UTA0560 exploited a Chrome-Windows zero-day chain against NGOs to deploy GRIMWEDGE; APT31 used the same chain to install LONGTALE.
Experts urge any organisation running self-managed GitLab instances to not wait for normal patch cycles and to remediate CVE-2026-85706 urgently.
A high-severity Telegram Desktop flaw allowed malicious JavaScript in bot-created buttons to steal chat content when conversations were exported as HTML.
A Telegram Desktop flaw lets bots inject JavaScript into exported chats, enabling data theft and page manipulation.