Technology & OSINT — 2026-03-21
FBI, NSA, CISA Pull All Speakers From RSA 2026 Over Easterly CEO Appointment
SOCRadar's threat intelligence analysis documents the Iran cyber conflict across five domains: MOIS-attributed wiper campaigns (including Stryker), IRGC-linked APT persistence in US critical infrastructure, hacktivist proxy operations through the "Electronic Operations Room" formed February 28, retaliatory DDoS campaigns against coalition partners, and information warfare via fabricated claims of infrastructure damage. The analysis provides an OSINT framework for tracking Iranian cyber escalation that directly contrasts with CISA's public "no uptick" assessment.
Let me clean all 9 blocks:
CISA, FBI, and NSA withdrew all speakers and participation from RSAC 2026 (March 23–26, 40,000+ attendees) after the conference appointed former CISA Director Jen Easterly as CEO. Cancelled sessions included a behind-the-scenes panel on FBI/NSA operations against China's Salt Typhoon, Volt Typhoon, and Flax Typhoon campaigns. The federal boycott of the world's largest cybersecurity conference disrupts a critical public-private intelligence sharing venue while CISA is already operating at one-third staffing.
Analysis
Prior IC briefs reported CISA's acting director claiming 'no uptick' in Iranian cyber threats, contradicting private-sector assessments. The RSA boycott compounds this disconnect: IC agencies are withdrawing from the primary venue where government and industry share cyber threat intelligence, precisely when Iran-linked wiper attacks are escalating.
View in full brief →