It’s a Paper Trail for the week ending in March 14, 2026, and we’ll cover what happened last week in the Information Security space.
Last Week, in Review
- Flashpoint’s 2026 Global Threat Intelligence Report observed over 11.1 million systems infected with InfoStealer malware in 2025, resulting in 3.3 billion stolen credentials and cloud tokens – highlighting the shift toward adversaries entering through the front door using legitimate credentials rather than breaking in.
- Instagram announced plans to discontinue end-to-end encryption after May 8, 2026, which was first introduced in 2023 after a similar feature was rolled out in Messenger.
- Microsoft announced that Windows hotpatching – the ability to apply security updates without requiring a device restart – will be enabled by default for all eligible Windows 11 devices managed via Microsoft Intune, starting with the May 2026 Windows security update.
- Microsoft is rolling out passkey support for Microsoft Entra on Windows devices, enabling phishing-resistant, passwordless authentication through Windows Hello, with a public preview beginning mid-March 2026.
Pulse
IBM X-Force identified malware, dubbed “Slopoly”, likely written by a generative AI model. While the delivery of the malware required a ClickFix social engineering lure, it represents only the initial phase of an emerging arms race between adversarial AI and defenders, forcing defenders to rethink their approach to building defenses.
Lumen’s Black Lotus Labs disclosed KadNap, a new malware campaign that has infected over 14,000 ASUS routers and other edge devices since August 2025, powering a proxy network called Doppelganger. It was found to hide its command infrastructure using a peer-to-peer system based on the Kademlia DHT protocol to evade blocklists. Infected devices – typically undermanaged consumer and small-business routers that are run for years without firmware updates, with default passwords unchanged, and with little to no monitoring – route malicious traffic for brute-force attacks and targeted exploitation campaigns.
Two Chrome extensions – QuickLens and ShotBird – were silently weaponized after ownership transfers, highlighting a systemic deficiency in browser extension marketplaces: the “Featured” badge offers only a one-time review, meaning any actor who acquires a trusted extension through a legitimate sale can push malicious updates to users.
Fix-it Frank
Microsoft’s March 2026 Patch Tuesday patched 82 vulnerabilities, of which 46 address Privilege Elevation bugs, 16 address Remote Code Execution bugs, and 10 address Information Disclosure bugs, across multiple products including Microsoft Windows, Microsoft Office, and .NET Framework.
Qualys reported nine vulnerabilities (dubbed CrackArmor) in AppArmor, a mandatory access control security module used primarily by Debian-based and SUSE Linux distributions. These vulnerabilities allow unprivileged users to circumvent kernel protections, escalate to root, and undermine container isolation guarantees. To address them, the Linux kernel should be upgraded to the latest version.
The Fine Print
Disney agreed to pay $2.75 million to settle an enforcement action by the California Attorney General for alleged violations under CCPA for deficiencies in consumer opt-out mechanisms across platforms and devices. This highlights a case of opt-out where a regulator tested whether opt-out mechanisms actually function end-to-end – not just whether a privacy policy exists.
Connecticut, on June 25, 2025, amended the Connecticut Data Privacy Act (CTDPA) to require disclosure of use of personal data to train artificial intelligence systems – specifically large language models – in covered organizations’ customer facing privacy policy starting from July 1, 2026. The disclosure is required to state whether the organization collects, uses or sells personal data for the purpose of training LLMs.
The Bottom Line
AI-authored malware and credential theft at scale signal a decisive shift toward identity as the primary attack surface – adversaries no longer need to break in when legitimate access is this abundant. At the same time, the broader rollout of phishing-resistant authentication and emerging mandates around AI training disclosures reflect an industry and regulatory posture that is beginning to meet the moment.Thanks for tuning-in to this edition of Paper Trail. If you found this helpful, don’t forget to visit hackwithheart.com and subscribe.