eprint.iacr.org Russian Intelligence Exploits Signal Backup Flaw, Cryptographic Fix Proposed
Article Content
- •Russian intelligence exploited Signal's backup recovery key flaw, compromising thousands of accounts.
- •The FBI and CISA issued an advisory detailing the exploitation method on June 26, 2026.
- •A new cryptographic proposal, STEBR, aims to enhance backup key security with a three-layer architecture.
A critical vulnerability in Signal's backup recovery key system has been exploited by Russian intelligence agencies, specifically the FSB and GRU, allowing unauthorized access to users' message archives. The FBI and CISA issued an advisory on June 26, 2026, detailing how attackers used social engineering techniques to obtain backup keys, compromising thousands of accounts globally. The flaw stems from a static recovery key that, once disclosed, exposes the entire backup history without self-healing capabilities. A proposed solution, STEBR (Secure Timed-Erasure Backup Ratchet), introduces a three-layer architecture to enhance security by limiting the exposure window and requiring multiple credentials for access. This proposal was published on July 27, 2026, coinciding with the advisory's findings. The vulnerability highlights the risks associated with static keys in encrypted messaging systems, emphasizing the need for improved key management protocols.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Unc5792 and Signal in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Signal Enhances Security with Automatic Key Verification to Prevent Man-in-the-Middle Attacks Signal has launched Automatic Key Verification (AKV) to enhance security against man-in-the-middle attacks. This feature allows users to verify their chat connections without needing to compare safety numbers in person. AKV employs a key transparency system, supported by independent auditors Cloudflare and Trail of…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…