Russians are posing as Signal support to launch phishing attacks
2026-03-23T07:24:01Z•faef113c0e07b6dcbda6f1f6e46aab77c2eba6e1a0d254f19c72dc6e4ae99b69
CISACVE-2026-20131Cisco Secure FirewallDDoSDarkswordEmennet PasargadFBIIntuneIoT botnetIranJapanNorth KoreaRussiaSharePointSignalStrykerbias','AI','open-source','Linux Foundation','RustSec','identity'facial-recognitioniOS exploitnation-stateoffensive-cyber-opsphishingransomwaresanctionszero-day
What happened
The feed compiles multiple high-impact security developments: US agencies warn that Russia-linked actors are impersonating customer support on messaging apps (e.g., Signal) to phish and take over accounts; unknown actors are actively exploiting a critical Microsoft SharePoint vulnerability; ransomware groups abused CVE-2026-20131 in Cisco Secure Firewall before public patching; and the US disrupted massive IoT botnets behind record DDoS traffic. Other notable items include an Iran-linked attack that abused Microsoft Intune against Stryker, a new iOS exploit kit called Darksword used by spyware
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- faef113c0e07b6dcbda6f1f6e46aab77c2eba6e1a0d254f19c72dc6e4ae99b69
- Enrichment time
- 2026-03-23T07:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.