Mezha Critical Telegram Zero-Day Vulnerability Exposes User Accounts to Remote Hijacking
Article Content
- •A zero-day vulnerability in Telegram allows remote account hijacking without user action.
- •The flaw has a CVSS score of 9.8, indicating a critical level of risk.
- •Users are urged to update their Telegram app as soon as patches are released.
A critical zero-day vulnerability in Telegram, discovered by researcher Michael DePlante, allows attackers to remotely hijack user accounts without any user interaction. The flaw has been assigned a CVSS score of 9.8, indicating its high risk level. It affects the confidentiality, integrity, and availability of user data and is categorized as easily exploitable over a network. Telegram has up to 120 days to release a patch, but experts anticipate an earlier response due to the severity of the issue. Users are advised to monitor for updates and implement security measures such as strong passwords and two-factor authentication. The vulnerability is identified as ZDI-CAN-30207, and no public technical details are available yet. This situation highlights the necessity for users to keep their software updated and remain vigilant against potential threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…