Connect with us

Infosecurity

Russia wants Telegram founder Pavel Durov on international wanted list for aiding terrorism

Published

on

Telegram founder Durov

Russia escalates legal war against Telegram founder

Russia’s Federal Security Service (FSB) has charged Telegram founder Pavel Durov with aiding terrorist activity and is pushing for an international arrest warrant. The move marks a sharp escalation in Moscow’s long-running battle with the encrypted messaging app, which has nearly 90 million users inside the country.

The FSB alleged Wednesday that Ukrainian intelligence used Telegram to recruit Russians — including teenagers — for sabotage missions. The agency specifically named a dating bot called Daivinchik, which operates within Telegram and boasts up to 16 million monthly users. According to the FSB, Ukrainian operatives posed as young women online, built relationships with men, then persuaded or coerced them into carrying out attacks.

Russian authorities said 46 people between the ages of 12 and 22 have been detained since last summer over the alleged recruitment campaign. The FSB released a video it claims shows several young people confessing to setting fire to gas stations after being recruited through Telegram by anonymous handlers. Recorded Future News could not independently verify those claims or the authenticity of the videos. Ukraine’s intelligence services did not comment.

What is Daivinchik and why does Russia want it banned?

Daivinchik functions like Tinder but runs entirely within Telegram. It was added to Russia’s official register of banned websites in December over content authorities classified as child pornography and what Russia terms LGBT propaganda. The bot’s popularity — 16 million monthly users — makes it a prime target for Moscow’s content moderation crackdown.

The FSB claims Telegram failed to remove channels and bots allegedly used by Ukrainian intelligence, as well as terrorist and extremist groups. That failure, the agency argues, amounts to aiding terrorist activity — a charge that carries a prison sentence of up to 15 years under Russian law.

Durov’s defiant response: a middle finger and a warning

Telegram did not issue a formal statement after the FSB’s announcement. But the company’s press service account on X posted a photo of Durov raising his middle finger — an image originally published by Durov in 2011 during his dispute with Mail.ru over control of VKontakte, the social network he founded before launching Telegram.

Durov said in February that Russian authorities had already opened a criminal case against him on similar grounds. “Each day, the authorities fabricate new pretexts to restrict Russians’ access to Telegram as they seek to suppress the right to privacy and free speech,” he said at the time. “A sad spectacle of a state afraid of its own people.”

Although Telegram is now reportedly inaccessible in Russia without a VPN or other circumvention tools, Russian government institutions — including the Kremlin — continue to publish updates on the platform daily. That contradiction has not been lost on critics.

Earlier this month, Kremlin spokesman Dmitry Peskov said discussions with Telegram over restoring broader access were continuing, though he suggested the company had shown little interest in negotiations. Andrei Svintsov, deputy chairman of the State Duma’s Committee on Information Policy, told TASS that Telegram could operate legally if it opened a representative office in Russia, stored Russian users’ personal data inside the country, and cooperated with security services on terrorism investigations.

Durov’s legal troubles go far beyond Russia

The Russian case adds to a growing pile of legal pressure on Durov abroad. In August 2024, French authorities detained him upon arrival at an airport and later charged him over allegations that Telegram failed to adequately combat criminal activity and cooperate with law enforcement. The French investigation focused on Telegram’s alleged use in distributing child sexual abuse material, facilitating drug trafficking, fraud, and other organized crime.

Durov has denied wrongdoing, arguing that Telegram complies with applicable laws and responds to legitimate legal requests. After spending several months in France as part of the investigation, he returned to Dubai in March, describing his arrest as “absurd.”

“The only outcome of my arrest so far has been massive damage to France’s image as a free country,” he said.

Born in Russia, Durov launched Telegram with his brother in 2013 after leaving VKontakte. The company later moved its headquarters to Dubai. Durov became a citizen of the United Arab Emirates in 2021 and also obtained French citizenship. His current whereabouts are unclear, though he said last week that he was in Georgia.

What happens next for Telegram and its founder?

Russia’s push for an international arrest warrant puts Durov in a precarious position. Even if he avoids Russian territory, the warrant could complicate his travel to countries that have extradition treaties with Moscow. The FSB’s charges also raise the stakes for Telegram’s content moderation policies, which have long been a flashpoint with governments worldwide.

Telegram’s refusal to comply with Russian demands — including content removal and data localization — has made it a target. But the platform’s encryption and ease of use have also made it a valuable tool for activists, journalists, and ordinary citizens in repressive environments. Durov has consistently framed the Russian government’s actions as an attempt to force users onto state-controlled services.

For now, the standoff shows no signs of resolution. The FSB’s latest charges are unlikely to change Telegram’s behavior, and Durov shows no inclination to negotiate. The question is whether the international community — or France, where Durov is a citizen — will treat Russia’s arrest warrant as credible or as another chapter in Moscow’s campaign against independent communication platforms.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

Laundry Bear’s webmail hackers had more in store after February, report says

Published

on

Laundry Bear hackers

Laundry Bear’s second, stealthier wave

Researchers at Proofpoint say the Russian-linked hacking group known as Laundry Bear didn’t stop with its Zimbra attacks earlier this year. A day before a global alert went out in late July, the same crew was already exploiting a fresh bug in Microsoft Outlook Web Access (OWA).

The finding, published Wednesday, expands the timeline of a campaign that government agencies and cybersecurity firms first flagged on July 23. That initial warning centered on a vulnerability in Zimbra Collaboration Suite’s webmail platform, which Laundry Bear had abused as recently as February.

Now Proofpoint says the group — also tracked as TA488 and Void Blizzard — began targeting OWA users on July 22, the day before the international advisory. The victims: US and European government entities, plus organizations in telecom, finance, hospitality and aerospace.

Half-click exploits and a new implant called OWAReaper

The attack chain relied on “half-click” exploits, meaning that simply opening a malicious email was enough to trigger the infection. No further user action was required.

Proofpoint described the payload as a JavaScript browser-based backdoor it named OWAReaper. The researchers called it “the most sophisticated backdoor delivered via half-click exploits that Proofpoint has observed at the time of writing,” citing its suite of subtle persistence mechanisms.

Greg Lesnewich, one of the report’s authors, posted on social media that OWAReaper was “one of the coolest implants we’ve ever examined.”

Zero-day potential

The researchers said it’s “feasible” that Laundry Bear was exploiting the OWA vulnerability as a zero-day — meaning the group had found and weaponized the bug before Microsoft was even aware of it. The flaw, tracked as CVE-2026-42897, was first publicized and patched in May. Microsoft posted remediation guidance in mid-July, months after the group allegedly began laying groundwork for the campaign in March.

An upgrade in tradecraft

Proofpoint assessed that the malware campaign represented “an improvement in the group’s tradecraft and capability.” The goal remained the same as the Zimbra operation: steal emails and account credentials. But the method evolved.

Dutch authorities and Microsoft first identified Laundry Bear as an advanced persistent threat (APT) group last year. US prosecutors have linked the group to the Russian IT firm Yutek-NN, which has connections to the FSB intelligence agency.

The OWAReaper campaign shows that Laundry Bear is adapting its toolkit and expanding its target list. For organizations still running unpatched OWA instances, the window for protection is narrowing.

What comes next

Proofpoint acknowledged that it didn’t have enough time to include the July 22 discovery in its initial alert. The update now gives defenders a fuller picture of the group’s recent activity.

Security teams should prioritize patching both Zimbra and OWA vulnerabilities, monitor for half-click exploit indicators, and review accounts for unusual OWA session behavior. The half-click vector makes traditional user training less effective — the infection starts before the user can make a choice.

Laundry Bear’s persistence and growing sophistication suggest that webmail platforms will remain a prime target for state-backed espionage. The group’s ability to pivot from Zimbra to OWA within months signals a flexible, well-resourced operation.

For now, OWAReaper is the group’s most advanced tool. Whether it’s the last remains an open question.

Continue Reading

Infosecurity

Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques

Published

on

Phishing initial entry method

Phishing Surges as the Top Attack Vector

Phishing has reclaimed its spot as the number one way cyber-attacks begin. According to a new report from Cisco Talos, covering March through June 2026, phishing was the initial entry method in just over half of all incidents that required professional remediation.

That’s a sharp jump from the previous quarter, when phishing accounted for only a third of cases. The report, published July 28, makes clear: attackers are doubling down on social engineering — and they’re getting better at it.

Other common entry points included exploitation of public-facing applications and drive-by compromise attacks, where a user simply visits a booby-trapped website. But phishing was the clear leader.

The QR Code Twist: A New Kind of Bait

Why the spike? Attackers are experimenting with fresh tools and techniques designed to slip past defenses. One standout example: a QR code phishing campaign targeting organizations to steal Microsoft 365 credentials.

Here’s how it works. The attacker, tracked by Cisco Talos as UAT-11764, auto-generates PDF documents tailored to each victim. Inside the PDF: a QR code. Scan it, and you land on a credential harvesting page hosted on a trusted cloud platform like SharePoint or Microsoft 365.

Two things make this tricky to stop. First, traditional email gateways often don’t flag QR codes as malicious — they’re just images. Second, the phishing pages live on legitimate infrastructure, so they don’t trigger typical security alerts.

Once the attacker has the credentials, they don’t stop at inbox access. They create email inbox rules to hide their tracks, then use the compromised account to blast more phishing emails to the victim’s contacts. The campaign was still active as of late June 2026.

“By weaponizing existing, trusted infrastructure like SharePoint and Microsoft 365, UAT-11764 can bypass many standard email security gateways,” the report warns. Defenders are advised to block or flag emails containing QR codes inside PDF attachments, enforce phishing-resistant multi-factor authentication, and watch for suspicious inbox rule creation.

Phishing-as-a-Service: Crime Made Easy

The report also highlights the growing sophistication of phishing-as-a-service (PhaaS) kits. These are off-the-shelf toolkits that let almost anyone run a phishing campaign — no coding skills required.

Modern PhaaS platforms come with a full suite of post-compromise tools. Capabilities observed during the period include:

  • Automated token management
  • Persistent access through Primary Refresh Tokens (PRTs)
  • OneDrive and SharePoint administration
  • Geo-dynamic templates that change the phishing page based on the victim’s location
  • Inbox rule manipulation
  • Cross-account keyword monitoring
  • Collaborative token sharing among attackers

Some kits can even bypass MFA by abusing the OAuth device authorization flow — a technique that doesn’t steal passwords but tricks the authentication process itself.

Researchers also found advanced anti-analysis features, including layered evasion mechanisms and encrypted client-side payloads. The report calls this “the increasing sophistication of modern PhaaS platforms.”

How to Defend Against These Evolving Threats

Cisco Talos offers concrete steps for organizations trying to stay ahead. The advice is practical, not theoretical:

  • Deploy phishing-resistant MFA — and configure it properly. Not all multi-factor authentication is equal.
  • Centralize your logging with adequate retention. You can’t detect what you don’t record.
  • Patch aggressively and reduce your exposed infrastructure. Fewer doors mean fewer entry points.
  • Set strict outbound email thresholds to limit how many messages a single account can send. This can stop a compromised mailbox from becoming a spam cannon.

The takeaway? Phishing isn’t going away. But with the right defenses — and awareness that attackers are constantly refining their methods — organizations can make themselves a much harder target.

Continue Reading

Infosecurity

Google Drops Massive Chrome 151 Update: 370 Vulnerabilities Patched, 7 Critical

Published

on

Chrome 151 vulnerabilities

Google’s biggest Chrome security update of the year just landed

On July 29, Google dropped patches for a staggering 370 security vulnerabilities in Google Chrome. That’s not a typo — three hundred and seventy flaws, seven of them rated critical. The update pushes the browser to version 151 for Windows, Mac (151.0.7922.71/.72), and Linux (151.0.7922.71).

For context, the typical monthly Chrome update addresses somewhere between 20 and 50 bugs. This one is nearly ten times that. It’s the kind of patch cycle that makes security teams sit up — and makes you want to check your browser version right now.

What’s inside the Chrome 151 patch: 7 critical CVEs

The seven critical vulnerabilities all involve memory management or input validation issues. Google’s internal security researchers reported them between May 18 and June 14, 2026. Here’s the breakdown:

  • CVE-2026-17650 — Use after free in Compositing (reported May 18)
  • CVE-2026-17651 — Insufficient validation of untrusted input in Dawn (May 28)
  • CVE-2026-17652 — Use after free in Views (June 2)
  • CVE-2026-17653 — Use after free in Skia (June 5)
  • CVE-2026-17654 — Race condition in the Updater (June 10)
  • CVE-2026-17655 — Insufficient validation of untrusted input in ANGLE (June 11)
  • CVE-2026-17656 — Use after free in Ozone (June 14)

“Use after free” bugs are a classic memory corruption pattern. A program tries to access memory after it’s been freed, which can let an attacker run arbitrary code. They’re the kind of flaw that browser makers dread — and that exploit developers love.

Dawn and ANGLE: The graphics pipeline under scrutiny

Two of the critical bugs hit graphics-related components. CVE-2026-17651 targets Dawn, Google’s WebGPU implementation. CVE-2026-17655 affects ANGLE, the open-source translation layer that converts OpenGL ES calls into Vulkan, DirectX, or Metal. ANGLE is what lets Chrome run 3D graphics smoothly across different hardware without requiring special drivers. A flaw there could potentially allow an attacker to corrupt GPU memory or crash the renderer.

The Updater race condition (CVE-2026-17654) is worth noting too. The auto-update mechanism is a critical part of Chrome’s security posture — a bug in the updater itself is the kind of irony that keeps security engineers up at night.

By the numbers: 71 high, 170 medium, 122 low

Beyond the critical seven, the patch batch includes 71 high-severity fixes, 170 medium-severity patches, and 122 low-severity corrections. That’s a lot of ground covered. Some of the medium-severity bugs might sound less scary, but in combination with other flaws, they can become dangerous. Google doesn’t release full technical details for most bugs until users have had time to update.

Security researchers who reported these flaws collected a combined $58,500 through Google’s bug bounty program. However, the company hasn’t disclosed payout details for 13 of the bugs yet — possibly because some are still under review or involved higher-tier rewards.

How to update Chrome right now

If you haven’t updated yet, here’s what to do:

  • Click the three-dot menu in the top-right corner of Chrome
  • Go to HelpAbout Google Chrome
  • Chrome will automatically check for updates and install version 151
  • Restart the browser to complete the update

That’s it. The whole thing takes about two minutes. Given the scale of this patch, it’s time well spent.

This update follows a busy year for Chrome security. In 2025, Google issued multiple emergency patches for Chrome zero-day vulnerabilities, including one in January and another in March. While this July update doesn’t mention any zero-days being actively exploited, the sheer volume of fixes suggests the Chrome security team has been working overtime.

Google’s message: Prevention, not just reaction

In its release notes, Google thanked “all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.” That’s a subtle but important shift — it means some of these bugs were caught internally or through partnerships before they could be exploited in the wild.

Still, 370 vulnerabilities in a single release is a lot. It raises the question: is Chrome getting more complex, or are researchers getting better at finding its weak spots? Probably both. As the browser adds features — GPU compute, WebGPU, advanced rendering — the attack surface grows. The good news is that Google’s bug bounty program is clearly working, and patches are being shipped fast.

Version 151 is rolling out now. Make sure you’re running it before you browse any further.

Continue Reading

Trending