Forwarded from exploit.org
SECURITY ALERT ⚠️
Possible RCE was detected in Telegram's media processing in Telegram Desktop application.
This issue expose users to malicious attacks through specially crafted media files, such as images or videos.
For security reasons disable auto-download feature. Please follow these steps:
1. Go to Settings.
2. Tap on "Advanced".
3. Under the "Automatic Media Download" section, disable auto-download for "Photos", "Videos", and "Files" across all chat types (Private chats, groups, and channels).
We are currently investigating this vulnerability.
Possible RCE was detected in Telegram's media processing in Telegram Desktop application.
This issue expose users to malicious attacks through specially crafted media files, such as images or videos.
For security reasons disable auto-download feature. Please follow these steps:
1. Go to Settings.
2. Tap on "Advanced".
3. Under the "Automatic Media Download" section, disable auto-download for "Photos", "Videos", and "Files" across all chat types (Private chats, groups, and channels).
We are currently investigating this vulnerability.
I ported THOUSANDS of apps to Windows 95
https://www.youtube.com/watch?v=CTUMNtKQLl8
Backport of .NET 2.0 - 3.5 to Windows 9x
GitHub Repo
https://www.youtube.com/watch?v=CTUMNtKQLl8
Backport of .NET 2.0 - 3.5 to Windows 9x
GitHub Repo
YouTube
I ported THOUSANDS of apps to Windows 95
▶VOTE for my NEXT PROJECT: https://www.patreon.com/posts/march-2024-poll-101363953
▶dotnet9x on GitHub: https://github.com/itsmattkc/dotnet9x
▶FOLLOW on Twitter: https://twitter.com/itsmattkc
▶FOLLOW on Twitch: https://twitch.tv/mattkclive
▶FOLLOW on…
▶dotnet9x on GitHub: https://github.com/itsmattkc/dotnet9x
▶FOLLOW on Twitter: https://twitter.com/itsmattkc
▶FOLLOW on Twitch: https://twitch.tv/mattkclive
▶FOLLOW on…
⚠ PuTTY CVE-2024-31497
📰Brief: attacker can gain access to private key with public key and some signed messages on hand via forged identification signature of legitimate user. Signed messages may be publicly visible due to storage in public Git.
🚩Possibilities: login into any servers key was used in, supply chain attacks software maintained git, etc.
📗Affected versions: 0.80 and prior.
📚Full description: https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html
📰Brief: attacker can gain access to private key with public key and some signed messages on hand via forged identification signature of legitimate user. Signed messages may be publicly visible due to storage in public Git.
🚩Possibilities: login into any servers key was used in, supply chain attacks software maintained git, etc.
📗Affected versions: 0.80 and prior.
📚Full description: https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html
Awhile back we heard rumors of a Telegram RCE 0day. We brushed it off as silly memes. Turns out the 0day was 100% real and you're all probably pwned.
It was unveiled on XSS. Nerds celebrated
(joking about pwned part... kind of)
More information: https://www.bleepingcomputer.com/news/security/telegram-fixes-windows-app-zero-day-used-to-launch-python-scripts/
It was unveiled on XSS. Nerds celebrated
(joking about pwned part... kind of)
More information: https://www.bleepingcomputer.com/news/security/telegram-fixes-windows-app-zero-day-used-to-launch-python-scripts/
BleepingComputer
Telegram fixes Windows app zero-day used to launch Python scripts
Telegram fixed a zero-day vulnerability in its Windows desktop application that could be used to bypass security warnings and automatically launch Python scripts.