The BlackBerry Security Briefing Center
Situational Awareness. Now.
Situational Awareness. Now.
The gap between a resilient communications architecture and a vulnerable one usually only becomes visible after an incident. This briefing center is a running record of that gap, built for the decision-makers operating in rapidly changing mission-critical environments.
%3Aquality(100)&w=3840&q=75)
Four Incidents, One Pattern: Trusted Platforms Are the New Perimeter
WHAT HAPPENED Four unrelated disclosures in one week — a Microsoft 365 calendar backdoor, a cascading supply-chain breach, hijacked NATO-adjacent cameras, and a ten-month undetected ministry breach — all built on abused trust, not exploited code. BLACKBERRY PERSPECTIVE Three of four needed no vulnerability at all. Architecture built outside shared, general-purpose trust boundaries doesn't inherit that exposure. Keep reading ›
%3Aquality(100)&w=3840&q=75)
Phishing Campaign Exploits Signal Backup Recovery Keys
WHAT HAPPENED Russian actors are phishing Signal Backup Recovery Keys from officials and journalists — keys that unlock a victim's full archive and outlive a phone swap. BLACKBERRY PERSPECTIVE Signal's encryption held. The self-custodied key didn't. Custody belongs with the organization — the gap BlackBerry SecuSUITE closes. Keep reading ›
%3Aquality(100)&w=3840&q=75)
CISA FortiBleed Advisory
WHAT HAPPENED Stolen credentials exposed 86,644 internet-facing Fortinet firewalls across 194 countries — no new vulnerability, just weak credentials and no MFA. The dataset is circulating in criminal markets now. BLACKBERRY PERSPECTIVE BlackBerry UEM enforces access independent of the perimeter. BlackBerry SecuSUITE routes through a sovereign channel the compromised device never touches. BlackBerry AtHoc keeps coordination running when the primary environment is down. Keep reading ›
Key Learnings – August 2026
Legitimate Features Are the New Attack Path
Linked devices, archiving compliance tools, and support requests are being weaponized because they're trusted by default, not because they're poorly built.
Third-Party Dependency as a Recurring Failure Point
Multiple recent incidents are tracing back to the same root cause: infrastructure an organization doesn't control was the point of compromise or exposure.
Attackers Are Exploiting Trust, Not Encryption
Attackers are bypassing strong encryption entirely by compromising the device-linking and account-recovery features users trust by default.
Supply Chain Vendors Are the Target
Smaller vendors that hold archived communications for multiple agencies and companies are weaker links in the supply chain and can expose all the data in a single breach.
All Critical Briefings – August 2026
CI Fortify Answers the Gap Minnesota's Attack Exposed
WHAT HAPPENED
CISA and Five Eyes agencies released a six-step guide for isolating OT systems during cyberattacks, days before a coordinated attack hit 30+ Minnesota water utilities.
BLACKBERRY PERSPECTIVE
Isolation protects the network. It doesn't keep people talking once that network goes dark. BlackBerry AtHoc and BlackBerry SecuSUITE close that gap.
_______________________________________________________________________________
Intern Arrested for Alleged Espionage Inside NATO's Top Operational Command
WHAT HAPPENED
An intern at SHAPE, NATO's top operational command, was arrested after internal security flagged her for suspected spying on behalf of an undisclosed third country.
BLACKBERRY PERSPECTIVE
When the person holding legitimate access is the risk, the only durable control is a communications architecture where that access is scoped, auditable, and revocable at the organizational level, which is precisely what NATO Restricted certification is built to assume.
_______________________________________________________________________________
Chinese and Russian Code Embedded in Apps Marketed to U.S. Military Personnel
WHAT HAPPENED
A university study found 64 percent of apps marketed to U.S. troops carry foreign-sourced SDKs, including Huawei's HMS Core in apps tied to National Guard units.
BLACKBERRY PERSPECTIVE
A privacy label says what a developer claims, not what the code inside actually does. BlackBerry UEM vetting and continuous monitoring reach the embedded supply chain, not just the listing.
_______________________________________________________________________________
TELESHIM Abuses Telegram's Own API for C2
WHAT HAPPENED
Zscaler identified malware against Middle East governments that routes C2 traffic through Telegram's own API, blending in with ordinary messaging activity.
BLACKBERRY PERSPECTIVE
When malware hides inside a messaging platform's API, the platform's popularity is the vulnerability. BlackBerry SecuSUITE's closed channel has no equivalent surface to hide inside.
_______________________________________________________________________________
Adversaries Are Already Inside Australia's Critical Infrastructure
WHAT HAPPENED
ASIO's 2026 Threat Assessment revealed nation-state hackers compromised an Australian critical infrastructure provider, stealing credentials from active users and the IT admins guarding the network — mapping it to cripple at a time of their choosing.
BLACKBERRY PERSPECTIVE
A stolen admin credential stays valid until someone revokes it. BlackBerry UEM's continuous compliance monitoring and centralized revocation cut standing access the moment compromise is suspected, not after the network's already mapped.
_______________________________________________________________________________
%3Aquality(100)&w=3840&q=75)
What the Report Covers
• What "mission-critical" actually demands from a communications platform • Total communications integrity: identity, device, policy, sovereignty • Mission orchestration: unified command across people, systems, and signals • How the highest-tier security authorities globally validated BlackBerry • Architecture decisions that cannot be approximated by commercial alternatives
Free downloadFind what this means for you
Get the Briefing Behind the Briefing
These summaries are the surface. Talk to a BlackBerry Secure Communications expert about what this month's incidents mean for your agency's specific architecture, certifications, and threat exposure.