Russian Spies Are After Your Signal Backup Key — Here's the 30-Second Fix
Saturday, June 27, 2026 · 5-minute read
Thalha Jubair, 20, and Owen Flowers, 18, admitted in a UK court to hacking Transport for London in August 2024. Flowers also admitted targeting two US healthcare providers. The pair are key members of Scattered Spider, a loose cybercrime group linked to $115 million in ransom payments across 47 US companies. Their guilty pleas came on the very first day of what was scheduled to be a six-week trial.
↗ Krebs on SecurityMillions of budget Android TV streaming boxes sold online are quietly enrolled in a residential proxy botnet called Popa. Security researchers linked Popa to NetNut, a proxy service run by publicly traded Israeli firm Alarum Technologies. The boxes advertise free access to streaming services — but in exchange, your home internet connection gets silently rented out to strangers to route their traffic through, potentially including malicious activity.
↗ Krebs on SecurityA state-sponsored hacking group called CL-STA-1062 has been quietly hitting government agencies and energy companies across Southeast Asia since at least 2022. Researchers at Palo Alto Networks found a new custom tool, called TinyRCT, planted on victims' systems to give attackers persistent remote access. The group speaks Chinese and overlaps with another known hacking team flagged for attacks on Taiwan.
↗ The Hacker NewsThe FBI and CISA updated an earlier warning: Russian intelligence hackers are now phishing Signal users not just for their accounts, but specifically for their Signal Backup Recovery Key. This is a special code that lets you restore all your private messages on a new device. If an attacker gets it, they can read your entire message history — and the key keeps working even if you get a new phone with the same number. The FBI links this to multiple Russian intelligence services including the FSB. Journalists, government workers, and activists are likely primary targets, but anyone using Signal is at risk.
Hackers broke into a third-party vendor that Polymarket — a popular prediction market platform — uses to serve its website. They injected a malicious script into the site's front page. Anyone who visited and interacted with the site during that window had money quietly drained from their account. This is called a supply-chain attack: you didn't do anything wrong, and the site looked completely normal. Polymarket says it will fully reimburse affected users.
A flaw in the Linux kernel lets a regular, unprivileged user on a shared system quietly gain root access. The clever part: the attack never touches files on disk, so standard security scans come back clean. Instead, it poisons a copy of a trusted program held in memory, injects a small payload, and runs it as root. A working exploit appeared publicly within 24 hours of the bug being disclosed. Red Hat and Debian systems were both confirmed vulnerable in testing.
Status: Patch available — update your Linux system immediately, especially any shared or cloud servers. Check with your Linux distribution for the specific update.
A serious flaw in Amazon's AI coding tool, Q Developer, meant that opening a malicious repository could hand attackers your AWS cloud credentials. The attack worked like this: a booby-trapped config file hidden in the project told Q Developer to silently launch attacker-controlled processes, which then inherited all your cloud keys, API tokens, and passwords. Wiz Research found that the path from "open a project" to "cloud account compromised" was extremely short.
Status: Amazon has patched this. Q Developer should auto-update, but verify you're running the latest version if you use it for development work.
CISA issued an urgent order giving US federal agencies until Sunday to patch a vulnerability in Cisco's Unified Communications Manager — the software many large organizations use to manage phone calls and messaging. Attackers are already actively exploiting this flaw in the wild. CISA adding a flaw to its "must patch immediately" list signals real, confirmed attacks happening right now.
Status: Patch available from Cisco — if your organization runs Cisco UC systems, contact your IT team today. This is not one to sit on.
Researchers discovered a new strain of macOS malware called "Gaslight" — and its most notable trick isn't stealing your data, it's confusing the AI tools that security analysts use to examine suspicious programs. Gaslight hides fake debugging data and prompt injection strings inside the program itself, designed to mislead AI-powered analysis tools into thinking it's harmless. This is a significant development: as the security industry leans more on AI to spot threats, attackers are now actively designing malware to beat those AI systems at their own game. It's an early sign of an arms race between AI defenders and AI-aware attackers.
Signal has a reputation as one of the most secure messaging apps on the planet. Its messages are end-to-end encrypted, its code is open source, and security experts routinely recommend it. So when the FBI issues a second warning in three months specifically about Signal — and upgrades it — that's worth sitting with for a moment.
Here's what changed. Back in March, the FBI warned that Russian intelligence operatives were running phishing campaigns to hijack Signal accounts by tricking users into scanning fake QR codes. That was bad enough. The updated advisory reveals they've added a new step to the playbook: getting victims to hand over their Signal Backup Recovery Key. Think of this key like a master password to your entire message history. Signal lets you back up your chats and restore them on a new device — the recovery key is what unlocks that backup. Hand it to an attacker, and they can restore your entire conversation history on their own device and read everything. Here's the especially nasty part: the key doesn't expire when you get a new phone or even change devices. If you keep the same phone number and never generate a new key, the old stolen one still works.
The FBI has named two hacking groups behind this campaign — UNC5792 and UNC4221 — and tied them to multiple branches of Russian intelligence, including FSB officers embedded with Russia's border guards. The primary targets are likely diplomats, journalists, activists, and military personnel. But the tactics will inevitably spread. Phishing kits used by state-sponsored groups have a history of getting copied by criminal gangs within months. What starts as an espionage tool becomes a commodity attack. If you use Signal — for any reason — this affects you.
The fix is simple and takes about 30 seconds: open Signal, go to Settings, find Account, and generate a new backup recovery key. The moment you do, the old one is dead. Any attacker who already downloaded your backup still has what they took — that part can't be undone — but they can't use the key to pull new backups going forward. Do it today. Then put a reminder in your calendar to do it again in six months.