New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages

2026-06-28T14:51:51Z0d8e920d0020cf5c12cc6f6950d22fe9105a5e0f6fc34cab4d9483996d653b7e
APTCISACL-STA-1062CellebriteDirtyCloneSignalTinyRCTTonRATaccount-takeovercryptocurrency-theftcurlespionageknown-exploited-vulnerabilitylibcurllinux-kernelmacOS.Gaslightmalwarephishingprivilege-escalationsupply-chain-breachthird-party-breachvulnerability

What happened

Multiple high-impact security developments: the FBI/CISA warn Russian intelligence actors are stealing Signal backup recovery keys to access message history and perform long-term account takeover. Microsoft details a hospitality-focused phishing campaign delivering TonRAT with resilient persistence. JFrog published a working exploit for DirtyClone (Linux kernel privilege escalation, CVE-2026-43503, CVSS 8.8) — a memory-only root escalation — and Curl maintainers fixed 18 vulnerabilities in a large release. Palo Alto Unit 42 reports Chinese APT CL-STA-1062 expanding attacks on Southeast Asian政府

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
0d8e920d0020cf5c12cc6f6950d22fe9105a5e0f6fc34cab4d9483996d653b7e
Enrichment time
2026-06-28T14:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.