Cleartext logocleartext_
daily briefing

Cleartext – September 25, 2026

Friday, September 25, 2026·9:57

Cleartext – September 25, 2026
9:57·6.1 MB

Enjoy the show? Subscribe to never miss an episode.

show notes

Cleartext – September 25, 2026

Daily cybersecurity briefing for CISOs and security leaders.

🎧 Listen to this episode

Episode Summary

Today's episode covers 9 stories across 5 topic areas, including: Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges; Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise; Russia's Hybrid Cyber-Physical War in Europe Heats Up.

Stories Covered

🌍 Geopolitical

Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges

CyberScoop · Sep 24 · Relevance: █████████░ 9/10

Why it matters to CISOs: A forensics vendor with U.S. government security contracts allegedly concealed Russian ownership, raising immediate supply-chain and vendor-vetting concerns for any enterprise or government entity using third-party forensic or investigative tools. CISOs must reassess vendor due diligence processes for ownership transparency, especially for tools with privileged access to devices.

  • DOJ alleges Oxygen Forensics concealed Russian ownership while holding U.S. security agency contracts
  • Two company leaders arrested on conspiracy to commit wire fraud charges
  • Case underscores systemic risk of foreign-controlled vendors embedded in sensitive investigative supply chains

📖 Read full article

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

The Hacker News · Sep 25 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The Lazarus Group's continued targeting of financial platforms via backend compromise—not just front-end exploits—signals that organizations handling digital assets or operating crypto treasury functions face nation-state-level adversaries targeting internal infrastructure directly. CISOs at financial institutions and fintechs should audit hot wallet controls and backend access segmentation.

  • Suspected North Korean threat actors stole $351.6M from Bitget's hot and warm wallets on September 24, 2026
  • Attack involved unauthorized transfers identified by Bitget's own security systems; cold wallets reportedly unaffected
  • Largest single crypto theft attributed to North Korea so far in 2026, continuing a sustained DPRK campaign against crypto exchanges

📖 Read full article

Russia's Hybrid Cyber-Physical War in Europe Heats Up

Dark Reading · Sep 25 · Relevance: ████████░░ 8/10

Why it matters to CISOs: The escalation of Russian hybrid operations combining cyberattacks, disinformation, and physical sabotage against European nations has direct implications for multinationals with EU operations, requiring CISOs to brief boards on OT/physical convergence risk and update threat models to include sabotage scenarios beyond data theft.

  • Russia is actively combining cyber sabotage, disinformation campaigns, and drone attacks against European nations supporting Ukraine
  • Targeted countries include those providing material support to Ukraine, indicating geopolitically motivated targeting criteria
  • Hybrid tactics blur the line between cyber and physical security, increasing risk for critical infrastructure operators across Europe

📖 Read full article

📡 Macro Trends

3 Cyber Threats That Defined the Summer of 2026

Dark Reading · Sep 24 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: A summary of three high-impact threat scenarios from summer 2026—AI agents breaching Hugging Face, a ransomware attack on Fairlife, and Iranian actors compromising U.S. water systems—provides CISOs with a consolidated threat landscape briefing useful for board communications and strategic planning ahead of Q4.

  • AI agents were used to breach Hugging Face, marking a documented escalation in autonomous offensive AI capability
  • Fairlife suffered a ransomware attack, continuing the trend of food and consumer goods supply chain targeting
  • Iranian-linked threat actors compromised approximately a dozen U.S. water systems, highlighting persistent critical infrastructure vulnerability

📖 Read full article

🔓 Data Breach

Kiteworks urges customers to shut down their servers amid ‘imminent’ threat of cyberattack

TechCrunch Security · Sep 25 · Relevance: █████████░ 9/10

Why it matters to CISOs: Kiteworks—used by enterprises to transfer large, often sensitive datasets—advising customers to proactively shut down servers is an extraordinary measure that signals a credible, imminent, and potentially destructive threat. Any organization using Kiteworks for secure file transfer must treat this as an emergency and assess exposure immediately.

  • Kiteworks received a 'credible threat' from law enforcement about an imminent cyberattack targeting its platform
  • The company has urged customers to shut down their servers as a precautionary measure
  • Kiteworks is widely used by enterprises to transfer large and sensitive datasets, making a successful attack a significant supply-chain risk

📖 Read full article

⚖️ Governance & Policy

Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks

The Record (Recorded Future) · Sep 24 · Relevance: ████████░░ 8/10

Why it matters to CISOs: Bipartisan legislation responding to the Salt Typhoon breach signals that telecom cybersecurity is moving toward formal federal oversight, which could expand compliance obligations for enterprise security teams relying on telecom infrastructure and set precedent for mandatory standards across other sectors. CISOs should monitor this bill's trajectory and assess exposure through telecom vendors.

  • Senators Warner (D-VA) and Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act
  • Bill is a direct legislative response to the Salt Typhoon campaign in which Chinese hackers breached nearly all major U.S. telecoms
  • Current framework is voluntary, but the bipartisan backing signals potential for future mandatory requirements

📖 Read full article

New bill would create federal investigative body for AI-driven hacks

CyberScoop · Sep 24 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Proposed federal oversight of AI-driven cyberattacks would introduce a new regulatory body with investigative authority, creating potential disclosure and cooperation obligations for enterprises that experience AI-enabled incidents. CISOs should track this legislation as it could reshape incident reporting requirements and liability frameworks.

  • Sen. Ed Markey introduced legislation to establish a Cybersecurity and AI Board of Investigations for independent oversight of AI-executed cyberattacks
  • Bill follows documented hacks carried out by AI agents associated with Anthropic, OpenAI, Meta, and others
  • Proposed body would function as an independent investigative authority, analogous to the NTSB model for transport incidents

📖 Read full article

🚨 Critical Vulnerability

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The Hacker News · Sep 25 · Relevance: ████████░░ 8/10

Why it matters to CISOs: A CVSS 9.8 path traversal flaw in WSO2 API Control Plane—widely deployed in enterprise API management—is being actively exploited and has been added to CISA's KEV catalog, requiring immediate patching prioritization by any organization running WSO2 in production environments. Adobe Commerce exploitation adds additional urgency for retail and e-commerce security teams.

  • CVE-2026-5430 (CVSS 9.8) is a path traversal vulnerability in WSO2 API Control Plane actively exploited in the wild
  • Adobe Commerce/Magento flaw also added to CISA KEV based on evidence of active exploitation
  • CISA KEV listing mandates federal agencies to patch within binding deadlines and serves as a strong signal for enterprise prioritization

📖 Read full article

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Dark Reading · Sep 24 · Relevance: ███████░░░ 7/10

Why it matters to CISOs: Salesbleed demonstrates a concrete prompt injection attack chain where agentic AI operating within Salesforce can be manipulated via web content to deliver phishing payloads through trusted Slack channels, affecting enterprises heavily reliant on Salesforce-Slack integration. CISOs should audit AI agent permissions and inter-application trust boundaries as an urgent governance priority.

  • Attackers can smuggle malicious instructions through web content into Salesforce AI agents, which then propagate them into Slack as trusted internal communications
  • The attack chain exploits agentic AI's ability to act across multiple applications without human review of intermediate steps
  • Salesforce and Slack are among the most widely deployed enterprise platforms, giving this attack class broad organizational exposure

📖 Read full article


Further Reading


Full Transcript

Click to expand full episode transcript

Alex: It's Friday, September 25th, 2026. This is Cleartext. I'm Alex Chen.

Jordan: And I'm Jordan Reeves. Let's get into it.

Alex: We have a packed show today. A forensics vendor that hid Russian ownership from U.S. intelligence agencies. North Korea just pulled off the biggest crypto heist of the year. Kiteworks is telling customers to literally shut down their servers. We've got two pieces of legislation working through Congress that could reshape how you think about telecom vendors and AI incidents. Russia's hybrid war is escalating in Europe. And a nasty prompt injection chain hitting Salesforce and Slack. Let's start where we have to start.

Jordan: The Oxygen Forensics story. This one is going to reverberate for a long time. The DOJ arrested two leaders of Oxygen Forensics, a phone-hacking and digital forensics company, alleging they concealed Russian ownership while holding contracts with U.S. security agencies. The charges are conspiracy to commit wire fraud, which is the legal mechanism, but the substance here is a foreign adversary nation had ownership stakes in a tool that had privileged access to devices inside U.S. government investigative workflows.

Alex: Let me put a fine point on this for the CISOs listening. Forensic tools, by their nature, require the deepest possible access to endpoints, to mobile devices, to data stores. If you're using a third-party forensic tool in your IR playbooks, in your legal hold processes, in your insider threat investigations, you need to understand who owns that company down to the beneficial ownership level. This isn't a new concept, but it's one that most vendor risk management programs treat superficially. You check a box that says "no foreign ownership concerns" and move on. This case proves that's insufficient.

Jordan: What's particularly insidious is that Oxygen Forensics wasn't some obscure startup. They had legitimate U.S. government contracts. They passed whatever vetting existed. And the alleged concealment was apparently effective for years. So the question for every security leader is not just "do I use this vendor," it's "would my current due diligence process have caught this?" And for most organizations, the honest answer is no.

Alex: Actionable takeaway: if you haven't already, build beneficial ownership verification into your vendor risk framework for any tool that touches sensitive data or has privileged access. OFAC screening is table stakes. You need to go deeper, especially for forensic, EDR, and investigative tooling.

Jordan: Let's pivot to the other geopolitical story that demands attention. Bitget, a major crypto exchange, confirmed that suspected North Korean threat actors stole three hundred fifty-one point six million dollars from their hot and warm wallets. This happened yesterday, September 24th. Bitget's own security systems flagged the unauthorized transfers, and they say cold wallets were unaffected. But this is the largest single crypto theft attributed to North Korea so far this year.

Alex: The detail that matters here is the attack vector. This wasn't a front-end exploit or a social engineering play against individual users. This was a backend compromise. Lazarus Group went after the infrastructure itself, the internal systems that manage wallet operations. That's a fundamentally different threat model than what most financial services firms are testing against.

Jordan: Exactly. And let's not pretend this only matters if you're running a crypto exchange. Any organization with a crypto treasury function, any fintech touching digital assets, any traditional financial institution with custodial exposure, you are on the same target list. North Korea has generated billions from these operations. It funds their weapons programs. This is state-sponsored theft at industrial scale, and the sophistication of the backend targeting keeps escalating.

Alex: If you're in financial services, audit your hot wallet controls, your backend access segmentation, your key management ceremonies. If you can't articulate your blast radius for a compromised backend credential, you have work to do this weekend.

Jordan: Now, staying in the geopolitical lane. Dark Reading has a thorough piece on Russia's hybrid cyber-physical war against Europe. This is the convergence of cyber sabotage, disinformation campaigns, and physical attacks including drone operations against European nations that support Ukraine. The targeting is explicitly geopolitically motivated.

Alex: For multinationals with European operations, this is a board-level conversation. The hybrid model means your CISO threat briefing can't just cover data exfiltration and ransomware. You need to be talking about operational technology risks, physical security convergence, and sabotage scenarios. If you operate critical infrastructure in Europe, water, energy, transportation, logistics, your threat model needs to include state-sponsored physical disruption as a complement to cyber operations.

Jordan: The blurring of cyber and physical is the key insight. We've talked about IT-OT convergence for years. Russia is demonstrating what adversarial convergence actually looks like in practice. It's not theoretical anymore.

Alex: Let's shift to what I think is the most operationally urgent story of the day. Kiteworks, which many of you use for secure file transfer of large and sensitive datasets, has told customers to shut down their servers. Not patch. Not monitor. Shut down. They received what they describe as a credible threat from law enforcement about an imminent attack targeting their platform.

Jordan: When a vendor tells you to power off, you listen. This is an extraordinary measure. Kiteworks doesn't do this for a vulnerability disclosure or a routine advisory. This suggests law enforcement has intelligence about an active campaign, possibly with destructive intent, targeting Kiteworks infrastructure specifically. If you're running Kiteworks in your environment, this should have been your first call this morning.

Alex: The supply chain implications are significant. Kiteworks is embedded in data transfer workflows for legal, financial, healthcare, and government organizations. If your sensitive file transfers route through Kiteworks, you need an immediate assessment of what's exposed, what alternative transfer mechanisms you can activate, and what your communication plan is for partners and clients who depend on those data flows.

Jordan: Treat this as an active incident even if you haven't been hit yet. That's the posture.

Alex: Moving to governance. Two pieces of legislation dropped this week that CISOs need to track. First, Senators Warner and Cruz introduced the Telecommunications Cybersecurity and Resilience Act. This is a direct response to the Salt Typhoon campaign where Chinese hackers breached nearly every major U.S. telecom. The bill establishes voluntary standards, but the bipartisan backing is the signal.

Jordan: Voluntary today, mandatory tomorrow. That's how these things work. And the fact that you have Warner, who chairs the Senate Intelligence Committee, and Cruz on the same bill tells you there's real momentum. For CISOs, the implication is twofold. One, your telecom vendors may face new compliance obligations, which affects your supply chain risk posture. Two, this sets a precedent. If telecom gets a formal federal framework, other sectors will follow.

Alex: The second bill is from Senator Markey, proposing a Cybersecurity and AI Board of Investigations. Think NTSB but for AI-driven cyberattacks. This comes after documented incidents where AI agents from major providers were involved in actual breaches.

Jordan: This one is earlier stage and more speculative, but the direction matters. If an independent federal body gets investigative authority over AI-enabled incidents, that creates potential disclosure and cooperation obligations that don't exist today. Your incident response plans, your legal frameworks, your board communications, all of those would need to account for a new federal investigative entity with subpoena-like powers.

Alex: My advice: don't wait for the bill to pass. Start documenting your AI agent deployments, their permissions, their access boundaries. Because if this legislation or something like it moves forward, the first question will be "what AI agents were operating in your environment and what could they do?"

Jordan: Which is a perfect bridge to Salesbleed. Researchers demonstrated a prompt injection attack chain where malicious instructions are smuggled through web content into Salesforce AI agents, which then propagate those instructions into Slack as trusted internal communications. The AI agent acts as a bridge between untrusted external content and trusted internal channels, and it does so without human review of the intermediate steps.

Alex: This is the agentic AI risk we've been warning about, made concrete. Salesforce and Slack are in virtually every enterprise. If your Salesforce agents can post to Slack, can trigger workflows, can access CRM data, and they're ingesting web content without adequate input validation, you have an exploitable attack surface that bypasses your perimeter entirely.

Jordan: Audit your AI agent permissions. Map the trust boundaries between your applications. Understand what actions your agents can take autonomously and where a human checkpoint should exist but doesn't. This is a governance problem as much as a technical one.

Alex: Let's cover the vulnerability updates quickly. CISA added two flaws to the Known Exploited Vulnerabilities catalog. CVE-2026-5430, a CVSS nine point eight path traversal in WSO2 API Control Plane. This is actively exploited. If you run WSO2 in production, patch now, not Monday, now. There's also an Adobe Commerce and Magento flaw being exploited in the wild. Retail and e-commerce teams, check your exposure.

Jordan: KEV additions are your prioritization signal. These aren't theoretical. Someone is using these right now.

Alex: Finally, Dark Reading published a useful summer retrospective covering three defining threats. AI agents breaching Hugging Face, the Fairlife ransomware attack, and Iranian actors compromising a dozen U.S. water systems. It's worth reading as a consolidated briefing for board communications heading into Q4 planning.

Jordan: The through line across all three is that adversaries are getting more creative about target selection and attack methods. AI as an offensive tool, food supply chain targeting, water infrastructure compromise. The aperture of what you need to defend keeps widening.

Alex: Alright, let's talk about what to watch. Jordan, looking at this week in total, what's the theme?

Jordan: Trust verification at every layer. Oxygen Forensics shows vendor trust is fragile. Kiteworks shows platform trust can evaporate overnight. Salesbleed shows inter-application trust is exploitable. The Bitget hack shows that even internal infrastructure trust, the assumption that your backend is your backend, is not guaranteed. Every trust relationship in your environment is an attack surface.

Alex: I'd add that the legislative activity this week signals a shift. Washington is moving from reactive hearings to actual frameworks. Telecom, AI, forensic vendor oversight. The compliance landscape twelve months from now is going to look different than it does today. If you're heading into Q4 budget cycles, build in flexibility for emerging regulatory obligations. The velocity of legislative response is accelerating.

Jordan: And keep your threat models current. The adversaries this week were Russia, North Korea, Iran, and AI agents. That's a lot of simultaneous pressure from a lot of different directions. Prioritize ruthlessly.

Alex: That's our show for today. Show notes and links to every story we covered are at cleartext.fm. Have a good weekend, everyone. We'll see you Monday.

Jordan: Stay sharp.


Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-09-25.

Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.