It’s a mystery … alleged unpatched Telegram zero-day allows device takeover, but Telegram denies
2026-03-30T14:51:47Z•567e7a91304f3c57ea335da6524000a1971f041d692732afabcd23394e2104b2
active-exploitationaptcitrixdarkweb-leakdata-breachexploitfortinetinfostealerios-exploitmacospatchingphishingremote-code-executionsecurity-alerttelegramvulnerability-disclosurezero-day
What happened
Multiple high-risk incidents and actively exploited vulnerabilities reported: an alleged Telegram zero-day disclosed via ZDI (ZDI-CAN-30207, CVSS 9.8) that Telegram disputes; active exploitation of a critical Fortinet FortiClient EMS RCE via SQL injection (CVE-2026-21643, CVSS 9.1); active probing of a critical Citrix NetScaler ADC/Gateway memory overread (CVE-2026-3055, CVSS 9.3); Apple issuing lock-screen warnings for devices vulnerable to web-based exploits; Russia-linked APT TA446 using the DarkSword iOS exploit kit in targeted phishing; a new macOS info-stealer campaign (Infinity Stealer)
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 567e7a91304f3c57ea335da6524000a1971f041d692732afabcd23394e2104b2
- Enrichment time
- 2026-03-30T14:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.