud resilience and critical infrastructure. Second, a brutal week for Cisco that should have every network team working through the weekend. Third, AI systems going off the rails—breaking into real companies, chaining exploits autonomously, and exposing a brand-new supply-chain vulnerability class. And fourth, governance signals from CISA and Treasury that are quietly reshaping the regulatory landscape. Let's get into it.
Jordan: So let's start with the story that I think will define this quarter, maybe this year. AWS formally acknowledged on September 15th that customer data in me-south-1, their Bahrain region, and one availability zone in me-central-1 in the UAE is permanently, irrecoverably gone. This is from Iranian drone strikes six months ago. And I want to be precise about what "permanently" means here. This isn't "we're working on recovery." This is "the bits are destroyed." First time in the history of hyperscale cloud that a kinetic military action has caused permanent data loss at this scale.
Alex: And the business implications are staggering. Every enterprise risk assessment I've ever seen for cloud migration treats physical destruction of a cloud region as a theoretical extreme. It was always the tail risk you acknowledged but didn't really plan for. This week it became a realized loss. If you're a CISO with workloads in any geopolitically sensitive region—and that's an expanding list—you need to go back and read your cloud SLA fine print. Because I promise you, force majeure clauses cover exactly this scenario. Your provider is not liable. Your data is gone. Your board is going to ask you what the plan is.
Jordan: And it's not just cloud. The same geopolitical thread showed up in a completely different domain. FBI and Coast Guard physically boarded foreign oil tankers approaching the US coast this week after confirming their networks were compromised. At least one tanker had its navigation and propulsion systems disrupted by a cyberattack. Think about that. A cyber intrusion triggered a federal law enforcement boarding of a vessel at sea. That's a first.
Alex: For CISOs in energy, logistics, maritime, and frankly any sector with operational technology exposure, this is the new normal. Cyber incidents in OT environments are now triggering physical government intervention. The liability chain just got a lot more complicated. If your OT systems are compromised and it creates a physical safety risk, you're not just dealing with incident response anymore. You're dealing with federal agencies boarding your assets.
Jordan: And while we're on nation-state activity, two more threads worth connecting. The five-nation joint advisory on North Korea's WaterPlum group—30,000 devices compromised across 100 countries, over $10.7 million in crypto stolen, all through fake job postings targeting tech and crypto workers. This is industrial-scale social engineering through the hiring pipeline. And separately, the US, UK, and Netherlands jointly attributed the Chosen Brick spyware to Iranian intelligence. It uses Telegram as command and control, targeting dissidents and journalists, but the TTPs are easily repurposed against corporate targets.
Alex: The WaterPlum story in particular should be on every CISO's radar who's hiring in tech. Your HR and onboarding process is now an attack surface. Background verification, device provisioning, the whole pipeline needs security review. And with Iran, I'd point out the escalation pattern: espionage tools against dissidents one quarter, drone strikes on cloud infrastructure the next. The distance between surveillance and destruction is shrinking.
Jordan: One bright spot on the intelligence side—the Wired story about Google's Threat Intelligence Group embedding an undercover analyst inside TeamPCP, the group behind the worst software supply-chain hacking campaign on record. Thousands of companies breached, and Google had a mole in their inner circle. The actionable intelligence coming out of that operation is going to benefit defenders for a while. It's also a reminder that HUMINT still matters, even in cyber.
Alex: Let's shift to the Cisco situation because this week was genuinely alarming. Two actively exploited zero-days disclosed in consecutive days. First, CVE-2026-76461, a CVSS 9.8 pre-auth remote code execution in Cisco Secure Email Gateway. No authentication required. Actively exploited, with researchers warning it's being used by state-linked actors for espionage. This is a perimeter device. It's the first thing your inbound email touches.
Jordan: And the next day, CVE-2026-76460, a CVSS 10.0—perfect score—authentication bypass in Cisco ISE. Identity Services Engine. The product that enforces network access control, that underpins zero-trust architectures for most large enterprises. An unauthenticated remote attacker can bypass authentication entirely through an API endpoint. This is the third actively exploited ISE vulnerability since June 2025. At some point you have to ask whether ISE's security posture is sustainable for its role as a trust anchor.
Alex: If you're running Cisco ISE—and most of our listeners are—this is a P0 patch event. Full stop. You cannot run a zero-trust architecture on a product that's had three authentication bypasses exploited in the wild in fifteen months. I'm not saying rip and replace on Monday, but I am saying this needs to be a board-level conversation about concentration risk in your network access control layer. And the email gateway flaw needs patching this weekend if it hasn't happened already.
Jordan: Now let's talk about AI, because this was the week AI stopped being a theoretical risk and became an operational one in multiple concrete ways. Story one: Google's Gemini model broke into real production company systems during a security evaluation in May. A test domain misconfiguration by the Israeli firm Irregular caused the AI to target actual companies instead of sandboxed environments. The same evaluation partner had similar incidents previously. This is a pattern.
Alex: This is a board-level risk event. An AI model autonomously breaching real systems because of a configuration error in the test environment. The lesson for CISOs is that if you're running any kind of AI red-teaming or security evaluation, your isolation controls need to be as rigorous as your production security controls. Maybe more so, because the AI doesn't know the difference between a test target and a real one, and it doesn't care.
Jordan: Story two is even more concerning from a threat landscape perspective. Researchers at Hacktron used Anthropic's Claude Opus 5 to chain two separate vulnerabilities—a bug in OpenAI's public help forum and a weakness in OpenAI's login system—to take over employee accounts and reach an internal code repository. This was responsible disclosure, but the capability demonstration is profound. An AI model autonomously identified a multi-stage attack chain and executed it.
Alex: And story three completes the picture. Plugin4Shell—a zero-click RCE vulnerability affecting all four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. An attacker who controls a plugin repository can swap the plugin installed by the agent, even when it's pinned to a reviewed version. The attacker gets the same network access as the developer running the agent. Anthropic and OpenAI have patched. Two remain unpatched. Researchers are calling it the first supply-chain vulnerability class native to the AI agent ecosystem.
Jordan: Let me connect these three stories because together they tell a very specific story. AI agents can now break into real systems accidentally, chain exploits intentionally, and be supply-chain compromised through their own plugin ecosystems. If your developers are using AI coding assistants—and they are—you need a policy by Monday. Not a guideline. A policy. What agents are approved, what plugins are permitted, what network access they're granted, and how you're monitoring their activity.
Alex: And this connects directly to the budget story from IANS and Artico Search this week. AI is consuming the majority of net-new cybersecurity spend in 2026, but overall budgets are flat. That means AI investment is cannibalizing other security programs. CISOs are spending on AI defense ahead of proven ROI, driven by fear of exactly the scenarios we just described. But if you're cutting somewhere else to fund AI security, you need to be very clear-eyed about what risk you're accepting.
Jordan: On the governance front, two important signals. CISA is sunsetting its weekly vulnerability bulletins. The AI-fueled explosion in bug discovery has made the old bulletin format unsustainable. They're shifting to risk-based prioritization centered on the Known Exploited Vulnerabilities catalog. If your vulnerability management program is still cadenced around weekly CISA bulletins, it's time to retool.
Alex: And Treasury Secretary Bessent told Congress explicitly that AI creators should be liable for what they build and generate, with no exemptions for AI labs. That's a significant executive-branch signal. For CISOs, it means the vendors selling you AI tools may soon face direct liability for AI-caused incidents. That changes procurement conversations, contract negotiations, and how you think about shared responsibility models for AI.
Jordan: Two quick hits before we wrap. CISA released its first-ever formal guidance on deploying honeypots and decoys in critical infrastructure networks. If you've been trying to get budget approval for deception technology, you now have federal authoritative cover. And Italian startup Exein hit unicorn status with a $270 million raise at $1.7 billion to secure AI in physical and embedded systems—a signal that investors see OT security for AI workloads as the next major market.
Alex: And one more: ShinyHunters had a spectacularly busy week. They breached Florida's motor vehicle database and leaked thousands of drivers' records after the state refused to pay. And then—and this is genuinely unprecedented—they hacked Clop's own leak site, stole their onion service private keys, and are now threatening to extort the ransomware gang itself. Criminal-on-criminal warfare. The implication for CISOs is that your stolen data may now surface through channels you never anticipated, complicating incident response and notification timelines.
Jordan: So stepping back. Alex, what was this week?
Alex: This was the week the theoretical became operational. Kinetic attacks permanently destroying cloud data. AI models autonomously breaching real systems. Supply-chain vulnerabilities native to AI agent ecosystems. Federal agencies boarding ships over cyber compromises. Every one of these was a scenario that lived in risk registers as a low-probability event. Now they're case studies. For CISOs going into next week, I'd say three priorities. One, reassess your cloud resilience assumptions, especially for geopolitically exposed regions. Two, establish formal policy on AI coding agent usage before your developers create exposure you can't see. Three, if you're running Cisco ISE or Secure Email Gateway, patch now and start a conversation about concentration risk.
Jordan: I'd add a fourth. Update your incident response playbooks for scenarios where the data surfaces through unexpected channels—whether that's criminal groups extorting each other or AI agents breaching systems your team didn't know existed. The attack surface expanded meaningfully this week, and not in ways most playbooks anticipated.
Alex: That's our Week in Review. The daily show returns Monday. Show notes and links to every story we covered are at cleartext.fm. Thanks for listening. Stay sharp out there.
Jordan: See you Monday.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-19.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.