<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 3/6/2026

SHARE

Top News

FBI targeted with 'suspicious' activity on its networks

The FBI found evidence that its networks had been targeted in a suspected cybersecurity incident, the bureau confirmed on Thursday, without sharing any further details. "The FBI identified and addressed suspicious activities on FBI networks, and we have leveraged all technical capabilities to respond," the agency said in a statement. "We have nothing additional to provide." CNN and CBS reported that the suspicious activity targeted a digital system the FBI uses to manage and conduct surveillance READ MORE...


Iran intelligence backdoored US bank, airport, software outfit networks

An Iranian cyber crew believed to be part of the Iranian Ministry of Intelligence and Security (MOIS) has been embedded in multiple US companies' networks - including a bank, software firm, and airport, among others - since the beginning of February, with more activity in the days following the US and Israeli military strikes, according to security researchers. Symantec and Carbon Black's threat hunting team uncovered the network activity after a third-party shared indicators of compromise. READ MORE...


Workers report watching Ray-Ban Meta-shot footage of people using the bathroom

Meta's approach to user privacy is under renewed scrutiny following a Swedish report that employees of a Meta subcontractor have watched footage captured by Ray-Ban Meta smart glasses showing sensitive user content. The workers reportedly work for Kenya-headquartered Sama and provide data annotation for Ray-Ban Metas. The February report is based on interviews with over 30 employees at Sama, including several people who work with video, image, and speech annotation for Meta's AI systems. READ MORE...

Breaches

Cyberattack on Mexico's Gov't Agencies Highlight AI Threat

For any cyber-defender continuing to deny the impact of AI on attacker efficiency, welcome to Exhibit A. Over the past few months, a small group of hacktivists compromised the computers and networks of at least nine Mexican government agencies, stealing more than 195 million identities and tax records, along with vehicle registrations, and more than 2.2 million property records, startup Gambit Security stated in a blog post this week that detailed the attack. READ MORE...

Hacking

Chinese state hackers target telcos with new malware toolkit

A China-linked advanced persistent threat actor tracked as UAT-9244 has been targeting telecommunication service providers in South America since 2024, compromising Windows, Linux, and network-edge devices. According to Cisco Talos researchers, the adversary is closely associated with the FamousSparrow and Tropic Trooper hacker groups, but is tracked as a separate activity cluster. This assessment has high confidence and is based on similar tooling, tactics, techniques, and procedures (TTPs). READ MORE...

Software Updates

March 2026 Patch Tuesday forecast: Is AI security an oxymoron?

Developers and analysts are using more AI tools to produce code and to test both the performance and security of the finished products. They are also embedding AI functionality in their products directly. But just how secure are these AI tools and routines themselves? Recent reports show they suffer from vulnerabilities just like any other code. For example, Google recently provided an update for CVE-2026-0628, associated with Gemini AI implemented in the Chrome browser. READ MORE...

Malware

Wikipedia hit by self-propagating JavaScript worm that vandalized pages

The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began modifying user scripts and vandalizing Meta-Wiki pages. Editors first reported the incident on Wikipedia's Village Pump (technical), where users noticed a large number of automated edits adding hidden scripts and vandalism to random pages. Wikimedia engineers temporarily restricted editing across projects while they investigated the attack and began reverting changes. READ MORE...


Beware of fake OpenClaw installers, even if Bing points you to GitHub

Attackers are abusing OpenClaw's popularity by seeding fake "installers" on GitHub, boosted by Bing AI search results, to deliver infostealers and proxy malware instead of the AI assistant users were looking for. OpenClaw is an open-source, self-hosted AI agent that runs locally on your machine with broad permissions: it can read and write files, run shell commands, interact with chat apps, email, calendars, and cloud services. READ MORE...

Exploits/Vulnerabilities

Cisco reveals 2 max-severity defects in firewall management software

Cisco released information on a pair of max-severity vulnerabilities in its firewall management software Wednesday that unauthenticated, remote attackers could exploit to obtain the highest level of access to the underlying operating system or on affected devices. The vulnerabilities - CVE-2026-20079 and CVE-2026-20131 - affect the web-based interface of Cisco Secure Firewall Management Center (FMC) Software, regardless of device configuration, the vendor said. READ MORE...


Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks

An old vulnerability affecting industrial control system (ICS) products from Rockwell Automation has been exploited in attacks, according to the vendor and the cybersecurity agency CISA. CISA added the flaw, tracked as CVE-2021-22681, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, instructing federal agencies to address it by March 26. The security hole affects the Studio 5000 Logix Designer software and several Logix programmable logic controllers (PLCs). READ MORE...

On This Date

  • ...In 1896, Charles King tested his automobile on the streets of Detroit, becoming the first person to drive a car in the Motor City.
  • ...in 1899, German company Bayer registers a trademark for its first major product: "Aspirin."
  • ...in 1917, cartoonist and graphic novelist Will Eisner ("The Spirit", "A Contract With God") is born in Brooklyn, NYC.
  • ...in 1972, basketball great (and former movie genie) Shaquille O'Neal is born in Newark, NJ.