← All issues
cybersecurityCyberBubbleSignal

Russia's Signal Attack Just Got Nastier — Here's the 30-Second Fix

🌐  World Intel
Ukraine & USA: Russia Ran a Long-Running Fake SMS Spy Campaign

Ukraine's Security Service and the FBI jointly revealed that Russian intelligence has been sending fake text messages impersonating messaging app support bots to trick government officials, military personnel, politicians, and activists into handing over their account credentials. The campaign targeted people in Ukraine, Europe, and the United States. The goal was to scoop up sensitive military, political, and economic information from private conversations.

↗ The Hacker News
Global: New SharkLoader Malware Hits Governments and Businesses Across 10 Countries

Researchers at Kaspersky discovered a previously unknown malware family called SharkLoader being used in a campaign they're calling StrikeShark. The malware acts as a delivery vehicle for Cobalt Strike, a powerful remote-access tool. Victims include a diplomatic organization in Indonesia, government agencies in Taiwan, and software companies in multiple countries including Lebanon, Serbia, Colombia, and Nepal — suggesting a wide net rather than a focused hit job.

↗ The Hacker News
Southeast Asia: Chinese-Linked Hackers Deploy New TinyRCT Backdoor on Energy & Government Networks

A Chinese-speaking APT group called CL-STA-1062 has been caught deploying a new custom backdoor called TinyRCT against state-owned energy companies and government agencies in Southeast Asia. Palo Alto Networks Unit 42 linked the group to activity dating back to March 2022. The attackers combine custom tools with freely available open-source software to stay under the radar.

↗ The Hacker News
⚔️  Active Attacks
Signal Users: Russian Hackers Now Steal Your Backup Recovery Key

The FBI and CISA updated an earlier warning about Russian intelligence groups targeting Signal users. The campaign has evolved: attackers are now also tricking people into surrendering their Signal Backup Recovery Key. If you hand that key over once, the attacker can read your entire message history — and the key keeps working even if you get a new phone on the same number. The FBI tied the operation to multiple Russian intelligence services including FSB units and Russian military hacking groups, tracked as UNC5792 and UNC4221. High-value targets include government officials, military personnel, and journalists, but regular users are also at risk.

🛡 What to do: Open Signal, go to Settings → Account → Generate a new Backup Recovery Key right now. This instantly cancels any key an attacker might already have. Never share this key with anyone — Signal will never ask for it by text or chat.
Polymarket Users: $3 Million Stolen in Supply-Chain Attack on Crypto Betting Platform

Hackers broke into a third-party vendor that supplies code to Polymarket, a popular prediction market platform where people bet real money on real-world events. The attackers injected a malicious script into Polymarket's website front end, silently stealing around $3 million from users. This is a classic supply-chain attack — the website itself looked fine, but poisoned code was running underneath. Polymarket says it will fully reimburse affected customers.

🛡 What to do: If you use Polymarket or similar crypto platforms, check your account for any unauthorized transactions and contact support. Consider keeping only small amounts of funds in any web-based crypto platform wallet.
🔓  New Vulnerabilities
CISCO-UCM-2026 Cisco Unified Communications Manager CRITICAL — Actively Exploited

A serious security flaw in Cisco's Unified Communications Manager — software that businesses use to run their phone and calling systems — is being actively exploited right now. Attackers who use this vulnerability can gain elevated, root-level control over affected servers. CISA gave U.S. federal agencies a hard deadline of this Sunday to patch it.

Status: Patch available from Cisco — apply it immediately if you run this software. Federal agencies had until June 29 to comply.

CISCO-SDWAN-2026 Cisco SD-WAN HIGH — Zero-Day Exploited

Mandiant revealed details on how attackers exploited a zero-day flaw in Cisco's SD-WAN software to gain full root access on affected devices. SD-WAN is widely used by businesses to manage their network connections across multiple locations. The technical report explains exactly how the attackers moved from a basic foothold to complete control of the system.

Status: Patch available from Cisco. If your organization uses Cisco SD-WAN, contact your IT team today.

FORTINET-2026 Fortinet Network Devices HIGH — Credential Exposure

CISA is urging organizations to harden their Fortinet devices after reports of widespread credential exposure. Login details from Fortinet appliances appear to have been leaked, meaning attackers could use stolen usernames and passwords to break into corporate networks. This affects businesses that use Fortinet firewalls and VPN products.

Status: No new patch required — but CISA is urging immediate configuration hardening and credential resets. Check the CISA advisory for specific steps.

🛠  New Tech
OpenAI Launches GPT-5.6 "Sol" — Its Most Powerful AI Model Yet, With Stronger Cybersecurity Guardrails

OpenAI quietly released three versions of its new GPT-5.6 model — named Sol, Terra, and Luna — to a small group of companies as part of a U.S. government engagement. Sol is the most powerful of the three and has been described as OpenAI's most capable model ever for cybersecurity research, making it much better at finding and analyzing software vulnerabilities. OpenAI says Sol also ships with its strongest safety controls to date, specifically hardened against misuse for sensitive cyber tasks. The company spent weeks stress-testing the model for weaknesses before release. For security researchers, Sol's ability to analyze vulnerabilities at speed could be a genuine force multiplier — but the same capability in the wrong hands is exactly what the safety work is meant to prevent.

Microsoft Quietly Extends Free Windows 10 Security Updates to October 2027

Microsoft has extended its free Extended Security Updates program for Windows 10 consumers by an extra year — now running until October 12, 2027. The change was made quietly, without a formal announcement. If you're still running Windows 10 and enrolled in the ESU program, your machine will keep getting security patches for another year. This is good news for anyone not yet ready to upgrade to Windows 11, though Microsoft will eventually stop supporting Windows 10 entirely.

💡  Deep Dive
Russia Is Hunting Your Signal Account — And the Attack Just Got Worse

Signal has long been the gold standard for private messaging. Journalists use it. Politicians use it. Military officials use it. And that's precisely why Russian intelligence has been working overtime to crack it — not by breaking the encryption, but by tricking you into handing over the keys yourself.

The campaign started with phishing attacks: fake SMS texts pretending to be Signal's support bot, asking users to confirm their credentials. The FBI and CISA first warned about this in March 2026. This week they updated that warning with a disturbing new twist. The same Russian groups — now publicly named as UNC5792 and UNC4221, linked to both the FSB and Russian military intelligence — have added a second step to their playbook. After getting into an account, they coax victims into sharing their Signal Backup Recovery Key. Think of this key like a master copy of your entire message archive. Hand it over, and the attacker can download and read every private and group conversation you've ever had on Signal. The nightmare doesn't stop there: the key keeps working even after you switch phones or create a new account on the same number. Your old messages remain exposed until you manually generate a new key.

For most people, the obvious response is: "I'm not a politician or a soldier, why should I care?" But the FBI was clear that personal accounts belonging to ordinary Ukrainian nationals — not just officials — are also being targeted. And the tactics being used by Russian intelligence today have a track record of spreading into criminal hands within months. SIM swapping, device-code phishing, fake support bots — all of these started as sophisticated spy tools and became everyday scams. Today's espionage technique is tomorrow's mass fraud campaign.

The fix is simple and takes about 30 seconds. Open Signal, go to Settings, find your Account settings, and generate a new Backup Recovery Key. Write it down somewhere safe offline — and never, ever share it with anyone. No legitimate app or service will ever ask for it over text or chat. If you use Signal for anything sensitive, do it now, before you scroll past this and forget.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →