Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Comments

  • LeviLevi Member
    edited March 30

    Don’t be lazzy, add hand written tl;tr summary, not just dry links.

    Thanked by 2384_cz forest
  • emaiIemaiI Member

    Tldr from the second link.

    This flaw does not exist. This researcher falsely claims that a corrupted Telegram sticker could be used as an attack vector — which completely disregards that all stickers uploaded to Telegram are validated by its servers before they can be played by Telegram apps.

    Thanked by 1Levi
  • A critical security flaw has been unearthed in Telegram, the world’s leading encrypted messaging platform, drawing significant attention within the cybersecurity community.. Discovered by Michael DePlante (@izobashi) of the Trend Micro Zero Day Initiative (ZDI), the vulnerability—tracked as ZDI-CAN-30207—has been assigned a severity score of 9.8 on the CVSS scale.

    Reported to Telegram on March 26, 2026, the flaw represents a “worst-case scenario” for digital privacy, as it allows for remote, unauthenticated exploitation without any user interaction.

    The vulnerability’s technical vector—AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H—puts more than one billion active users of the platform at risk:

    Network (AV:N): The attack can be launched remotely over the internet.
    Low Complexity (AC:L): No specialized conditions or complex bypasses are required to trigger the flaw.
    No Privileges (PR:N): The attacker does not need an account or special permissions on the target system.
    No User Interaction (UI:N): This is a zero-click vulnerability. A victim does not need to click a link, open a file, or even be active on the app for their system to be compromised.
    High Impact (C:H/I:H/A:H): A successful exploit grants total control, allowing attackers to steal data (Confidentiality), modify system files (Integrity), and crash services (Availability).
    The exact technical details remain under wraps to prevent immediate exploitation. According to the ZDI’s upcoming advisory portal, the public disclosure date is set for July 24, 2026. This gives the vendor a four-month window to develop and deploy a patch before the full mechanics of the bug are revealed to the public.

    Historically, vulnerabilities in messaging apps have been highly sought after by state-sponsored actors and mercenary “spyware” groups for high-value targeting. Given the 9.8 severity rating, ZDI-CAN-30207 likely involves a fundamental flaw in how the application handles incoming data, such as media files or automated bot requests.

    Until a formal patch is released, security experts recommend the following:

    Enable Automatic Updates: Ensure your Telegram client (Desktop, iOS, and Android) is set to update automatically.
    Limit Contact: Restrict who can send you messages and files in the Privacy and Security settings.
    Monitor Official Channels: Watch for an “Emergency Security Update” notification from Telegram.
    Update:

    A Telegram spokesperson told us: “This flaw does not exist. This researcher falsely claims that a corrupted Telegram sticker could be used as an attack vector — which completely disregards that all stickers uploaded to Telegram are validated by its servers before they can be played by Telegram apps.”

    from the article

    Thanked by 1host_c
  • @Protocol903 said: the world’s leading encrypted messaging platform

    Telegram is not E2EE so what are they smoking?

    Thanked by 2oloke tentor
  • @Netralex said: Telegram is not E2EE so what are they smoking?

    ssl encryption :p

    Thanked by 1Netralex
  • @Protocol903 said:

    @Netralex said: Telegram is not E2EE so what are they smoking?

    ssl encryption :p

    SSL 3.0 bestest secure encryption no government will have access to my private cat sticker collection.

    Thanked by 1Protocol903
  • dbadudedbadude Member

    russian tech is flawed by design

  • ThrowRaPestThrowRaPest Member, Patron Provider

    @Levi said:
    Don’t be lazzy, add hand written tl;tr summary, not just dry links.

    I agree, this annoys me too.

  • JosephFJosephF Member

    @Levi said:
    Don’t be lazzy, add hand written tl;tr summary, not just dry links.

    That's what AI is for.

  • Carlin0Carlin0 Member
    edited March 30

    @Levi said:
    Don’t be lazzy, add hand written tl;tr summary, not just dry links.

    I don't have time, if you're interested, click the links and read them, everyone else can move on...

  • xaocxaoc Member

    @Carlin0 said:

    @Levi said:
    Don’t be lazzy, add hand written tl;tr summary, not just dry links.

    I don't have time, if you're interested, click the links and read them, everyone else can move on...

    It's "read the links and click them", I think.

Sign In or Register to comment.