The 94% Bot Reality, Shift in AI landscape, & The Quantum Horizon


Listen to Article

0:00 / 0:00

It’s a Paper Trail for the week ending in March 7, 2026, and we’ll cover what happened last week in the Information Security space.

Last Week, in Review

  • Cloudflare’s 2026 Threat Report revealed that, in the last three months, bots now account for 94% of all login attempts on its network, and that 63% of all login attempts involved credentials compromised somewhere else – highlighting the need for multi-factor authentication and possibly adopting passwordless authentication mechanisms. [Cloudflare, Inc.]
  • In preparation for quantum computers, Google Chrome team, in collaboration with Cloudflare and IETF’s PLANTS working group, is working on improvements to make HTTPS certificates secure for the quantum age, with initial performance and security discovery already underway and plans to finalize requirements to bring new certificate authorities to Chrome Quantum-resistant Root Store (CQRS) by Q3 of 2027. [Google Chrome, Cloudflare, Inc.]
  • With the limited release of Anthropic’s Claude and OpenAI’s Codex Security demonstrating the ability to identify security vulnerabilities in codebases, both have reported multiple high-risk findings with claims of low noise ratios – potentially adding a new dimension to the landscape of code security scanning. [Anthropic PBC, OpenAI]
  • Google announced that Chrome will move from a four-week to a two-week major release cycle starting with Chrome 153 on September 8, 2026. The change applies to desktop, Android, and iOS versions. Weekly security patches will continue between milestones while the Enterprise Extended Stable channel will remain on an eight-week cycle. [Chrome, 9to5google]

Pulse

Microsoft identified ongoing phishing campaign(s) that abuse OAuth’s legitimate redirect mechanism in popular identity providers, such as Entra Id and Google Workspace, that redirect users to adversary controlled websites – typically phishing frameworks, among others – that appear benign but ultimately lead to compromise of credentials and session cookies. Since this approach takes advantage of expected OAuth flows and not exploitation of existing vulnerabilities, it makes it harder for traditional URL-based phishing detection methods to protect against such attacks. [Microsoft]

Passaic County in New Jersey disclosed a malware attack that disrupted phone lines and government IT systems, affecting services for nearly 600,000 residents. The county is working with state and federal agencies on remediation. The attack underscores the threats that local government entities face, which often have limited cybersecurity resources. [The Record, N12N, LLC]

Fix-it Frank

Google’s March 2026 Android security update addresses over hundred vulnerabilities, including several critical-severity bugs. The update also includes patches for a Qualcomm zero-day (CVE-2026-21385), an actively targeted high-severity memory corruption vulnerability, privilege escalation in Framework and privilege escalation flaws in Kernel components. As mobile device fleets make up a substantial part of BYOD for the organization, March Android security patches to managed device fleets should be rolled out with urgency. [AOSP, The HackerNews]

The Fine Print

The NY Raise Act, signed in December 2025 and set to take effect from January 2027, establishes requirements for large developers of frontier AI models to publish safety and security practices publicly, publishing certain transparency reports, and notifying the government within 72 hours of the determination of a safety incident. [Davis Wright Tremaine LLP]

Wilson Sonsini’s 2026 Year In Preview reports that cyber insurance carriers are increasing conditioning coverage on AI-specific security controls, with some starting to introduce AI-specific security riders as a prerequisite for underwriting. [Wilson Sonsini Goodrich & Rosati]

CalPrivacy fined PlayOn Sports – a high school sports media platform – $1.1 million for failure to configure its digital assets to recognize and honor consumers’ requests to opt out of sale or sharing of personal information in violation of California Consumer Privacy Act (CCPA). It was further noted that use of phone or email opt-out when the company uses digital tracking technologies is insufficient to satisfy the opt-out obligation. [Holland & Knight LLP]

The Bottom Line

From the introduction of various Artificial Intelligence laws to the adoption of AI security practices in cyber insurance space, there appears to be a shift towards the need and desire for a transparent AI culture. Coupled with the roadmap for Quantum-Resistant Root Stores adoption also highlights that the infrastructure needed to support and survive such major changes is being built right now – introducing risk of being caught in the paper trail of a legacy era if not properly planned for.Thanks for tuning-in to this edition of Paper Trail. If you found this helpful, don’t forget to subscribe.