Skip to content
TrackPodcasts
newsMar 12, 20267:09

Meta apps offer new scam protection, Google's Wiz acquisition finalized, China curbs state-run OpenClaw use

About this episode

Meta apps offer new scam protection

Google's Wiz acquisition finalized

China curbs state-run OpenClaw use

Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-meta-offers-scam-protection-googles-wiz-acquisition-finalized-china-curbs-openclaw-use/

Huge thanks to our sponsor, Dropzone AI

Here is something worth asking any AI security vendor you meet at RSAC. 
 
Can you show me exactly what your AI did? Not just the verdict. The reasoning. Every tool it queried, every piece of evidence, every step it took to get there.
 
Most cannot. Dropzone AI can. Every investigation is fully transparent. You do not have to trust the AI. You can verify it. 
 
See it for yourself at Booth 455. dropzone.ai/rsa-2026-ai-diner
 

Get every episode summarized

Each time Cybersecurity Headlines publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

107 searchable segments. Every word is indexed and playable.

Meta apps offer new scam protection, Google's Wiz acquisition finalized, China curbs state-run OpenClaw use

Cybersecurity Headlines

0:00
7:09

Full transcript

Cybersecurity HeadlinesMeta apps offer new scam protection, Google's Wiz acquisition finalized, China curbs state-run OpenClaw use. Machine-transcribed; use the interactive transcript above to jump the player to any line.

From the CISO series, it's Cybersecurity Headlines. These are the Cybersecurity Headlines for Thursday, March 12, 2026. I'm Sarah Lane. MetaApps offer new scam protection. Meta is adding new scam detection features across Facebook, Messenger and WhatsApp to warn users about suspicious activity before interaction. The updates include alerts for unusual device linking attempts on WhatsApp, warnings for suspicious friend requests on Facebook, and expanded AI-based scam detection on Messenger that can review chats for common fraud patterns. This is all meant to help users identify and block potential scams before they become a problem. Google's Wiz acquisition finalized. Google completed its $32 billion all-cash acquisition of Cloud Security Startup Wiz, the largest deal in Google's history. Wiz will join Google Cloud but continue supporting multiple platforms,

including AWS, Azure and Oracle Cloud as its own multi-cloud security provider. The deal closed after US and EU regulatory approval. Wiz surpassed $1 billion in annual recurring revenue in 2025. China curbs state-run open-claw use. Chinese authorities have barred state-run enterprises and government agencies, including major banks, from installing open-claw AI on office computers or personal devices connected to company networks due to security risks. Open-claw is an agentic AI platform that autonomously manages tasks and accesses private data, raising some concerns over external communications and rogue behavior. Some employees and military families face restrictions, while other notices require prior approval. Chinese tech firms like Tencent, Alibaba, and Minimax continue promoting open-claw apps. SESA orders N8N RCE-FLAW-PATCH. SESA has directed US federal agencies

to patch or remote code execution vulnerability in the N8N workflow automation platform, actively exploited in attacks. The FLAW allows authenticated attackers to execute arbitrary code, potentially exposing sensitive data such as API keys, database credentials, and CICD secrets. N8N patched the issue back in December, but shadow server reports over 40,000 unpatched instances online. Federal agencies have to remediate by March 25th, but SESA urges all organizations to secure their N8N deployments immediately. Huge thanks to our sponsor DropZoneAI. Here's something worth asking any AI security vendor you might meet at RSAC. Can you show me exactly what your AI did? Not just the verdict, the reasoning. Every tool that it queried, every piece of evidence, every step it took to get there. Most can. DropZoneAI can.

Every investigation is fully transparent. You don't have to trust the AI, you can verify it. See it for yourself at booth455 and learn more at dropzone.ai-rsa-20206-AI-diner. Comet AI browser tricked into Fishing Scam. Researchers have shown that agentic AI browsers, like perplexity's Comet, can be manipulated into Fishing Scams in minutes by exploiting how the AI reasons and narrates its actions. Guardio Researcher Shekhead Chen described this as agentic blabbering, where the AI exposes its observations and plans, allowing attackers to train malicious pages to bypass defenses. Stav Cohen explained intent collusion, where user requests merge with attacker instructions, enabling hidden commands to execute. Related work from Trail of Bits and Zenity Labs demonstrated prompt injections and zero click attacks to exfiltrate data like Gmail content

and one password credentials. France's National Cybersecurity Agency sees ransomware drop. The French Cybersecurity Agency, also notice ANC or ANSSI, reported 128 ransomware attacks in 2025. That's down from 141 in 2024, partly due to law enforcement operations like Operation Endgame. SMBs remained the main targets. Healthcare and education sectors saw the largest year-over-year increase. Chilean Akira and Lockbit 3.0 Lockbit Black were the most common strains, with new variants also observed. Overall cyber incidents stayed stable at 1,366 confirmed cases. Data exfiltration claims Rose and DDoS attacks declined. Striker offline after Wiper malware attack. Medtech company Striker is offline after a Wiper malware attack claimed by Hendala and Iranian-linked pro-Palestinian activist group.

The attackers say they stole 50 terabytes of data and wiped over 200,000 systems, servers, and mobile devices, affecting offices in 79 countries. Staff reported losing both corporate and personal device data. Internal services and applications were also disrupted, forcing some teams to revert to manual workflows. Hendala, linked to Iran's Ministry of Intelligence and Security, has targeted Israeli organizations since December of 2025 with destructive malware. Leaky Looker found in Google Looker Studio. Tenable researchers uncovered nine vulnerabilities in Google Looker Studio, dubbed Leaky Looker, that could have let attackers extract or manipulate sensitive cloud data. The flaws affected SQL connectors, authentication, and report sharing features, allowing zero-click attacks using report-owner credentials and one-click attacks targeting viewers. Services at risk include BigQuery, Spanner, PostgreSQL, MySQL, Google Sheets, and Cloud Storage.

Google patched the platform globally with no customer action required. Security tools are supposed to solve problems and make our lives easier. So why does it seem like they're doing the opposite and creating more work? That's what we're trying to answer on this week's episode of Defense in Depth. Look for the episode, are your security tools creating more work for your team, wherever you get your podcasts? If you have thoughts on the news from today, or about our show in general, be sure to reach out to us at Feedback at CISOSeries.com. We want to hear from you. I am Sarah Lane reporting for the CISOS series. Thank you for listening, and we'll talk to you tomorrow. Cybersecurity headlines are available every weekday. Head to CISOSeries.com for the full stories behind the headlines.

More episodes

More from Cybersecurity Headlines

View all episodes →