Hello friends! 👋
Welcome back to Simplifying Cybersecurity, the weekly newsletter where I distill 25 years of vCISO experience into 5 ideas, tools, and career hacks. This week: nation-state social engineering that doesn't require a single line of code, an AI governance framework you need to know, and the networking approach that gets responses from people you've never met.
Let's go.
🧠 1. Why Break Encryption When You Can Just Ask for the Key?
On March 21, 2026, the FBI and CISA issued a joint advisory warning that Russian intelligence-linked actors are running phishing campaigns against Signal and WhatsApp users. The targets: current and former U.S. government officials, military personnel, political figures, and journalists (Source: The Hacker News).
The attackers are not breaking end-to-end encryption. They don't need to. They're posing as "Signal Support" or "Signal Security Chatbot," messaging targets directly, and asking them to share their verification codes or PINs. Once the victim complies, the attacker links their own device to the account or takes it over entirely (Source: Malwarebytes).
Thousands of accounts have been compromised globally (Source: The Hacker News). Dutch intelligence confirmed that government employees were among the victims (Source: Help Net Security). France's Cyber Crisis Coordination Center issued its own warning about the same campaign (Source: The Hacker News).
Why this matters for aspiring analysts: This is a social engineering attack. No malware. No zero-day. No code. The entire operation depends on convincing a human to hand over a six-digit code. And it's working against trained government officials.
The Hack: Go into your Signal and WhatsApp settings right now. Review your linked devices. Remove anything you don't recognize. Turn on registration lock (Signal) or two-step verification (WhatsApp). And remember: no legitimate support team will ever ask for your verification code through a chat message. If someone asks, it's a scam.
🔍 2. INTERPOL Takes Down 45,000 Malicious Servers
🔵 Operation: Global Crackdown, 72 Countries, 94 Arrests
An international INTERPOL-coordinated operation across 72 countries dismantled 45,000 malicious IPs and servers linked to phishing, malware distribution, and ransomware ecosystems. The operation resulted in 94 arrests (Source: DIESEC).
Why this matters for your career: Cybercrime is an industrialized service economy. Threat actors rent infrastructure, automate distribution, and scale campaigns globally. When you hear "ransomware as a service" in a training module, this is what it looks like in practice: supply chains of criminal infrastructure spanning dozens of countries.
Understanding how criminal infrastructure operates, from bulletproof hosting to phishing kits to credential marketplaces, is a skill set that makes you more valuable in threat intelligence, incident response, and SOC roles.
Your Takeaway: The next time you see a phishing email in your inbox (or in a simulation), trace the thinking backwards. Someone built the phishing kit. Someone rented the domain. Someone hosted the landing page. Someone laundered the credentials. That chain is your career territory.
📋 3. AI Governance in 5 Minutes
If you're going to work in cybersecurity in 2026, you need to understand AI governance. Not because you'll be writing policy on day one. Because employers are looking for analysts who understand the bigger picture, and AI governance is part of that picture.
The NIST AI Risk Management Framework (AI RMF) is the closest thing the U.S. has to a standard for managing AI risk. Released in January 2023 and built through collaboration with 240+ organizations, it's voluntary, sector-agnostic, and designed to be practical (Source: NIST).
Here's what you need to know:
The framework has four core functions (Source: NIST AI Resource Center):
GOVERN: Establish policies, roles, and accountability structures for AI risk. Who owns the risk? Who decides what's acceptable?
MAP: Identify and document the context around your AI systems. What data are they trained on? Where are they deployed? Who's affected by their outputs?
MEASURE: Assess and track AI risks using quantitative and qualitative methods. How do you know if your AI system is behaving as intended?
MANAGE: Prioritize and act on identified risks. Allocate resources. Respond to incidents. Monitor continuously.
NIST also released a Generative AI Profile (NIST-AI-600-1) in July 2024 that addresses risks specific to generative AI: hallucinations, data poisoning, deepfakes, and more (Source: NIST).
Why aspiring analysts should care: The NIST AI RMF is becoming the operational layer beneath regulatory compliance. The Colorado AI Act explicitly references it. Organizations using AI-enabled security tools (97% of them, according to StationX data from Issue 1) need people who understand both the technical and governance sides. NIST is expected to release RMF 1.1 guidance updates through 2026 (Source: Nemko Digital).
The Hack: Bookmark the NIST AI RMF Playbook. Read the Govern section first. It's the foundation. If you mention "NIST AI RMF" in an interview and explain the four functions, you're already ahead of 90% of entry-level candidates.
😂 4. Who Names Their Dog “P@ssword1!”?

🛠️ 5. Send One Genuine Connection Request Per Week
Most career advice tells you to "network." Few people explain how to do it without feeling like you're selling something.
Here's the approach that works for me and for the analysts I mentor:
Find one person per week who posted something on LinkedIn that taught you something or made you think.
Read their post carefully. Don't skim.
Leave a comment that adds your own perspective. Not "Great post!" Not a fire emoji. A sentence or two that shows you engaged with the content.
Send a connection request with a short note referencing what you commented on.
That's it. One per week. 52 per year.
Why this works: People remember the person who said something thoughtful on their post. Not the person who blasted 200 generic connection requests. Quality compounds. After 6 months, you'll have a network of people who know your name, have seen your thinking, and are far more likely to respond when you need advice or a referral.
Bonus: If you're job searching, this habit makes you visible to hiring managers before you ever apply. A quiet LinkedIn profile with zero activity tells recruiters nothing. A profile with weekly comments and thoughtful engagement tells them you're active, curious, and invested in the field.
🔐 Sponsored: Worth Reading: Securing Agentic AI in AWS Bedrock
Agentic AI is no longer a concept. It's in production. And the security playbook hasn't caught up. XM Cyber's free ebook, "Building and Scaling Secure Agentic AI Applications in AWS Bedrock," breaks down the core components of AWS Bedrock (Guardrails, Knowledge Bases, Agents) and shows how attackers exploit them to exfiltrate data and bypass security filters. If your organization runs AI workloads on AWS, or if you want to understand how cloud AI security works, this is a practical, research-backed read for architects and security leaders.
Download the free ebook: Building and Scaling Secure Agentic AI Applications in AWS Bedrock
🚨 The 30 Day Career Sprint: Becoming a Cybersecurity Analyst is now available on Amazon!
If you're ready to stop overthinking and start moving toward your first role in cybersecurity, this book is your roadmap. Grab your copy here ➡️ https://simplifyingcybersecurity.com/30DayCareerSprint
Have a great week!
Jerod Brennen
🔗 Connect with me on LinkedIn
👥 Join the Simplifying Cybersecurity group
Did someone forward this to you? Subscribe so you don't miss next week's issue. Have a question or topic you'd like covered? Hit reply. I read every message. 💬

