Signal backup keys targeted; Linux kernel RCE; AWS Q credential theft
ID: 58d213d1-a3ce-581f-b90c-193311d49493
STIX ID: report--58d213d1-a3ce-581f-b90c-193311d49493
Feed Name: defend.network
High-severity briefing: Russian intelligence has escalated Signal phishing to coerce Backup Recovery Keys enabling persistent access; Linux kernel pedit COW (CVE-2026-46331) has a public working exploit allowing local privilege escalation; Amazon Q (CVE-2026-12957) permitted malicious repos to exfiltrate cloud credentials (patched by AWS); new SharkLoader/StrikeShark campaigns deploy Cobalt Strike; and a third-party supply-chain injection on Polymarket led to ~$3M in customer losses — recommended actions include immediate patching, credential rotation, user education on recovery keys, and scanning/blocking of C2 and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
