logo

Signal backup keys targeted; Linux kernel RCE; AWS Q credential theft

ID: 58d213d1-a3ce-581f-b90c-193311d49493

STIX ID: report--58d213d1-a3ce-581f-b90c-193311d49493

Feed Name: defend.network

Threat Score
87/100

Date Published: 2026-06-27

Date Updated: 2026-06-27

...
...

High-severity briefing: Russian intelligence has escalated Signal phishing to coerce Backup Recovery Keys enabling persistent access; Linux kernel pedit COW (CVE-2026-46331) has a public working exploit allowing local privilege escalation; Amazon Q (CVE-2026-12957) permitted malicious repos to exfiltrate cloud credentials (patched by AWS); new SharkLoader/StrikeShark campaigns deploy Cobalt Strike; and a third-party supply-chain injection on Polymarket led to ~$3M in customer losses — recommended actions include immediate patching, credential rotation, user education on recovery keys, and scanning/blocking of C2 and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.