Seedworm Targeting Networks of Multiple U.S. Companies

Plus, Trump calls for more aggressive responses to cyber-attacks.

SPONSORED BY

Good morning (West Coast edition)! Here’s what’s up.

People

James “Aaron” Bishop has been named Deputy CIO for Cybersecurity and Chief Information Security Officer for the U.S. Department of War (DoW).

Clips ✂️

Seedworm: Iranian APT on Networks of U.S. Bank, Airport, Software Company

The Iranian APT group Seedworm (aka MuddyWater, Temp Zagros, Static Kitten) has been active on the networks of multiple U.S. companies since the beginning of February 2026, with activity continuing in recent days following U.S. and Israeli military strikes on Iran that have sparked conflict in the region.

A U.S. bank, software company and airport, and non-governmental organizations in both the U.S. and Canada, have experienced suspicious activity on their networks in recent days and weeks. The software company is a supplier to the defense and aerospace industries among others, and has a presence in Israel, with the company’s Israel operation seeming to be the target in this activity.

A previously unknown backdoor, which we have named Dindoor, was found on the networks of the Israeli outpost of this software company, with the same backdoor seen on the networks of a U.S. bank and the Canadian non-profit organization. This backdoor leverages Deno, the secure runtime for JavaScript and TypeScript, to execute. This backdoor was signed with a certificate issued to “Amy Cherne.”

by Security.com

Trump calls for more aggressive responses to cyberattacks in long-awaited cyber strategy

The era of quiet responses to cyberattacks against U.S. networks is over.

The White House on Friday released its long-awaited National Cyber Strategy, laying out in plain terms the Trump administration’s intention to “deploy the full suite of U.S. government defensive and offensive cyber operations” to erode adversary capabilities and “raise the costs for their aggression.”

An accompanying executive order describes how the U.S. plans to more aggressively target transnational cybercrime groups across the departments of State, Justice and Homeland Security.

But absent from the text of both documents are direct mentions of China and Russia — Washington’s main cyber foes.

The document marks a shift from past cyber strategies released under both the first Trump administration and the Biden administration, with an emphasis on prioritizing cyber offensive measures. By contrast, the Biden administration’s cyber strategy sought to use regulation to nudge companies to write more secure code and shift the burden of cyber defense from small companies to major tech providers.

by Politico

HHS adds cybersecurity guidance to healthcare sector self-assessment tool

Healthcare organizations can take advantage of new cybersecurity guidance from the federal government that will help them assess their practices and identify risks.

The Department of Health and Human Services (HHS) on Thursday released an updated version of its Risk Identification and Site Criticality (RISC) toolkit that assesses organizations against the latest NIST Cybersecurity Framework and HHS’s own Cybersecurity Performance Goals.

The new cybersecurity module “will help our partners understand what is needed to strengthen their resilience and we strongly encourage them to take advantage of it,” John Knox, HHS’s principal deputy assistant secretary for preparedness and response, said in a statement.

RISC 2.0 “can compare multiple facilities across systems, coalitions, and regions to identify dependencies and interdependencies in a consistent, repeatable way,” HHS said on the toolkit’s website.

The department said more than 3,500 healthcare organizations are already using the service.

by Cybersecurity Dive

How AI Assistants are Moving the Security Goalposts

AI-based assistants or “agents” — autonomous programs that have access to the user’s computer, files, online services and can automate virtually any task — are growing in popularity with developers and IT workers. But as so many eyebrow-raising headlines over the past few weeks have shown, these powerful and assertive new tools are rapidly shifting the security priorities for organizations, while blurring the lines between data and code, trusted co-worker and insider threat, ninja hacker and novice code jockey.

The new hotness in AI-based assistants — OpenClaw (formerly known as ClawdBot and Moltbot) — has seen rapid adoption since its release in November 2025. OpenClaw is an open-source autonomous AI agent designed to run locally on your computer and proactively take actions on your behalf without needing to be prompted.

by Krebs on Security

Consulting Firms Say AI Agents Are Upending the Company Org Chart - Business Insider

Every few years, corporate executives call for a "Great Flattening," arguing that their organizations have grown sluggish from the weight of over management, duplicate roles, and bureaucracy.

Back in 2023, Meta CEO Mark Zuckerberg coined one of the tech industry's favorite tongue twisters when he said at a company Q&A session that he didn't want to see a management structure governed by "managers managing managers, managing managers, managing managers, managing the people who are doing the work."

That year he cut 10,000 workers from the company's ranks. Other companies followed suit. Later that year, Citi announced plans to cut its 13 layers of management to 8. By January 2024, UPS had begun eliminating 12,000 of its 85,000 managers.

Now, as AI unleashes waves of digital agents into the workforce, consulting firms are predicting a new wave of delayering and organizational change.

by Business Insider

Only 30 minutes per quarter on cyber risk: Why CISO-board conversations are falling short

Cybersecurity is, as it should be in this era of AI-driven cyberattacks, a regular item on enterprise board agendas. However, the ways in which CISOs and boards interact, and the depth of those discussions, remain brief and superficial.

According to a new report from IANS, Artico Search, and The CAP Group, CISO-board interactions remain short (typically 30 minutes per quarter), lack depth around threats, particularly those posed by AI and other emerging technologies, and are more about “listening” than active participation.

According to the study, just 30% of boards describe their relationship with CISOs as “strong and collaborative,” while 35% call it “adequate and functional,” and 24% say it needs improvement.

This indicates that deep trust and partnership remain “uneven and far from universal,” the report notes.

by CSO Online

SPONSORED BY

Incident Response Forum D.C. 2026 is set for Wednesday, April 22, 2026 at the historic Mayflower Hotel in Washington, D.C.!

Incident Response Forum is the only conference of its kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. It is focused solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.

Join us in person or tune in virtually to hear from nearly 50 luminaries in the incident response field—including senior officials from the DOJ and FBI, and lawyers and consultants from the best firms and in the world.

👉 UNTIL FRIDAY, MARCH 27: Please use the codes below to get a 25% early-bird discount (regular in-person registration fee is $1,500; regular virtual registration fee is $750). Please register here:

In-person attendance: UPDATE909DC25
Virtual attendance: UPDATE909V25

X