New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages
2026-06-28T14:51:51Z•0d8e920d0020cf5c12cc6f6950d22fe9105a5e0f6fc34cab4d9483996d653b7e
APTCISACL-STA-1062CellebriteDirtyCloneSignalTinyRCTTonRATaccount-takeovercryptocurrency-theftcurlespionageknown-exploited-vulnerabilitylibcurllinux-kernelmacOS.Gaslightmalwarephishingprivilege-escalationsupply-chain-breachthird-party-breachvulnerability
What happened
Multiple high-impact security developments: the FBI/CISA warn Russian intelligence actors are stealing Signal backup recovery keys to access message history and perform long-term account takeover. Microsoft details a hospitality-focused phishing campaign delivering TonRAT with resilient persistence. JFrog published a working exploit for DirtyClone (Linux kernel privilege escalation, CVE-2026-43503, CVSS 8.8) — a memory-only root escalation — and Curl maintainers fixed 18 vulnerabilities in a large release. Palo Alto Unit 42 reports Chinese APT CL-STA-1062 expanding attacks on Southeast Asian政府
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 0d8e920d0020cf5c12cc6f6950d22fe9105a5e0f6fc34cab4d9483996d653b7e
- Enrichment time
- 2026-06-28T14:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.