Abstract digital security visualization with blue circuit board patterns and padlock icon
Photo via Unsplash

Today's Headlines:

  • RSA Conference 2026 opens tomorrow. FBI, NSA, and CISA are boycotting. Former NSA chief Keith Alexander speaks while current officials stay home.
  • Section 702 FISA: 29 days to sunset. Over 130 organizations demand Congress close the data broker loophole. Deadlock continues.
  • Kentucky House passes ACR privacy bill. Smart TV "automatic content recognition" would become sensitive data requiring consent.
  • Stryker still crippled 11 days post-attack. FBI seized four Handala domains. The Iranian hackers already launched new ones.
  • Iran's FindFace surveillance exposed. Joint investigation reveals Russian facial recognition tech tracking dissidents.

RSA Conference Opens Tomorrow: Without the Feds

The world's largest cybersecurity conference kicks off at San Francisco's Moscone Center tomorrow. 44,000 attendees. 700+ vendors. Zero current FBI, NSA, or CISA officials.

In January, RSA announced Jen Easterly as CEO, the former CISA director who ran the agency from 2021 until Trump's team fired her. Eight days later, every federal speaker vanished from the agenda. CISA's Marci McCarthy confirmed the agencies "will not participate" in RSA 2026, citing "good stewardship of taxpayer dollars."

Panels on China's Typhoon hackers? Gone. FBI cyber operations discussions? Pulled. Instead, we get General Keith Alexander (Ret.), former NSA Director, talking security while his successors are barred from attending.

The irony: RSA's theme this year is "Power of Community." The federal cybersecurity community (the people who actually investigate nation-state attacks) isn't allowed to show up.

What to watch this week: AI surveillance tools marketed as "security solutions," endpoint detection that phones home, and vendor announcements that'll end up in police departments within months. We'll be monitoring.

Read our RSA 2026 preview

FISA Section 702: 29 Days, 130+ Organizations, Zero Progress

Section 702 sunsets at midnight on April 20. We're down to 29 days. Congress has held meetings, introduced reform bills, and achieved exactly nothing.

On March 19, a coalition of over 130 organizations (including EFF, ACLU, Brennan Center, and dozens of civil liberties groups) sent a letter to Congressional leadership with one demand: don't reauthorize 702 without closing the data broker loophole.

That loophole lets the government buy your location data, browsing history, and personal information from data brokers: data they'd need a warrant to collect directly. The current 702 law says nothing about this end-run around the Fourth Amendment.

Where things stand:

  • Cotton wants a clean extension. Senator Tom Cotton (R-UT) is pushing an 18-month renewal with zero reforms. No warrant requirement. No data broker ban.
  • Reform bills exist but lack votes. The bipartisan Government Surveillance Reform Act would require warrants for American data and ban commercial data purchases. Last time a warrant requirement came to a vote, it lost 212-212.
  • The White House is silent. A classified hearing in February "erupted in frustration" when intelligence officials wouldn't say whether the Trump administration even wants renewal.

Speaker Johnson is scrambling. The dynamic shifted when ICE started using 702 data for immigration raids, turning abstract surveillance debates into political fights.

Full Section 702 analysis

Kentucky Takes On Smart TV Surveillance

Kentucky's House of Representatives unanimously passed HB 692 on March 16, a bill that would classify "automatic content recognition" (ACR) data as sensitive information requiring consumer consent.

ACR is how your smart TV spies on you. The technology watches what you watch (frame by frame) and reports it back to manufacturers and data brokers. Samsung, LG, Vizio, and others have been doing this for years, often buried in incomprehensible terms of service.

The Kentucky bill, sponsored by Rep. Josh Branscum (R-Russell Springs), would:

  • Define ACR as technology that "identifies content based on a sample of content or by reference to data files"
  • Add ACR data to Kentucky's Consumer Data Protection Act as "sensitive data"
  • Require explicit consent before companies can collect it

Effective date: July 1, 2027, if it passes the Senate.

This matters because most Americans have no idea their TV is watching them. When Samsung got caught in 2015, the company's response was basically "it's in the terms of service." Now states are saying that's not good enough.

How your smart TV spies on you

Stryker Update: Day 11, Still Offline

America's largest medical device maker remains crippled. Eleven days after Iranian hackers wiped 200,000+ devices across 79 offices, Stryker is still working to restore systems.

On March 20, the DOJ made it official: the Handala hacking group is run by Iran's Ministry of Intelligence and Security (MOIS). Not "suspected ties." Not "believed to be affiliated." Direct MOIS operation.

The FBI seized four Handala domains: Justicehomeland.org, Handala-Hack.to, Karmabelow80.org, and Handala-Redwanted.to. Handala's response? They launched new domains within hours and posted on Telegram: "We are more than only a website... this is nothing more than the latest desperate attempts by the United States and its allies to silence the voice of Handala."

They're not wrong about domain seizures being whack-a-mole. But the formal MOIS attribution changes things. It could trigger additional sanctions, justify cyber responses, and affects how allies coordinate intelligence.

Meanwhile, Stryker hasn't confirmed what patient data (if any) was exfiltrated. The company claims surgical systems remain operational, but their internal network is still a mess.

Full Stryker coverage

Iran's Russian Facial Recognition: The Investigation

A joint investigation by journalists from multiple countries revealed this month that Iran secretly acquired FindFace, a Russian facial recognition system, in 2019. The regime is now using it to track dissidents and crush protests.

The details, according to Forbidden Stories and partners:

  • An Iranian company called Rasadco bought FindFace directly from NtechLab on August 19, 2019
  • Rasadco was later absorbed by Kama, which distributed the software to the IRGC and Iran's Ministry of Intelligence
  • FindFace can identify faces in public spaces within seconds and cross-reference them against security service databases
  • The system enables "social mapping": tracking connections between individuals and monitoring their movements across the country

During protests that peaked in January 2026, evidence suggests Iran used FindFace to identify demonstrators. Early estimates put the death toll at over 30,000 in 48 hours.

Context: The EU sanctioned NtechLab in July 2023 for human rights violations in Russia. The US blacklisted the company in December 2024. None of that stopped the sale to Iran or prevented its use against protesters.

Full FindFace investigation

State Privacy Bills: Quick Hits

Hawaii SB 1163: Passed the Senate on March 10. Would prohibit selling geolocation data and browser history without consent. Also bans selling data from apps running in the background, targeting the surveillance ad-tech industry.

Oklahoma SB-546: The Senate voted 38-7 to pass a comprehensive privacy bill. Heads to the governor.

Alabama: A consumer data privacy bill advanced after amendments removed the requirement to recognize opt-out preference signals. Translation: companies don't have to honor "Do Not Sell My Data" browser settings.

New York S3699: The Facial Recognition Technology Study Act passed the State Senate and moves to the Assembly. Would create a task force to study facial recognition privacy implications and potential regulations.

What We're Watching

  • March 23-26: RSA Conference: expect AI surveillance announcements dressed up as "security solutions"
  • March 30-31: IAPP Global Privacy Summit in Washington DC
  • April 6: Meta's deadline to respond to Senate questions about facial recognition in Ray-Ban smart glasses
  • April 20: Section 702 FISA sunset date: 29 days
  • Ongoing: Stryker recovery, Kentucky HB 692 in Senate, DOJ Handala investigation

References

  1. RSA Conference 2026
  2. Section 702 FISA 2026 Resource Page - Brennan Center
  3. Congress Is Dropping the Ball with a Clean Extension of FISA - EFF
  4. Kentucky HB 692 - ACR Privacy Bill
  5. US accuses Iran's government of operating Handala - TechCrunch
  6. Eyes of Iran: How the regime secretly monitors its citizens - Forbidden Stories
  7. Iran using NtechLab's facial recognition to crush dissent - Biometric Update
  8. Proposed State Privacy Law Update: March 16, 2026 - Troutman