EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 27, 20263 min read

Security Briefing | June 27, 2026 - Russian Hackers Target Signal Recovery Keys, Linux Kernel pedit COW Flaw, Amazon Q Developer Credential Theft

The FBI and CISA warn that Russian intelligence-linked phishing campaigns now target Signal Backup Recovery Keys, enabling full account takeover that survives a password change. A new Linux kernel flaw (CVE-2026-46331), nicknamed "pedit COW," allows local privilege escalation to root with a public exploit already available. Meanwhile, a high-severity Amazon Q Developer vulnerability (CVE-2026-12957) could let malicious repositories steal cloud credentials.

By EACA Summit Content Team

Security Briefing | June 27, 2026 - Russian Hackers Target Signal Recovery Keys, Linux Kernel pedit COW Flaw, Amazon Q Developer Credential Theft

1. Russian Hackers Target Signal Backup Recovery Keys

The FBI and CISA updated their March warning about Russian intelligence phishing campaigns targeting Signal users. Attackers now coerce victims into providing their Signal Backup Recovery Key, allowing full account takeover and access to private and group message history. The key remains valid even after password changes.

Verified Facts

  • FBI and CISA jointly warned of Russian intelligence phishing targeting Signal accounts
  • Attackers now specifically request the Signal Backup Recovery Key
  • Once obtained, the key enables account takeover and access to historical messages
  • The key continues to work even after the user changes their password

Evidence

  • FBI/CISA joint advisory updated June 26, 2026
  • BleepingComputer article confirming the evolution of the campaign

Impact

Signal users, particularly those in government or sensitive roles, risk complete loss of message confidentiality and account control. Organizations relying on Signal for secure communications should enforce multi-factor authentication and educate users about this specific phishing tactic.

Confidence Level: High

The Hacker News | BleepingComputer

2. Linux Kernel 'pedit COW' Flaw Enables Local Privilege Escalation

A critical vulnerability in the Linux kernel's traffic-control subsystem (CVE-2026-46331) allows local unprivileged users to gain root access. The flaw, nicknamed 'pedit COW', is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public exploit was released within a day of the CVE assignment on June 16, 2026.

Verified Facts

  • CVE-2026-46331 affects the Linux kernel's act_pedit module
  • The vulnerability is an out-of-bounds write leading to privilege escalation
  • A public working exploit was released on June 17, 2026
  • Red Hat rates the flaw as important/critical

Evidence

  • CVE-2026-46331
  • Red Hat advisory
  • Public exploit code available

Impact

Any system running a vulnerable Linux kernel is at risk of local privilege escalation. Organizations should prioritize patching, especially for multi-user systems and servers where unprivileged users have shell access.

Confidence Level: High

The Hacker News | BleepingComputer

3. Amazon Q Developer Flaw Allows Cloud Credential Theft

A security tool interface showing an alert that blocked a GitHub repository creation operation from an AI coding assistant's MCP server, representing a vulnerability that could allow credential theft through malicious repositories.

A high-severity vulnerability (CVE-2026-12957, CVSS 8.5) in Amazon Q Developer allows malicious repositories to execute commands and steal cloud credentials. The flaw resides in how the AI coding assistant handles Model Context Protocol (MCP) servers. Amazon has patched the issue, and Wiz researchers disclosed the details.

Verified Facts

  • CVE-2026-12957 affects Amazon Q Developer
  • The flaw enables command execution and credential theft via malicious repositories
  • CVSS score of 8.5 (High)
  • Amazon has released a patch

Evidence

  • CVE-2026-12957
  • AWS advisory
  • Wiz research disclosure

Impact

Developers using Amazon Q Developer are at risk of credential theft if they open malicious repositories. Organizations should apply the patch immediately and review MCP server configurations.

Confidence Level: High

The Hacker News | SecurityWeek

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings