Russians are posing as Signal support to launch phishing attacks

2026-03-23T07:24:01Zfaef113c0e07b6dcbda6f1f6e46aab77c2eba6e1a0d254f19c72dc6e4ae99b69
CISACVE-2026-20131Cisco Secure FirewallDDoSDarkswordEmennet PasargadFBIIntuneIoT botnetIranJapanNorth KoreaRussiaSharePointSignalStrykerbias','AI','open-source','Linux Foundation','RustSec','identity'facial-recognitioniOS exploitnation-stateoffensive-cyber-opsphishingransomwaresanctionszero-day

What happened

The feed compiles multiple high-impact security developments: US agencies warn that Russia-linked actors are impersonating customer support on messaging apps (e.g., Signal) to phish and take over accounts; unknown actors are actively exploiting a critical Microsoft SharePoint vulnerability; ransomware groups abused CVE-2026-20131 in Cisco Secure Firewall before public patching; and the US disrupted massive IoT botnets behind record DDoS traffic. Other notable items include an Iran-linked attack that abused Microsoft Intune against Stryker, a new iOS exploit kit called Darksword used by spyware

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
faef113c0e07b6dcbda6f1f6e46aab77c2eba6e1a0d254f19c72dc6e4ae99b69
Enrichment time
2026-03-23T07:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russians are posing as Signal support to launch phishing attacks · Baitaphish