FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
2026-03-22T01:24:11Z•5181c5c0b79e8a177f0df5a4aaa5c349a091ea14fc780edfbf73f23cb8a15bf6
CISACiscoFBIOracleactive-exploitationci/cd-secretsespionageiot-botnetmobile-malwarenpm-compromisepatchingphishingransomwareremote-code-executionsupply-chainunauthenticated-rcezero-day
What happened
A broad set of high-impact security incidents and advisories: Russian intelligence–linked actors are conducting mass phishing campaigns to hijack Signal and WhatsApp accounts; Oracle released a patch for a critical unauthenticated RCE (CVE-2026-21992, CVSS 9.8); Trivy’s supply-chain compromise has spawned a self-propagating CanisterWorm and GitHub Actions tag hijacks to steal CI/CD secrets; multiple high-severity flaws are being actively exploited (Langflow CVE-2026-33017, Cisco FMC CVE-2026-20131 exploited by Interlock ransomware, GNU telnetd CVE-2026-32746), and CISA has added several bugs (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5181c5c0b79e8a177f0df5a4aaa5c349a091ea14fc780edfbf73f23cb8a15bf6
- Enrichment time
- 2026-03-22T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.