0:00
From the CISO series, it's Cybersecurity Headlines.
0:06
These are the Cybersecurity Headlines for Wednesday, March 11th, 2026. I'm Rich Truffalino.
0:12
NSA and Cybercommand had confirmed. In a rare floor vote, the US Senate voted 71-29 to confirm
0:19
Army Lieutenant General Joshua Rudd as the head of US Cybercommand and Director of the
0:24
National Security Agency. The post had been vacant for almost a year, with Lieutenant
0:28
General William Hartman serving in an acting capacity. Rudd currently serves as the deputy
0:33
chief of US Indo-Pacific Command and previously as held jobs in Special Forces leadership.
0:39
He has no prior experience in signals intelligence or cyber operations. Rudd will continue the
0:44
dual-hat leadership of Cybercommand and the NSA, with the record sources saying President
0:49
Trump told AIDS he settled on a clean 18-month extension for the leadership format. Senator
0:55
Ron Wyden called for the floor vote as part of his opposition to Rudd's nomination, signing
1:00
his lack of experience, and vague answers about using the NSA's surveillance tools for warrantless
1:04
spying on US citizens.
1:07
Russians targeting encrypted messaging app users. The Netherlands Defense Intelligence and Security
1:12
Service and the General Intelligence and Security Service published details about a campaign
1:17
by entities tied to Russian state actors, targeting users of signal and WhatsApp. This didn't
1:22
crack either apps end-to-end encryption. Instead, Dutch intelligence saw signal users targeted
1:27
by people posing as the app's support team, warning specific users about data leaks and
1:32
trying to get their pin codes. These codes could be used to register into device and intercept
1:37
new messages. On WhatsApp, the attacks tried to trick people into using the link device
1:41
feature to gain access to all messages.
1:45
OpenAI rolls out vulnerability scanner. It was big news when Anthropic rolled out
1:50
vulnerability scanning in Claude code, and so it's a big deal when OpenAI did the same
1:54
now with Codex. Codex Security was previously known as ARDVARC in private beta testing since
2:00
last year, and now available as a research preview to chat GPT-Pro, Enterprise, Business,
2:06
and EDU customers. In testing, OpenAI said it found over 10,000 high-severity issues with
2:11
Codex Security, including in widely used projects like Chromium, Open SSL, PHP, and GNU TLS.
2:19
Anthropics announcement had stock market implications, mostly of that become as part of the story,
2:23
with Codex Security.
2:25
Fins warned of persistent cyber espionage. According to a new security assessment from the
2:30
Finnish security and intelligence service, the country's tech sector, government, and
2:34
research institutions faced sustained operations from Russian and Chinese intelligence services.
2:39
The assessment painted a bleak picture, stating that the country faces continual attempts
2:43
at cyber espionage with no prospect of such operations subsiding, even in the long term.
2:50
These attacks are attempting to steal sensitive research and intellectual property, supplement
2:54
traditional espionage efforts that were scuttled after Finland expelled Russian diplomats,
2:58
and spreading misinformation as part of larger influence operations.
3:04
And now thanks to today's episode sponsor, Dropzone AI. Remember yesterday's 3AM thread
3:09
intel? Here is how it plays out with Dropzone AI.
3:13
The Threat Intelligence Drops. Dropzone picks it up, turns it into a thread hunt, and
3:18
runs it across your SIM, EDR, and cloud data while your team sleeps. By morning, your analysts
3:24
have answers, not a backlog. That is the AI Threat Hunter, the newest agent on the team,
3:30
debuting at RSAC, Booth 455, South Expo Hall. To learn more, head on over to Dropzone.ai.
3:40
Meta acquires moldbook. You'll be forgiven if you've already forgotten about the AI flavor
3:45
of the week that was moldbook. This was a Reddit clone designed for use by AI agents created
3:50
by Matt Schlicht and Ben Par. Well, Meta didn't forget them, acquiring the platform and
3:55
the team behind it in an undisclosed deal. Schlicht and Par will roll into Meta's super
4:00
intelligence labs unit on March 16th, with moldbook itself shutting down around the same time.
4:06
Book was notable in that it left its production database completely exposed at launch, revealing
4:10
that a large number of accounts were created by just a few users, and that it had no system
4:14
for verifying if users were actually bots. This comes a month after open-call creator Peter
4:19
Steinberger was hired by OpenAI.
4:23
Cadnap Botnet targeting ASUS routers. Researchers at Black Lotus Labs detailed the newly discovered
4:29
Cadnap Botnet active since August 2025. This currently has about 14,000 of world devices
4:35
communicating through a customized version of the Cadem Lea distributed hash table protocol
4:40
to conceal IP addresses. About half the botnet is made of ASUS routers, with 60% of all
4:46
infected devices in the US. Cadnap spreads through a malicious script that establishes persistence
4:52
on routers and edge devices as a cron job that runs every 55 minutes. The researchers
4:57
believe Cadnap is tied to the doppelganger proxy service.
5:02
Cloud rolls out PASCII support for Entra. Microsoft says it will allow users to create device
5:07
bound PASCII stored in the Windows Hello container and authenticate using Windows Hello.
5:12
Each Entra account will register a PASCII per device with support for multiple accounts
5:16
per machine. These keys will be device bound and not synced. PASCII support will go into
5:22
a opt-in global public preview in mid-March and run through the end of April. After that
5:27
it will roll out to government cloud environments starting in mid-April through mid-May.
5:32
CESA shortens patch time for critical bugs. Generally when CESA adds a vulnerability to its
5:37
known exploited vulnerabilities catalog, federal civilian agencies have three weeks to patch.
5:42
However, the latest round of additions have been given tighter deadlines.
5:46
On Monday, CESA added a critical vulnerability for SolarWinds web help desk first discovered
5:51
by trend micro back in September and has since been actively exploited.
5:55
Agencies have until Thursday March 12th to patch. CESA also added two vulnerabilities this week
6:00
with a shorter two week patch deadline, one of which impacts Avanti EPM and reportedly has been
6:05
actively exploited since February. Are you subscribed to the CESO series YouTube channel?
6:11
You're not? Well, it's not too late. Just search for CESO series on YouTube. You'll find us.
6:16
There, you'll see clips from all of our shows, original shorts and interviews,
6:20
product demos, and the latest updates from the CESO series. Be sure to subscribe
6:25
so you don't miss a thing. And if you're in the San Diego area, be sure to join us for our
6:30
San Diego Cyber Group Meetup today, March 11th. You'll get to meet David Spark,
6:35
fellow CESO series fans, and maybe even get some sweet CESO series swag.
6:40
Full details are on our events page at CESO series dot com. Check it out if you're interested
6:44
in coming. And if you have any thoughts about the news from today or about the show in general,
6:49
be sure to reach out to us at feedback at CESO series dot com. We'd love to hear from you.
6:53
Reporting for the CESO series, I'm Rich Drafolino reminding you to have a super sparkly day.