It’s a mystery … alleged unpatched Telegram zero-day allows device takeover, but Telegram denies

2026-03-30T14:51:47Z567e7a91304f3c57ea335da6524000a1971f041d692732afabcd23394e2104b2
active-exploitationaptcitrixdarkweb-leakdata-breachexploitfortinetinfostealerios-exploitmacospatchingphishingremote-code-executionsecurity-alerttelegramvulnerability-disclosurezero-day

What happened

Multiple high-risk incidents and actively exploited vulnerabilities reported: an alleged Telegram zero-day disclosed via ZDI (ZDI-CAN-30207, CVSS 9.8) that Telegram disputes; active exploitation of a critical Fortinet FortiClient EMS RCE via SQL injection (CVE-2026-21643, CVSS 9.1); active probing of a critical Citrix NetScaler ADC/Gateway memory overread (CVE-2026-3055, CVSS 9.3); Apple issuing lock-screen warnings for devices vulnerable to web-based exploits; Russia-linked APT TA446 using the DarkSword iOS exploit kit in targeted phishing; a new macOS info-stealer campaign (Infinity Stealer)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
567e7a91304f3c57ea335da6524000a1971f041d692732afabcd23394e2104b2
Enrichment time
2026-03-30T14:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · It’s a mystery … alleged unpatched Telegram zero-day allows device takeover, but Telegram denies · Baitaphish