A high-severity Telegram Desktop flaw allowed malicious JavaScript in bot-created buttons to steal chat content when conversations were exported as HTML.
KREMLIN targets Brazilian bank users with malicious Chrome and Edge extensions that steal credentials, session tokens, ...