Daily brief at 7am Melbourne. Unsubscribe any time.

Sunday 28 June 2026

Fake "Support" Texts, Real Credential Theft: Russia's FSB Was Reading Your Messages

Russia's FSB ran a fake-support SMS campaign to hijack messaging accounts of officials across Ukraine, Europe, and the US — and the SSU/FBI joint disclosure is a masterclass in how modern credential theft actually works.

Lead story

Fake "Support" Texts, Real Credential Theft: Russia's FSB Was Reading Your Messages

The Security Service of Ukraine and the FBI have jointly disclosed a long-running Russian intelligence operation that used fake technical-support SMS messages to steal messaging credentials from government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States. The campaign is attributed to Russian intelligence services — and the operational detail in the joint disclosure makes it one of the more instructive espionage write-ups of the year.

The mechanics are straightforward, which is precisely what makes them effective. Targets received text messages impersonating legitimate platform support teams — think "your account has been flagged for suspicious activity, click here to verify." Once a target clicked through and entered credentials, attackers had access not just to current messages but to archived conversation history. For intelligence services, that archive is the prize.

What's notable here is the targeting profile. This wasn't a spray-and-pray phishing run after banking credentials. The victims were specifically people who matter: military officers coordinating defence, politicians shaping policy, activists whose communications could expose networks. That specificity tells you this was a patient, resourced operation — not opportunistic crime dressed up as espionage.

The campaign also illustrates a persistent problem with SMS-based authentication and verification flows. Even users who are generally phishing-aware can be caught off-guard by a well-timed message that mimics a platform they actually use. The fake support pretext is particularly nasty because it creates urgency ("your account is at risk") while appearing to come from a trusted source.

What defenders should take from this is less about the specific lure and more about the attack surface. Messaging platforms that offer SMS-based verification flows are inherently vulnerable to this kind of impersonation. Hardware security keys or app-based authentication — anything that can't be intercepted or spoofed over SMS — dramatically reduces the exposure.

The joint SSU/FBI disclosure is also a signal worth reading carefully. Joint attributions at this level of detail are relatively rare and typically indicate that both agencies have high confidence in the attribution and want to establish a public record. The timing — mid-2026, with Russia's war in Ukraine still active — suggests this is partly operational (warning targeted communities) and partly political (naming Russia publicly in a period of diplomatic flux).

For Australian readers, the targeting profile is directly relevant. Australian defence personnel, politicians, and civil society figures are routine targets of foreign intelligence services — including Russia, but especially China and Iran. The ACSC has previously warned about SMS-based phishing against Australian government users, and the broader pattern here maps cleanly onto techniques documented in Australian threat advisories. If your organisation issues mobile devices to staff in sensitive roles and those devices still rely on SMS for any authentication flow, this disclosure is a useful prompt to review that.

The full technical indicators from the joint SSU/FBI advisory are worth pulling into your threat intel platform. The lure templates, infrastructure patterns, and targeting criteria are all documented — and this kind of nation-state technique tends to be recycled across campaigns.

Also today

Chinese Framework Powers 200,000 Scam Sites — and the Toolkit Is Legitimate

Researchers have found that threat actors are mass-producing investment scam websites using templates built on DCloud's Uni-App, a legitimate cross-platform development framework popular in China. The result is a cottage industry of convincing-looking scam sites — around 200,000 identified so far — that are cheap to spin up and hard to distinguish from real investment platforms. The abuse of legitimate developer tooling is the key angle here: it makes takedowns harder (the framework itself isn't malicious) and gives scam pages a veneer of polish that pure hand-rolled fraud can't match. Australian victims of investment scams — already losing hundreds of millions annually per ACCC Scamwatch data — are likely encountering some of these sites.

SecurityWeek

LastPass Users Had Their Data Stolen — Again

LastPass is back in breach headlines, with Wired reporting another theft of user data. Given the password manager's history — the catastrophic 2022 breach exposed encrypted vaults that attackers are still cracking today — any further data exposure is significant for users who haven't already migrated. The specific nature of what was stolen this time is still being reported out, but the pattern is becoming difficult to ignore: LastPass has had more serious security incidents than any major password manager competitor. If you or your organisation are still on LastPass, this is a good weekend to evaluate alternatives. Bitwarden, 1Password, and Dashlane have all maintained cleaner records in recent years.

WIRED Security

Third-Party Breaches Are Costing the Education Sector — and It's Getting Worse

A Dark Reading analysis of recent breaches in the education sector finds that third-party vendor compromises — not direct attacks on schools or universities — are now the dominant breach vector. Student data, including health records and financial information, is flowing through dozens of specialist EdTech vendors whose security posture varies enormously. Ransomware groups have noticed: a single compromised vendor can yield data from hundreds of institutions simultaneously. The pattern maps closely onto the broader third-party risk problem documented across critical sectors. Australian universities, which collectively handle millions of student records and are heavy consumers of US-origin EdTech platforms, face direct exposure here — particularly under Privacy Act obligations for handling sensitive personal information.

Dark Reading

OpenAI Previews GPT-5.6 in Three Flavours — With Tighter Cyber Guardrails

OpenAI has released a limited preview of GPT-5.6 — codenamed Sol, Terra, and Luna — to a small group of partner organisations under a US government engagement framework. Sol is the flagship, Terra balances power and efficiency, and Luna is optimised for speed at lower cost. The notable addition is what OpenAI is calling its strongest-yet cyber safeguards baked into all three versions. Access is deliberately restricted at this stage, reflecting the ongoing White House oversight arrangement that shaped last week's rollout. The three-tier naming structure suggests OpenAI is moving toward a more explicit product segmentation model — different capability and safety profiles for different deployment contexts.

The Hacker News

Asian AI Startups Are Filling the Gap Left by Anthropic's Export Ban

With Anthropic's export restrictions continuing to lock out much of Asia from its most capable models, a wave of regional startups are launching what they're describing as Mythos-equivalent models — and doing so without the compliance overhead that comes with US-origin AI. The concern for US labs isn't just the current revenue loss; it's that Asian enterprises building workflows around locally developed models today are unlikely to switch back once restrictions ease. The window for US AI dominance in Asian markets may be closing faster than Washington's policy apparatus has accounted for. For Australia, which sits at the intersection of Five Eyes alignment and deep regional trade ties, the bifurcation of the global AI market creates its own strategic complexity.

TechCrunch

Apple's Vision Pro Hardware Lead Is Heading to OpenAI

Paul Meade, the Apple VP who oversaw the Vision Pro headset programme, is reportedly departing to join OpenAI's hardware team. The move is a significant signal about where OpenAI's hardware ambitions are headed — the Vision Pro, for all its commercial struggles, was one of the most technically complex consumer devices ever shipped. Meade's expertise is in premium spatial computing hardware, not commodity devices. OpenAI already hired former Apple design chief Jony Ive's firm for its consumer device project; adding someone with Meade's engineering depth suggests the hardware push is moving from concept to execution. This is worth watching alongside OpenAI's custom silicon (Jalapeño) move from last week — the pieces of a vertically integrated AI hardware stack are assembling quickly.

TechCrunch

Elon Musk's Orbital Data Centre Vision Draws Scepticism — Including From SoftBank's CEO

Masayoshi Son, whose SoftBank has made some of the most ambitious tech bets of the last decade, is reportedly among those unconvinced by Elon Musk's pitch for orbital data centres — server infrastructure running in low-Earth orbit rather than on the ground. The physics and economics are daunting: launch costs, thermal management in vacuum, latency for ground-based users, and the sheer capital required make it a tough case to build. Other investors and analysts are raising similar questions. The idea isn't entirely fanciful — there are niche use cases — but as a mainstream compute strategy it faces enormous practical obstacles. For now it reads more as a narrative device than a credible infrastructure roadmap.

TechCrunch

Apple Is Seeking an Exception to Buy RAM From a Pentagon-Blacklisted Chinese Supplier

Apple has approached the Trump administration for a waiver to purchase memory chips from CXMT, a Chinese semiconductor company blacklisted by the Pentagon for alleged ties to the People's Liberation Army. The motivation is clear: RAM prices have surged sharply, driven partly by AI infrastructure demand, and Apple has already raised prices across its product line citing unsustainable input costs. CXMT isn't legally off-limits for purchases, but the Pentagon blacklisting creates political risk. The request puts Apple in an awkward position — a company that has positioned itself on privacy and security grounds now seeking to buy components from a supplier the US military says shouldn't be supported. The outcome will be an interesting test of how much supply-chain pragmatism the current administration is willing to accommodate.

The Verge

AI Is Driving Your Next Price Hike — Apple's Tim Cook Says So Explicitly

Apple's CEO Tim Cook has publicly framed the company's recent price increases — up to $300 more on the 16-inch MacBook Pro — as a direct consequence of AI-driven demand for memory and storage components. The phenomenon, dubbed "RAMageddon" in some corners of the tech press, is hitting across the hardware industry: Xbox consoles are up nearly 25 percent, and the HomePod Mini got a $30 bump. The mechanism is straightforward — AI training and inference infrastructure is consuming DRAM and NAND flash at rates that have tightened supply for consumer devices. For Australian consumers, price increases are further amplified by the AUD/USD exchange rate, making an already expensive product cycle noticeably more painful.

The Verge

Matter Smart Home Standard Turns Four — Still Promising, Still Incomplete

A Verge deep-dive from inside the Connectivity Standards Alliance's Unify conference finds that Matter — the interoperability standard backed by Apple, Google, Amazon, and Samsung — is still very much a work in progress four years after its launch. The original promise was simple: buy any Matter-certified device and it'll work with any platform. The reality is more complicated, with implementation inconsistencies, feature parity gaps between ecosystems, and a slower-than-expected device certification pipeline. The industry hasn't abandoned Matter, but the candour inside the conference rooms apparently contrasts with the public optimism. For Australian consumers navigating smart home choices, the practical takeaway remains: ecosystem lock-in hasn't gone away yet.

The Verge

A Founder Used Claude to Navigate His Own Cancer Diagnosis — Here's What Actually Happened

Connor Christou, a health-focused startup founder, fed his entire medical record into Anthropic's Claude after a cancer diagnosis — blood results, scan data, wearable outputs, journal entries — and used the model as an active reasoning partner throughout treatment planning. TechCrunch's account is specific and measured rather than triumphalist: Claude helped him ask better questions of his oncology team and identify patterns across his data, but it wasn't replacing clinical judgement. The story is a useful grounded counterpoint to both AI-in-healthcare hype and blanket scepticism. It also raises genuine questions about data privacy — feeding sensitive health records into a commercial AI system sits in a regulatory grey zone in most jurisdictions, including Australia under the Privacy Act.

TechCrunch

Sources consulted