New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages

2026-06-27T20:51:47Zf137d11b713a995fb5fa91d5686d5db51f653e54aef6c374fee90beb30ff54d4
CVE-2026-43503DirtyClonecellebritechina-aptcisa-kevcl-sta-1062cryptotheftcurl-vulnerabilitiescve-2026-12569dprkhospitality-sectorlinux-kernelmacos-malwaremacos.gaslightphishingpolymarketprivilege-escalationprompt-injectionrussian-intelligencesignalsupply-chain-breachtata-electronicsthird-party-breachtinyRCTtonrat

What happened

Multiple high-impact incidents and advisories: the FBI warns Russian intelligence actors are harvesting Signal backup recovery keys to access message history and enable long-term account takeover; Microsoft details a hospitality-sector phishing campaign delivering TonRAT with resilient persistence; JFrog disclosed DirtyClone (CVE-2026-43503), a Linux kernel privilege-escalation that rewrites executables in memory (CVSS 8.8) — patch urgently recommended. Palo Alto Unit 42 reports Chinese APT CL-STA-1062 targeting Southeast Asian government and energy networks using custom TinyRCT backdoor. CISA

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f137d11b713a995fb5fa91d5686d5db51f653e54aef6c374fee90beb30ff54d4
Enrichment time
2026-06-27T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.