-
A stored cross-site scripting (XSS) vulnerability in Telegram Desktop could enable attackers to steal the contents of exported chat histories by embedding malicious code in an inline keyboard button, according to security researchers. This issue affect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging platform and blocking reinstalls for users who had previously deleted the app. This global d…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram while operating almost entirely from memory with aggressive polymorphism and defense evasion. A…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are increasingly blending malicious traffic with legitimate services, and a newly uncovered campaign shows how far this tactic has evolved. The activity has been attributed to a threat actor with links to East Asia, with researchers uncovering …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram feature…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Forg365 is a commercial phishing-as-a-service (PhaaS) platform specifically targeting Microsoft 365 users. It employs methods such as device-code phishing, adversary-in-the-middle (AiTM) workflows, AI-assisted lure generation, and token persistence too…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Millenium RAT version 4.* exposes a compact but potent evolution: the malware has migrated from .NET to native C++, while retaining a stealthy Telegram-based command-and-control (C2) model that requires no bespoke server infrastructure. The sample set …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A long-running Telegram influence and fraud campaign where a solo threat actor leveraged stolen Google Gemini API keys and jailbroken AI to automate content generation, credential theft, and infrastructure operations at scale. Tracked as “bandcampro,” …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


