Cleartext – September 23, 2026
Wednesday, September 23, 2026·10:25
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – September 23, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 9 stories across 5 topic areas, including: Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware; OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems; Ransomware Attacks Reach Record High for 2026.
Stories Covered
🌍 Geopolitical
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News · Sep 23 · Relevance: █████████░ 9/10
Why it matters to CISOs: A Chinese state-aligned actor (UTA0565) chained three zero-days across Chrome and Windows ALPC to achieve full compromise via drive-by sites — a browser-to-OS exploit chain that bypasses typical endpoint controls and signals advanced, well-resourced adversary capability targeting enterprise endpoints at scale.
- UTA0565 exploited CVE-2026-85046 and CVE-2026-87491 (Chrome) plus CVE-2026-85880 (Windows ALPC) as a chained zero-day sequence in early September 2026
- Attacks delivered CLEANGULP malware via fake websites; Volexity confirmed the same exploit kit is shared across multiple Chinese threat groups, indicating tooling distribution within the ecosystem
- Enterprises should validate Chrome and Windows patch status immediately and review proxy/NGFW logs for indicators from September 3–4 attack window
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
CyberScoop · Sep 23 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: The Daybreak partnership operationalizes AI-driven cyber defense for critical infrastructure in an active warzone, providing a real-world test case for AI-assisted OT/ICS security that will generate transferable intelligence — CISOs responsible for critical infrastructure or OT environments should track outcomes closely as both a defensive model and a signal of adversary response.
- OpenAI and Ukraine's government formalized 'Daybreak' to automate cybersecurity functions protecting power grids and water systems amid ongoing Russian cyber operations
- The program represents one of the first state-level deployments of frontier AI models specifically for OT/critical infrastructure defense in an active conflict context
- Russian targeting of Ukrainian infrastructure has been a sustained campaign, making this a live proving ground for AI defensive efficacy against nation-state adversaries
📡 Macro Trends
Ransomware Attacks Reach Record High for 2026
Infosecurity Magazine · Sep 23 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: August 2026 setting a single-month record of 1,073 confirmed ransomware victims — with industrial sector as the primary target — is a board-level data point for CISOs building the case for investment in OT security, resilience planning, and cyber insurance adequacy reviews heading into year-end budget cycles.
- 1,073 organizations confirmed as ransomware victims globally in August 2026, the highest monthly total on record per NCC Group data
- Industrial sector was the most heavily targeted vertical, consistent with multi-year trends of ransomware operators prioritizing operational disruption for leverage
- Record volume coincides with active exploitation of multiple zero-days in enterprise infrastructure (Check Point, F5, VeloCloud), suggesting opportunistic operators benefit from patching lag
🔓 Data Breach
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
BleepingComputer · Sep 22 · Relevance: █████████░ 9/10
Why it matters to CISOs: ShinyHunters' claimed exploitation of an Oracle PeopleSoft zero-day to breach FBI personnel data is a high-signal event: any enterprise still running on-prem PeopleSoft HR or identity systems must treat this as an active threat indicator and audit exposure immediately, while the counterintelligence implications of compromised law enforcement identities raise the threat landscape for all organizations that work with federal partners.
- ShinyHunters claims breach via a new Oracle PeopleSoft zero-day, defaced FBIjobs.gov, and asserts access to data on 'almost ALL FBI Agents' and job applicants
- FBI confirmed it is investigating; the jobs site remained unavailable as of reporting time
- TechCrunch noted stolen agent identities could enable foreign intelligence services to extort agents into cooperation — a counterintelligence escalation beyond typical data breach impact
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
The Hacker News · Sep 22 · Relevance: ████████░░ 8/10
Why it matters to CISOs: EvilTokens industrialized device-code phishing with AI at every stage, compromising over 12,000 inboxes including likely enterprise Microsoft 365 accounts; the takedown is welcome but the platform's architecture — $1,500 entry fee, $500/month subscriptions, Telegram distribution — signals that sophisticated BEC and account-takeover tooling is now commodity infrastructure that will be replicated.
- Microsoft seized 50 websites and disabled 150+ domains with court authorization from Eastern District of Virginia; two UK arrests followed
- EvilTokens used AI throughout the attack chain to compromise tokens, analyze breached inboxes, and identify optimal monetization paths for BEC and financial fraud
- Health-ISAC, Cloudflare, Coinbase, OpenAI, and SpyCloud participated in the coordinated takedown — a notable cross-sector enforcement model
⚖️ Governance & Policy
EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
Infosecurity Magazine · Sep 23 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The EU Court of Auditors formally criticizing the bloc's cross-border cyber incident response coordination is a governance signal for CISOs of multinationals operating under NIS2 and DORA — regulatory expectations for information sharing are rising even as the infrastructure to support them remains immature, creating compliance and operational risk.
- EU Court of Auditors identified structural information-sharing gaps between member states as a key impediment to effective major incident response
- Findings arrive as NIS2 and DORA enforcement timelines are active, raising the bar for what regulators expect from both public bodies and regulated private-sector entities
- The audit signals likely EU legislative or guidance activity to mandate more formal cross-border sharing frameworks that will cascade to enterprise compliance obligations
Citing China, President Trump doubles down on hands-off approach to AI regulation
CyberScoop · Sep 22 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The administration's explicit rejection of AI regulation — framed around competitive pressure from China and occurring against a backdrop of documented agentic AI hacks — directly shapes the threat and liability environment CISOs operate in: expect fewer federal guardrails on AI deployment, meaning security teams must drive internal governance where regulation will not.
- Trump administration reinforced a deregulatory AI posture following a series of agentic AI-related security incidents, treating regulatory restraint as a strategic competitive necessity
- The policy creates a governance vacuum that enterprises must fill internally, particularly for agentic AI systems with access to sensitive data and infrastructure
- Congress is simultaneously proposing its own AI-cyber programs (e.g., $100M DHS pilot, story index 41), creating a fragmented and uncertain regulatory trajectory
Insurance sector begins to offer clarity on AI-related cyber claims
Cybersecurity Dive · Sep 22 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: As agentic AI and frontier models introduce novel loss scenarios, insurers are beginning to define coverage boundaries for AI-related cyber incidents — CISOs need to engage their risk and legal teams now to understand emerging exclusions and how AI-driven events will be characterized under existing cyber policies before a claim event forces the conversation.
- Cyber insurers are actively developing AI-specific policy language in response to agentic AI hacks and frontier model-related incidents that don't map cleanly to legacy coverage categories
- Widespread policyholder uncertainty exists around whether AI-initiated or AI-assisted attacks trigger different coverage treatment than traditional intrusions
- CISOs should expect insurers to add AI governance attestation requirements to renewal questionnaires in 2026–2027 underwriting cycles
🚨 Critical Vulnerability
Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Help Net Security · Sep 23 · Relevance: ██████████ 10/10
Why it matters to CISOs: Simultaneous active exploitation of Check Point Security Management Server (CVE-2026-93616, pre-auth RCE, exploited since July) and F5 BIG-IP APM (CVE-2026-94127, unauthenticated RCE on OAuth servers) represents an emergency patching event for any enterprise running these ubiquitous perimeter and access control platforms. CISOs must treat both as zero-day incidents requiring immediate hotfix deployment and retroactive threat hunting back to late July.
- Check Point Management Server CVE-2026-93616 exploited as far back as July 23, 2026 — two months before emergency patches released September 22
- F5 BIG-IP APM CVE-2026-94127 allows unauthenticated RCE on systems where APM functions as an OAuth authorization server; engineering hotfixes now available
- Check Point Quantum Security Gateway RCE (CVE-2026-85102, patched September 9) began active probing within days of patch release, widening the attack surface
Further Reading
- 🌍 Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware — The Hacker News
- 🌍 OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems — CyberScoop
- 📡 Ransomware Attacks Reach Record High for 2026 — Infosecurity Magazine
- 🔓 ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach — BleepingComputer
- 🔓 Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises — The Hacker News
- ⚖️ EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response — Infosecurity Magazine
- ⚖️ Citing China, President Trump doubles down on hands-off approach to AI regulation — CyberScoop
- ⚖️ Insurance sector begins to offer clarity on AI-related cyber claims — Cybersecurity Dive
- 🚨 Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances — Help Net Security
Full Transcript
Click to expand full episode transcript
Alex: Good morning. It's Wednesday, September 23rd, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. This is Cleartext.
Jordan: So let's start here. ShinyHunters says they popped the FBI. Not a contractor, not some peripheral system. They claim they exploited an Oracle PeopleSoft zero-day to breach FBIjobs.gov and walk out with identity data on, and I'm quoting here, "almost all FBI agents" plus job applicants. The site is still down. The FBI says they're investigating. And if even a fraction of this is real, the counterintelligence implications are genuinely ugly.
Alex: That's where we're starting today, and it sets the tone. We've got a packed show. Chinese state actors chaining zero-days through Chrome and Windows. Record ransomware numbers. Emergency patches for Check Point and F5 that should have been on your desk yesterday. An AI-for-defense partnership in Ukraine that's worth watching closely. And on the governance side, the EU is admitting its cyber coordination is broken, the White House is doubling down on no AI regulation, and insurers are finally starting to define what they will and won't cover when AI goes sideways. Let's get into it.
Jordan: Back to the FBI breach. ShinyHunters is not a new name. These are the same operators behind a string of major breaches going back years. What's different here is the target and the claimed vector. An Oracle PeopleSoft zero-day. If that's confirmed, every organization still running on-prem PeopleSoft for HR, identity, payroll, you need to be treating this as a live threat right now. Don't wait for Oracle's advisory cycle.
Alex: And let's talk about what stolen FBI agent identities actually mean. TechCrunch made the point that foreign intelligence services could use this data to identify, approach, and potentially coerce agents into cooperation. That's not a data breach in the traditional sense. That's a counterintelligence event. And it cascades. If you're a defense contractor, a law firm doing federal work, a financial institution with a relationship to federal law enforcement, your threat model just shifted.
Jordan: The uncomfortable truth is that PeopleSoft is still load-bearing infrastructure at a shocking number of large organizations. It's one of those systems that's been on the migration roadmap for a decade but never quite gets replaced. And now we're seeing what that deferral costs.
Alex: Exactly. Legacy risk isn't theoretical anymore. It's an active exploitation vector. Let's pivot to the other major zero-day story, because this one is arguably more broadly impactful. UTA0565, a Chinese state-aligned group, chained three zero-days, two in Chrome, one in Windows ALPC, to achieve full compromise through drive-by websites. Browser to OS. No user interaction beyond visiting a page.
Jordan: This is the kind of exploit chain that makes defenders' stomachs drop. CVE-2026-85046, CVE-2026-87491 on the Chrome side, CVE-2026-85880 on Windows ALPC. Volexity confirmed that this exploit kit isn't just one group's work. It's being shared across multiple Chinese threat groups, which tells you this is an ecosystem-level capability, not a single operator. The tooling is being distributed like infrastructure.
Alex: So what should CISOs be doing right now?
Jordan: Three things. First, validate Chrome and Windows patch status across your fleet immediately. If you have systems that were unpatched between September 3rd and 4th, that's your exposure window. Second, pull your proxy and next-gen firewall logs for that same window and hunt against the IOCs Volexity published. Third, have an honest conversation about whether your endpoint controls would have caught a browser-to-kernel exploit chain. For most organizations, the answer is probably not without behavioral detection tuned for this.
Alex: And this connects directly to our vulnerability segment. Check Point and F5 both have critical zero-days under active exploitation. I want to be specific because this is actionable. Check Point Security Management Server, CVE-2026-93616, pre-auth remote code execution, exploited since July 23rd. That's two months of adversary access before patches dropped on September 22nd. And F5 BIG-IP APM, CVE-2026-94127, unauthenticated RCE on any system functioning as an OAuth authorization server.
Jordan: Let me underscore the Check Point timeline. July 23rd. If you're running Check Point Management Servers, you don't just need to patch. You need to threat hunt back to late July. Assume compromise, prove otherwise. And on F5, if your BIG-IP APM is configured as an OAuth authorization server, that's your crown jewels access control sitting behind an unauthenticated RCE. Engineering hotfixes are available now. Deploy them today.
Alex: Check Point also patched a Quantum Security Gateway RCE, CVE-2026-85102, on September 9th, and active probing started within days. The window between patch release and exploitation has essentially collapsed for perimeter devices.
Jordan: Perimeter devices are the new endpoints. Except they're worse because they're trusted by design, they're hard to instrument, and they often don't have the same patching discipline as your endpoint fleet. This is a pattern we've been warning about for two years and it's only accelerating.
Alex: Let's zoom out to the macro picture. NCC Group's data shows 1,073 confirmed ransomware victims globally in August 2026. That's the highest single-month total ever recorded. The industrial sector is the most heavily targeted vertical, which is consistent with multi-year trends but the volume is new.
Jordan: And here's the connection. Those Check Point and F5 zero-days we just talked about, plus the VeloCloud vulnerabilities from earlier this month, ransomware operators are riding the same exploitation waves as state actors. The initial access is often the same. What differs is the monetization. So when you see record ransomware numbers coinciding with a spike in enterprise infrastructure zero-days, that's not a coincidence. It's a supply chain effect. More zero-days in perimeter gear means more initial access for everyone, including ransomware affiliates who buy or find those footholds.
Alex: This is the data point CISOs need for year-end budget conversations. We're heading into Q4 planning cycles. If your board asks whether the threat is really getting worse, 1,073 victims in a single month is your answer. And the industrial sector concentration makes the case for OT security investment specifically.
Jordan: Which brings us to Ukraine. OpenAI and the Ukrainian government formalized a program called Daybreak to automate cybersecurity functions protecting power grids and water systems. This is happening in an active war zone under sustained Russian cyber operations.
Alex: This is significant for several reasons. It's one of the first state-level deployments of frontier AI models specifically for OT and critical infrastructure defense. Ukraine's infrastructure has been under constant Russian cyber and kinetic attack for years. So this isn't a proof of concept. It's a live proving ground against a sophisticated nation-state adversary.
Jordan: Every CISO responsible for critical infrastructure or OT environments should be tracking outcomes from Daybreak closely. Not because you're going to replicate it tomorrow, but because it will generate real data on what AI-assisted defense can and can't do against determined adversaries in OT environments. That intelligence will be transferable. And frankly, it'll also show us how Russia responds. Adversary adaptation to AI-driven defenses is something we have almost no empirical data on. We're about to get some.
Alex: Now let's shift to governance, because there are three stories today that together paint a very specific picture of where the regulatory landscape is heading. First, the EU Court of Auditors formally criticized the bloc's cross-border cyber incident response coordination, identifying structural information-sharing gaps between member states.
Jordan: This matters because NIS2 and DORA are live. The regulators are raising the bar for what they expect from private sector entities on information sharing and incident response, but the auditors are saying the public infrastructure to support that doesn't actually work yet. If you're a multinational operating in the EU, you're being held to standards that the governments themselves can't meet. That's the compliance environment.
Alex: Second, the Trump administration explicitly doubled down on a deregulatory posture toward AI, framing it as competitive necessity against China. This comes after a series of documented agentic AI security incidents.
Jordan: So we're in a world where AI-driven attacks are increasing, AI-driven defense is being deployed in war zones, and the U.S. government's position is that regulation would be a strategic mistake. I understand the competitive argument. I don't think it's wrong on its face. But for CISOs, the practical implication is clear. There will be no federal guardrails on AI deployment in the near term. Your internal governance program is the only governance program. If you haven't built one, you're operating without a net.
Alex: And that connects directly to our third governance piece. Cyber insurers are actively developing AI-specific policy language. They're trying to figure out how to characterize AI-initiated or AI-assisted attacks under existing coverage. CISOs should expect AI governance attestation requirements showing up in renewal questionnaires in the 2026-2027 underwriting cycle.
Jordan: This is the market filling the regulatory vacuum. When the government won't regulate, insurers will. And their incentives are actually pretty well aligned with good security outcomes because they're the ones writing the checks when things go wrong. So if you want to know what AI governance standards will look like in practice, watch what the underwriters require, not what Congress debates.
Alex: One more story before we close. Microsoft took down EvilTokens, a device-code phishing service that used AI at every stage of the attack chain. Fifty websites seized, 150 domains disabled, two arrests in the UK, 12,000 inboxes compromised.
Jordan: The cross-sector coordination here was notable. Microsoft, Health-ISAC, Cloudflare, Coinbase, OpenAI, SpyCloud, all participating in a coordinated takedown. That's the enforcement model that actually works. But the business model is what should concern you. Fifteen hundred dollars entry fee, five hundred a month subscription, distributed via Telegram. This is commodity infrastructure for sophisticated BEC and account takeover. The platform is gone. The architecture will be replicated within weeks.
Alex: So looking ahead, what's the through line today?
Jordan: The theme is convergence. State actors and criminal operators are exploiting the same infrastructure zero-days. AI is simultaneously the attack tool, the defense tool, and the governance gap. And the regulatory landscape is fractured, EU trying to coordinate and failing, U.S. explicitly stepping back, insurers trying to fill the void. CISOs are operating at the intersection of all of these forces.
Alex: Agreed. If I'm a CISO this week, I have three immediate priorities. Patch Check Point and F5. Audit any PeopleSoft exposure. And start the internal conversation about AI governance before your insurer forces it. Strategically, the budget case for 2027 is writing itself. Use the data.
Jordan: And hunt. Don't just patch. Hunt. The Check Point exploitation window goes back to July. The Chrome-Windows chain was active September 3rd and 4th. If you only patch forward, you're leaving adversaries already inside your environment.
Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. We'll be back tomorrow.
Jordan: Stay sharp.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-23.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.