A Telegram-marketed phishing kit illustrates how cloud identity abuse has been industrialized, with ready-made lures and reported paths for token theft, device-code tricks, and OAuth consent abuse.
A reported multi-stage malware chain tied to OctLurk points to a familiar but effective pattern: trusted processes, host-bound payloads, and low-noise communications that make analysis harder than delivery.
A short-lived removal from Apple’s marketplace showed how quickly app availability, policy enforcement, and user confidence can collide in one centralized distribution channel.
Telegram’s temporary removal from Apple’s App Store shows how a single distribution gate can interrupt downloads, block reinstalls, and unsettle users without touching the app itself.
A macOS malware variant tied to poisoned Xcode projects is being described as memory-heavy and evasive, with reported targeting of Chrome and Telegram that puts developer workflows under the microscope.
A reported Telegram instruction, an open-source agent framework, and a tool-calling model formed a chain that may have let one session move from conversation to exploit selection with little human steering.
Russia is pushing to place Pavel Durov on an international wanted list, but the deeper issue is how a messenger built for reach and privacy becomes a target when states turn platform design into a national-security argument.
A Russian charge involving Telegram’s founder underscores how moderation duties can turn a messaging platform into a legal and technical fault line.
Threat researchers traced a targeted campaign to three newly named malware families, showing how a familiar messaging platform can be repurposed as covert command infrastructure.
A trust-based campaign tied to BlueNoroff shows how compromised messaging accounts and fake meetings can turn one breach into the next.
A reported Python framework ties together wireless credential extraction, disruption, proxy use, and DDoS-style traffic, showing how a single script can mix access, control, and impact.
A newly described intrusion set used Telegram bots for command and control, then layered in obfuscation and environment-bound payloads to make analysis and detection harder.
A Windows delivery path built on trusted components and remote file retrieval is being used to chase passwords, active sessions, and wallet-related data with unusually little on-disk noise.
A newly examined malware chain shows how attackers can hide command-and-control inside a trusted messaging service while using layered loaders and host-bound checks to slow defenders down.
A reported macOS infostealer shows how stolen sessions, browser secrets, and fake wallet launch paths can move a single endpoint problem into account and crypto risk.
A Telegram lure impersonating UniCredit points to a deeper mobile threat: an Android banking trojan built for on-device fraud, not simple password theft.
Telegram’s t.me links stopped resolving after a .ME registry status change, showing how a public entry point can fail even when the underlying app still works.
A worldwide t.me suspension shows how a seemingly small naming layer can interrupt browser access, automation, and fast-moving workflows that depend on it.
A status change on t.me shows how one domain can sit at the center of a messaging platform’s identity, sharing, and access paths.
A registry-level hold on t.me shows how a single domain action can disrupt Telegram's link ecosystem worldwide while the main app may still be reachable.