EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 28, 20263 min read

Security Briefing | June 28, 2026 - Russian Intelligence Steals Messaging Credentials via Fake Support Texts, AI Coding Agents Tricked by Clean GitHub Repos

The Security Service of Ukraine and the FBI have uncovered a long-running Russian intelligence campaign using fake support text messages to steal messaging credentials from government officials, military personnel, and activists across Ukraine, Europe, and the US. Separately, a new attack technique uses seemingly clean GitHub repositories to trick AI coding agents into executing malware that evades scanners and human reviewers.

By EACA Summit Content Team

Security Briefing | June 28, 2026 - Russian Intelligence Steals Messaging Credentials via Fake Support Texts, AI Coding Agents Tricked by Clean GitHub Repos

1. Russian Intelligence Campaign Steals Messaging Credentials via Fake Support Texts

The Security Service of Ukraine (SSU) and the FBI uncovered a campaign by Russian intelligence to steal messaging credentials from government officials, military personnel, and activists in Ukraine, Europe, and the US. The attackers used fake support text messages to trick victims into revealing their credentials. The campaign targeted sensitive information and has been ongoing for an extended period.

Verified Facts

  • The SSU and FBI jointly uncovered the campaign
  • Attackers used fake support texts to steal messaging credentials
  • Targets included government officials, military personnel, politicians, and activists in Ukraine, Europe, and the US
  • The campaign was orchestrated by Russian intelligence services

Evidence

  • Official statement from the Security Service of Ukraine (SSU)
  • FBI involvement confirmed

Impact

This campaign poses a direct threat to national security and operational security of government and military personnel across multiple countries. Credential theft can lead to further espionage and data breaches.

Confidence Level: High

The Hacker News

2. Clean GitHub Repo Tricks AI Coding Agents into Running Malware

A GitHub repository warning page stating the repository contains malicious content preserved for security research, representing a clean-looking repo used to trick AI coding agents into executing malware.

A new attack technique uses seemingly benign GitHub repositories to trick AI coding agents into executing malicious payloads. The malware remains invisible to security scanners, AI agents, and human reviewers, posing a significant risk to organizations using AI-assisted development tools.

Verified Facts

  • The attack involves clean GitHub repositories that appear benign
  • AI coding agents are tricked into cloning and setting up the repository, which triggers the malicious payload
  • The malware is designed to evade detection by security scanners and human reviewers
  • The technique was reported by BleepingComputer

Evidence

  • BleepingComputer report detailing the technique

Impact

Organizations using AI coding agents are at risk of supply chain compromise. This attack vector bypasses traditional security measures and could lead to widespread malware deployment in development environments.

Confidence Level: Medium

BleepingComputer

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings