BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
CIPHERThreat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
β€’
Β© 2026
β€’
blacktemple.net
  1. Feed
  2. /Russian Intelligence Targets Signal Users as CISA Orders Emergency Cisco Patches

Russian Intelligence Targets Signal Users as CISA Orders Emergency Cisco Patches

March 21, 2026Malware & Threats3 min readcritical

Originally reported by BleepingComputer, Malwarebytes Labs

#russian-intelligence#signal-phishing#cisco-vulnerability#cisa-kev#oracle-rce#operation-alice#biometric-privacy
Share

TL;DR

The FBI warns of Russian intelligence-linked phishing campaigns targeting Signal and WhatsApp users. CISA has ordered federal agencies to patch critical vulnerabilities in Cisco firewalls and Oracle identity management systems by Sunday.

Why critical?

CISA has added a maximum-severity Cisco vulnerability to the KEV catalog with a federal patching deadline, indicating confirmed active exploitation of critical infrastructure components.

Russian Intelligence Targets Encrypted Messaging Platforms

The FBI has issued a public service announcement warning that Russian intelligence-linked threat actors are conducting active phishing campaigns against users of encrypted messaging applications including Signal and WhatsApp. According to the bureau, these operations have already compromised thousands of accounts across multiple platforms.

The campaigns represent a strategic shift toward targeting secure communication channels, potentially aiming to intercept encrypted communications or establish footholds within high-value target networks. The FBI has not disclosed specific technical details about the attack vectors or attribution methodology.

CISA Orders Emergency Cisco Firewall Patching

The Cybersecurity and Infrastructure Security Agency has added CVE-2026-20131 to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch the maximum-severity vulnerability in Cisco Secure Firewall Management Center by Sunday, March 22.

The emergency directive indicates CISA has evidence of active exploitation targeting this critical network security infrastructure. The vulnerability affects Cisco FMC deployments and carries a CVSS score of 10.0, suggesting unauthenticated remote code execution capabilities.

Oracle Releases Emergency Identity Manager Fix

Oracle has pushed an out-of-band security update addressing CVE-2026-21992, a critical unauthenticated remote code execution vulnerability in Oracle Identity Manager and Web Services Manager. The emergency patch delivery suggests either active exploitation or imminent threat intelligence regarding this enterprise identity management flaw.

Organizations running Oracle identity infrastructure should prioritize this update given the potential for privilege escalation and lateral movement within enterprise environments.

Law Enforcement Dismantles Massive Dark Web Operation

International law enforcement agencies have concluded Operation Alice, shutting down over 373,000 dark web sites offering fraudulent child sexual abuse material packages. The coordinated action represents one of the largest dark web takedown operations to date.

While these sites contained fake content designed to defraud users rather than distribute actual illegal material, the operation demonstrates the scale of criminal infrastructure operating within anonymous networks and the challenges facing digital forensics teams.

Geopolitical Cyber Defense Strategies for CISOs

Security leadership must adapt defensive strategies to address the rising threat of nation-state destructive attacks designed to disrupt operations rather than extract ransom payments. These geopolitically-motivated campaigns often deploy wiper malware and target critical infrastructure with the goal of maximum operational impact.

CISOs should focus on network segmentation, rapid containment capabilities, and recovery planning specifically designed for destructive rather than encrypting attacks.

NYC Proposes Biometric Tracking Restrictions

New York City lawmakers are advancing legislation to limit commercial biometric tracking before widespread deployment enables real-time surveillance pricing and customer profiling. The proposed regulations would require explicit consent and disclosure for facial recognition systems used in retail and public spaces.

The legislative push addresses growing concerns about the intersection of biometric surveillance technology and algorithmic pricing systems that could enable discriminatory practices based on demographic profiling.

Sources

  • https://www.bleepingcomputer.com/news/security/fbi-links-signal-phishing-attacks-to-russian-intelligence-services/
  • https://www.bleepingcomputer.com/news/security/oracle-pushes-emergency-fix-for-critical-identity-manager-rce-flaw/
  • https://www.bleepingcomputer.com/news/security/police-take-down-373-000-fake-csam-sites-in-operation-alice/
  • https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-max-severity-cisco-flaw-by-sunday/
  • https://www.bleepingcomputer.com/news/security/how-cisos-can-survive-the-era-of-geopolitical-cyberattacks/
  • https://www.malwarebytes.com/blog/news/2026/03/could-your-face-change-what-you-pay-nyc-wants-limits-on-biometric-tracking

Originally reported by BleepingComputer, Malwarebytes Labs

Tags

#russian-intelligence#signal-phishing#cisco-vulnerability#cisa-kev#oracle-rce#operation-alice#biometric-privacy

Threat Actors

🏴Anonymous

Tracked Companies

πŸ‡ΊπŸ‡ΈMeta Platforms
πŸ‡ΊπŸ‡ΈOracle Data Cloud

Related Intelligence

  • Critical SharePoint Exploits, Mobile Malware, and Data Breaches Hit Major Organizations

    criticalMar 19, 2026
  • CISA Flags Active Exploitation While New Ransomware Tactics and AI Shadow Operations Emerge

    criticalMar 17, 2026
  • Week in Malware: CISA Adds n8n to KEV, Iran-Linked Wiper Hits Medical Giant

    criticalMar 12, 2026

Related Knowledge

  • CIPHER Deep Training: Malware Analysis, Reverse Engineering, and Evasion Techniques

    offensive
  • Malware Analysis Deep Dive β€” CIPHER Training Module

    dfir
  • DFIR & Threat Hunting Deep Training β€” CIPHER Knowledge Base

    dfir

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Supply Chain Attack Compromises Aqua Security's Trivy Scanner

Next Article

Magento Under Siege: PolyShell Zero-Day Fuels Mass Defacements, AI Fraud Tactics Emerge β†’