Urgent.News

What's breaking now, across thousands of outlets.

Tech

Telegram Desktop vulnerability allowed any user's file to be stolen

Telegram Desktop vulnerability allows any user's file to be stolen. An attacker can craft a link that, when clicked, results in the victim's Telegram account being compromised. The link arrives as multiple commands, and the third command enables an attacker to read and send any file from the victim's machine to a chat. This occurs due to an injection vulnerability and the lack of authorization checks within Telegram Desktop.

The flaw allows the attacker to read any file on the victim's disk, without needing their credentials or any additional foothold. The only requirement is for the attacker to trick the victim into clicking a malicious link in a group or broadcast channel.

Written by urgent.news from Hacker News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at beaksec.github.io →

More in Tech

48-Hour Field Notes: I Would Fingerprint the Locale Before I Blame the Fixture

Have you ever watched a text fixture pass on your laptop and then fail on a clean remote job? I keep meeting that surprise when the file looks identical and the decoder still disagrees with it.

  • Record locale before diagnosing text fixture failures.
  • Consider codec as first suspect for UnicodeDecodeError.
  • Compare free model and free server environments.

When Cloudflare WAF detections fail, choose a rule response for each route

A security detection can fail before it decides whether a request is safe. That is a different event from a detection matching an attack.

  • The field is an array of strings, indicating failures reported by various detectors.
  • Use len(cf.appsec.request.faileddetections) gt 0 to match any reported failure in rule expressions.

SafeLine WAF vs Imperva: Self-Hosted WAF vs Enterprise Cloud Protection

SafeLine WAF vs Imperva: Self-Hosted WAF vs Enterprise Cloud Protection When people compare SafeLine to Imperva, they're usually comparing two very different things: a lightweight self-hosted WAF and…

  • SafeLine is a self-hosted WAF from Chaitin, runs as reverse proxy, blocks SQL injection, XSS, bots.
  • Imperva is an enterprise cloud WAF with CDN, DDoS protection, bot management at network edge.

More from Saturday 10 October →