Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

2026-06-29T01:24:12Z643a8337aabe0a17086b84ac1bbd744518d9d2b7810722531f5f7c4f8d737861
account-takeoverai-prompt-injectionchrome-extensionci-cdcobalt-strikedirtyclonegaslightgithub-actionsknown-exploited-vulnerabilitylinux-kernelmalwaremiasmanpmopenai-gpt-5.6pedit-cowphishingprivilege-escalationremote-code-executionrussian-intelligencesharkloadersignal-backup-keysupply-chain

What happened

This collection highlights multiple active and high-impact threats: Russian intelligence-operated phishing campaigns (including fake support texts) targeting messaging accounts and coaxing Signal Backup Recovery Keys to enable account takeover; several new malware/backdoor families (SharkLoader deploying Cobalt Strike, TinyRCT, STOCKSTAY, Mistic, Gaslight) and supply-chain attacks (Miasma affecting npm/Go and Cordyceps CI/CD abuses); and multiple high-severity vulnerabilities and public exploits — notably Linux kernel privilege-escalation flaws (pedit COW/CVE-2026-46331 and DirtyClone/CVE-2026

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
643a8337aabe0a17086b84ac1bbd744518d9d2b7810722531f5f7c4f8d737861
Enrichment time
2026-06-29T01:24:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.