New FBI Alert: Russian Intelligence Uses Signal Recovery Keys to Access Messages
2026-06-27T20:51:47Z•f137d11b713a995fb5fa91d5686d5db51f653e54aef6c374fee90beb30ff54d4
CVE-2026-43503DirtyClonecellebritechina-aptcisa-kevcl-sta-1062cryptotheftcurl-vulnerabilitiescve-2026-12569dprkhospitality-sectorlinux-kernelmacos-malwaremacos.gaslightphishingpolymarketprivilege-escalationprompt-injectionrussian-intelligencesignalsupply-chain-breachtata-electronicsthird-party-breachtinyRCTtonrat
What happened
Multiple high-impact incidents and advisories: the FBI warns Russian intelligence actors are harvesting Signal backup recovery keys to access message history and enable long-term account takeover; Microsoft details a hospitality-sector phishing campaign delivering TonRAT with resilient persistence; JFrog disclosed DirtyClone (CVE-2026-43503), a Linux kernel privilege-escalation that rewrites executables in memory (CVSS 8.8) — patch urgently recommended. Palo Alto Unit 42 reports Chinese APT CL-STA-1062 targeting Southeast Asian government and energy networks using custom TinyRCT backdoor. CISA
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f137d11b713a995fb5fa91d5686d5db51f653e54aef6c374fee90beb30ff54d4
- Enrichment time
- 2026-06-27T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.