
New Cyber Command chief, Russia targets Signal, Codex Security
About this episode
NSA and Cyber Command head confirmed
Russians targeting encrypted messaging app users
OpenAI rolls out vulnerability scanner
Get links to all the stories in our show notes: https://cisoseries.com/cybersecurity-news-march-11-2026/
Huge thanks to our sponsor, Dropzone AI
Get every episode summarized
Each time Cybersecurity Headlines publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
83 searchable segments. Every word is indexed and playable.
Full transcript
Cybersecurity Headlines — New Cyber Command chief, Russia targets Signal, Codex Security. Machine-transcribed; use the interactive transcript above to jump the player to any line.
From the CISO series, it's Cybersecurity Headlines. These are the Cybersecurity Headlines for Wednesday, March 11th, 2026. I'm Rich Truffalino. NSA and Cybercommand had confirmed. In a rare floor vote, the US Senate voted 71-29 to confirm Army Lieutenant General Joshua Rudd as the head of US Cybercommand and Director of the National Security Agency. The post had been vacant for almost a year, with Lieutenant General William Hartman serving in an acting capacity. Rudd currently serves as the deputy chief of US Indo-Pacific Command and previously as held jobs in Special Forces leadership. He has no prior experience in signals intelligence or cyber operations. Rudd will continue the dual-hat leadership of Cybercommand and the NSA, with the record sources saying President Trump told AIDS he settled on a clean 18-month extension for the leadership format. Senator Ron Wyden called for the floor vote as part of his opposition to Rudd's nomination, signing
his lack of experience, and vague answers about using the NSA's surveillance tools for warrantless spying on US citizens. Russians targeting encrypted messaging app users. The Netherlands Defense Intelligence and Security Service and the General Intelligence and Security Service published details about a campaign by entities tied to Russian state actors, targeting users of signal and WhatsApp. This didn't crack either apps end-to-end encryption. Instead, Dutch intelligence saw signal users targeted by people posing as the app's support team, warning specific users about data leaks and trying to get their pin codes. These codes could be used to register into device and intercept new messages. On WhatsApp, the attacks tried to trick people into using the link device feature to gain access to all messages. OpenAI rolls out vulnerability scanner. It was big news when Anthropic rolled out vulnerability scanning in Claude code, and so it's a big deal when OpenAI did the same now with Codex. Codex Security was previously known as ARDVARC in private beta testing since
last year, and now available as a research preview to chat GPT-Pro, Enterprise, Business, and EDU customers. In testing, OpenAI said it found over 10,000 high-severity issues with Codex Security, including in widely used projects like Chromium, Open SSL, PHP, and GNU TLS. Anthropics announcement had stock market implications, mostly of that become as part of the story, with Codex Security. Fins warned of persistent cyber espionage. According to a new security assessment from the Finnish security and intelligence service, the country's tech sector, government, and research institutions faced sustained operations from Russian and Chinese intelligence services. The assessment painted a bleak picture, stating that the country faces continual attempts at cyber espionage with no prospect of such operations subsiding, even in the long term. These attacks are attempting to steal sensitive research and intellectual property, supplement traditional espionage efforts that were scuttled after Finland expelled Russian diplomats, and spreading misinformation as part of larger influence operations.
And now thanks to today's episode sponsor, Dropzone AI. Remember yesterday's 3AM thread intel? Here is how it plays out with Dropzone AI. The Threat Intelligence Drops. Dropzone picks it up, turns it into a thread hunt, and runs it across your SIM, EDR, and cloud data while your team sleeps. By morning, your analysts have answers, not a backlog. That is the AI Threat Hunter, the newest agent on the team, debuting at RSAC, Booth 455, South Expo Hall. To learn more, head on over to Dropzone.ai. Meta acquires moldbook. You'll be forgiven if you've already forgotten about the AI flavor of the week that was moldbook. This was a Reddit clone designed for use by AI agents created by Matt Schlicht and Ben Par. Well, Meta didn't forget them, acquiring the platform and the team behind it in an undisclosed deal. Schlicht and Par will roll into Meta's super intelligence labs unit on March 16th, with moldbook itself shutting down around the same time.
Book was notable in that it left its production database completely exposed at launch, revealing that a large number of accounts were created by just a few users, and that it had no system for verifying if users were actually bots. This comes a month after open-call creator Peter Steinberger was hired by OpenAI. Cadnap Botnet targeting ASUS routers. Researchers at Black Lotus Labs detailed the newly discovered Cadnap Botnet active since August 2025. This currently has about 14,000 of world devices communicating through a customized version of the Cadem Lea distributed hash table protocol to conceal IP addresses. About half the botnet is made of ASUS routers, with 60% of all infected devices in the US. Cadnap spreads through a malicious script that establishes persistence on routers and edge devices as a cron job that runs every 55 minutes. The researchers believe Cadnap is tied to the doppelganger proxy service. Cloud rolls out PASCII support for Entra. Microsoft says it will allow users to create device
bound PASCII stored in the Windows Hello container and authenticate using Windows Hello. Each Entra account will register a PASCII per device with support for multiple accounts per machine. These keys will be device bound and not synced. PASCII support will go into a opt-in global public preview in mid-March and run through the end of April. After that it will roll out to government cloud environments starting in mid-April through mid-May. CESA shortens patch time for critical bugs. Generally when CESA adds a vulnerability to its known exploited vulnerabilities catalog, federal civilian agencies have three weeks to patch. However, the latest round of additions have been given tighter deadlines. On Monday, CESA added a critical vulnerability for SolarWinds web help desk first discovered by trend micro back in September and has since been actively exploited. Agencies have until Thursday March 12th to patch. CESA also added two vulnerabilities this week with a shorter two week patch deadline, one of which impacts Avanti EPM and reportedly has been actively exploited since February. Are you subscribed to the CESO series YouTube channel?
You're not? Well, it's not too late. Just search for CESO series on YouTube. You'll find us. There, you'll see clips from all of our shows, original shorts and interviews, product demos, and the latest updates from the CESO series. Be sure to subscribe so you don't miss a thing. And if you're in the San Diego area, be sure to join us for our San Diego Cyber Group Meetup today, March 11th. You'll get to meet David Spark, fellow CESO series fans, and maybe even get some sweet CESO series swag. Full details are on our events page at CESO series dot com. Check it out if you're interested in coming. And if you have any thoughts about the news from today or about the show in general, be sure to reach out to us at feedback at CESO series dot com. We'd love to hear from you. Reporting for the CESO series, I'm Rich Drafolino reminding you to have a super sparkly day.
More episodes
More from Cybersecurity Headlines

Passkey phishing attack, Anthropic's blockbuster report, airline cybersecurity l...
Cybersecurity Headlines

The Department of Know: Liquid drained, CISA urges change, agentic whistleblower...
Cybersecurity Headlines

NetScaler vulnerability exploited, AdaptHealth suffers breach, new Android malwa...
Cybersecurity Headlines

Fortinet auth holes, China distills AI, Mythos vulnerability
Cybersecurity Headlines
