FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
2026-03-21T19:24:07Z•c0e4f8a50b6cc373ae5585bb8bf8bed66b6317e4ee48b619203ccea77112454d
APTCISA KEVCVE-2026-20131CVE-2026-21992CVE-2026-32746CVE-2026-33017CanisterWormCisco FMCGitHub Actions compromiseLangflowMagento PolyShellOracleRCERussian intelligenceTrivyaccount takeoveractive exploitationexploit kit (DarkSword)iOS exploitsmessaging appsphishingransomware (Interlock)supply chaintelnetdunauthenticated RCE
What happened
A broad set of high-risk incidents and vulnerabilities was reported: Russian intelligence‑affiliated actors are conducting mass phishing campaigns to compromise commercial messaging apps (Signal, WhatsApp) for account takeovers; Oracle released an out‑of‑band patch for a critical unauthenticated RCE in Identity Manager/Web Services Manager (CVE-2026-21992, CVSS 9.8); the Trivy supply‑chain and its GitHub Actions were compromised, leading to CI/CD secret theft and a self‑propagating npm worm dubbed CanisterWorm. Multiple high‑severity/critical flaws are being actively exploited or added to CISA
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c0e4f8a50b6cc373ae5585bb8bf8bed66b6317e4ee48b619203ccea77112454d
- Enrichment time
- 2026-03-21T19:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.