✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Newspapers/Journalism
Breach intelligence, attack campaigns, and threat reports targeting the Newspapers/Journalism sector.
Explore Other Sectors
Newspapers/Journalism Threat Reports
FBI Uncovers Russian-Linked Phishing Attacks on Encrypted Messaging Apps
In March 2026, the FBI issued a public service announcement attributing phishing campaigns targeting users of encrypted messaging apps, notably Signal and WhatsApp, to Russian intelligence services. These campaigns, active since at least early 2026, have compromised thousands of accounts by tricking users into sharing verification codes or scanning malicious QR codes, thereby granting attackers access to private messages and contact lists. The primary targets include individuals with access to sensitive information, such as U.S. government officials, military personnel, political figures, and journalists. This incident underscores the evolving tactics of nation-state actors in circumventing end-to-end encryption by exploiting human vulnerabilities. The widespread nature of these attacks highlights the urgent need for enhanced user awareness and robust security measures to protect against sophisticated phishing schemes.
4 months ago
Kill Chain
ICE's 2025 Reactivation of Paragon Solutions Spyware Contract Raises Privacy Concerns
In September 2025, the U.S. Immigration and Customs Enforcement (ICE) reactivated a $2 million contract with Israeli spyware vendor Paragon Solutions, initially signed in 2024 but paused for compliance review under an executive order restricting the use of commercial spyware. The contract involves Paragon's Graphite spyware, capable of infiltrating mobile devices and accessing encrypted communications. This reactivation has raised significant concerns among civil rights organizations regarding potential overreach and misuse of surveillance technology. The decision to proceed with the contract underscores the ongoing debate over the balance between national security measures and individual privacy rights, especially in light of previous controversies surrounding the use of commercial spyware by government agencies.
4 months ago
Kill Chain
Russian Hackers Exploit Phishing to Hijack Signal and WhatsApp Accounts in 2026
In March 2026, Dutch intelligence agencies reported a large-scale cyber campaign by Russian state-sponsored hackers targeting Signal and WhatsApp accounts of government officials, military personnel, and journalists. The attackers employed phishing and social engineering tactics, impersonating support chatbots to deceive users into revealing security verification codes and PINs. This enabled unauthorized access to sensitive communications and group chats. ([english.aivd.nl](https://english.aivd.nl/latest/news/2026/03/09/russia-targets-signal-and-whatsapp-accounts-in-cyber-campaign?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors exploiting human vulnerabilities rather than technical flaws. It highlights the critical need for heightened vigilance and robust security protocols to protect sensitive information in secure messaging platforms.
4 months ago
Kill Chain
CRESCENTHARVEST Malware Campaign Exploits Iran Protests to Target Supporters
In early January 2026, a cyberespionage campaign named CRESCENTHARVEST emerged, targeting individuals supporting Iran's anti-government protests. Attackers distributed malicious archive files containing authentic protest media and Farsi-language reports, alongside disguised Windows shortcut (.LNK) files. When executed, these shortcuts deployed a remote access trojan (RAT) capable of executing commands, logging keystrokes, and exfiltrating sensitive data. The campaign's sophistication suggests alignment with Iranian state interests, aiming for long-term surveillance and information theft. This incident underscores the increasing use of geopolitical events as lures in cyberattacks, highlighting the need for heightened vigilance among activists, journalists, and dissidents. The campaign's reliance on social engineering and legitimate-looking media emphasizes the importance of verifying the authenticity of received files, especially those related to sensitive political contexts.
5 months ago
Kill Chain
Kenyan Activist's Phone Compromised by Cellebrite Extraction
In July 2025, Kenyan pro-democracy activist Boniface Mwangi was arrested, and his personal devices were confiscated by authorities. Upon their return in September 2025, Mwangi discovered that his Samsung phone's password protection had been removed. Forensic analysis by Citizen Lab revealed with high confidence that Kenyan authorities utilized Cellebrite's forensic extraction tools on his device during its custody, enabling full access to sensitive information including messages, personal files, financial data, and passwords. This incident underscores the potential misuse of advanced surveillance technologies by government entities to target civil society members. The case highlights the growing concerns over digital privacy and the ethical implications of deploying such tools without proper oversight, emphasizing the need for stringent regulations to prevent abuse and protect individual rights.
5 months ago
Kill Chain
Germany 2026: Signal Account Hijacking Targets Senior Figures
In February 2026, Germany's Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) issued a warning about state-sponsored threat actors targeting high-ranking individuals through phishing attacks on messaging apps like Signal. The attackers employed social engineering tactics, impersonating support teams to deceive politicians, military officers, diplomats, and investigative journalists into granting access to their accounts. This campaign did not exploit technical vulnerabilities or deploy malware but leveraged legitimate app features to gain unauthorized access to sensitive communications. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/germany-warns-of-signal-account-hijacking-targeting-senior-figures/?utm_source=openai)) This incident underscores a growing trend of sophisticated social engineering attacks that exploit trust in legitimate platforms. Organizations must enhance user awareness and implement robust security measures to mitigate such threats, especially as attackers increasingly target high-profile individuals through commonly used communication tools.
5 months ago
Kill Chain
WhatsApp Unveils "Strict Account Settings" to Combat Spyware in 2024
In June 2024, WhatsApp introduced a lockdown-style "Strict Account Settings" feature to counter the growing threat of spyware targeting its user base—including journalists, activists, and public figures. This proactive measure allows users to limit messaging and attachment options from unknown contacts, mitigating risks of exploitation similar to past incidents like the Pegasus spyware attacks. The rollout follows WhatsApp’s ongoing legal battles with threat actors and reflects the platform’s drive to strengthen user privacy and security in the wake of sophisticated surveillance malware campaigns. This development highlights an industry-wide shift towards advanced, user-accessible security controls as spyware campaigns become more adept at circumventing traditional defenses. Organizations and high-risk users face mounting pressure from both regulatory frameworks and adversary innovation, compelling tech platforms to continually adapt and raise the bar for account protection and threat mitigation.
5 months ago
Kill Chain
WhatsApp Rolls Out Lockdown Security for High-Risk Users After Spyware Attacks
In early 2026, WhatsApp introduced a new 'Strict Account Settings' feature to defend high-risk users such as journalists and public figures against highly targeted spyware attacks. This rollout followed a series of incidents in recent years where advanced zero-click exploits—many attributed to government-linked actors—were used to deploy spyware like NSO Group’s Pegasus and Paragon Graphite onto users’ devices via messaging platforms. Exploits leveraged zero-day vulnerabilities in WhatsApp’s iOS and macOS clients, enabling attackers to compromise devices without user interaction, raising severe risks to privacy and personal safety for individuals facing nation-state targeting. This event is particularly relevant as threat actors increasingly adopt sophisticated, zero-click methods to compromise high-value targets. Security and privacy expectations for messaging apps are under heightened scrutiny, with regulators and civil society urging greater protections and rapid incident response to curtail such threats.
6 months ago
Kill Chain
Predator Spyware: New Evasion and Troubleshooting Capabilities Outpace Defenders
In June 2024, cybersecurity researchers at Jamf Threat Labs uncovered advanced anti-analysis and troubleshooting features in Predator spyware, developed by the Intellexa alliance. The spyware's sophisticated error code system enables operators to pinpoint why an infection attempt failed, such as detecting the presence of security tools (error code 304) or security researchers' activities. Predator also detects common investigation tools like netstat and automatically aborts installation, suppressing crash logs to thwart forensic analysis. These features demonstrate the spyware's focus on evading both defensive products and researcher scrutiny. This incident highlights a significant escalation in the arms race between threat actors and defenders, as commercial spyware rapidly evolves more effective evasion and detection-resistance capabilities. Organizations and individuals must recognize the ongoing advancement of targeted surveillance malware and enhance endpoint and network defenses accordingly.
6 months ago
Kill Chain
One Click IP Exposure: How Telegram Proxy Links Created a Privacy Vulnerability in 2026
In January 2026, security researchers revealed that Telegram users could have their real IP address exposed by clicking specially crafted proxy links disguised as regular usernames or harmless URLs. When users clicked these links in Telegram's Android or iOS apps, the app would automatically attempt to connect to the attacker-controlled proxy server, revealing the user's actual IP without further confirmation. This behavior, demonstrated across various public channels, posed targeted privacy risks, including location tracking and the potential for follow-on attacks. Telegram acknowledged the issue and stated they would introduce warnings to alert users about proxy links but did not commit to a timeline for deployment. This incident highlights a growing trend of information disclosure vulnerabilities related to messaging apps and link-based attacks, demonstrating the persistent risk of metadata and IP leaks in platforms used for privacy and circumvention. It brings renewed urgency to strengthen client security and increase user awareness, especially amid rising concerns over digital privacy and targeted cyber threats.
6 months ago
Kill Chain
US Treasury Lifts Sanctions on Key Intellexa Predator Spyware Figures
In December 2025, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) removed three individuals previously sanctioned for their involvement with Intellexa and its Predator commercial spyware from the Specially Designated Nationals (SDN) list. The individuals—Merom Harpaz, Andrea Nicola Constantino Hermes Gambazzi, and Sara Aleksandra Fayssal Hamou—were linked to leadership and distribution roles within the Intellexa Consortium. Their removal followed a petition and OFAC’s evaluation that they had separated themselves from the Intellexa ecosystem, but no underlying details or independent confirmation were disclosed. The original sanctions stemmed from their roles in developing, distributing, and enabling Predator software, a tool implicated in high-profile surveillance of civil society figures, including journalists and activists, through stealth zero-day and social engineering attacks. This case underscores the continued risks posed by commercial spyware vendors and associated compliance exposures. Ongoing public reporting highlights Predator’s persistent activity despite regulatory efforts, as well as geopolitical pressures that drive international balkanization and new attack trends targeting sensitive sectors. With regulatory frameworks evolving and threat actors shifting tactics, the risk of spyware misuse for human rights abuses and espionage remains acute.
6 months ago
Kill Chain
AI Deepfake Geospatial Maps Incident Exposes New Security Frontier (2025)
In December 2025, a high-profile security research initiative revealed significant risks in the unchecked proliferation of AI-generated deepfake satellite maps. Sparked by the personal experience of a deepfake attack, a 17-year-old cybersecurity researcher demonstrated how adversaries could blend or fabricate satellite imagery using advanced GANs and diffusion models. These manipulations, undetectable to the naked eye, could mislead governments and emergency responders, mask critical infrastructure weaknesses, or facilitate large-scale misinformation campaigns with potentially catastrophic consequences on national security and public trust. The incident highlights a rising threat: geospatial deepfakes are evolving rapidly, outpacing current detection solutions and exposing new vulnerabilities in organizations' data and decision pipelines. Growing reliance on AI-generated imagery and the lack of robust verification frameworks make this an urgent issue for security leaders and risk managers in both public and private sectors.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports