Telegram Removed from App Store After Extortionist Plants AI-Modified CSAM in Archived Message
Telegram and its experimental client Telegram X disappeared from the App Store on the morning of August 4 in several countries, including Russia, Turkey, and the United States. The removal lasted roughly ninety minutes and temporarily disrupted push notifications for some iOS users, while macOS and Android versions were unaffected.
Founder Pavel Durov attributed the incident to an extortionist who modified an archived message in a public group. The attacker inserted material depicting child sexual abuse (CSAM) that had been altered with artificial intelligence, making the post invisible to active participants and preventing normal user reports. The same account then submitted a complaint directly to Apple, which detected the prohibited content and removed the applications.
According to Durov, the perpetrator belongs to a group that targets owners of public channels and groups. The extortionists demand payment under threat of planting illegal material and filing complaints with Apple. Automated accounts and technical bypasses are used to evade standard moderation filters.
Apple confirmed that the applications were reinstated after Telegram removed the prohibited material and blocked the distributing account. Durov expressed concern that Apple had activated the removal process without first contacting Telegram administrators, describing the approach as dangerous for any platform hosting user-generated content.
Telegram called on Apple to apply consistent and thorough verification to all reports across every application rather than acting on isolated complaints that can be engineered to trigger sudden delisting.
Related articles
Cl0p Exploits Critical Windchill Vulnerability CVE-2026-12569 to Steal Industrial Designs
The Cl0p extortion group is actively targeting internet-exposed PTC Windchill and FlexPLM servers to exfiltrate engineering projects, technical specifications, and other sensitive data. The campaign focuses on organizations in the industrial, automotive, aerospace, defense, and retail sectors. Attackers leverage the critical remote code execution vulnerability CVE-2026-12569, which stems from unsafe deserialization and carries a CVSS score of 9.8, allowing unauthenticated exploitation over the network. The intrusion chain also combines a WSDL endpoint information disclosure in FlexPLM with a login mechanism weakness in Windchill to gain initial access and execute commands without valid credentials. After compromise, operators deploy JSP web shells to maintain persistence, explore files, and prepare data for exfiltration. Affected systems often contain unreleased product designs, engineering drawings, and strategic manufacturing documents. The activity began in early June 2026, with extortion emails sent to hundreds of employees starting July 20 to increase internal pressure ahead of potential data leaks.
Chaos Ransomware Group Uses msaRAT Trojan to Hide C2 Traffic Through Invisible Chrome and Edge Browsers
The Chaos ransomware group has adopted a new Rust-based trojan called msaRAT to conceal its command-and-control communications inside legitimate browser sessions. The malware launches Chrome or Edge in invisible mode and controls it via the Chrome DevTools Protocol, keeping all outbound traffic restricted to localhost. It then injects JavaScript to negotiate a WebRTC connection through Cloudflare Workers before routing data over Twilio TURN servers, preventing the attackers' real infrastructure from appearing in network logs. Commands are executed through cmd.exe, and the implant includes queuing mechanisms that support reliable transfer of files, screenshots, and larger data volumes. In the analyzed incident, operators delivered the malware via an MSI installer disguised as a Windows update that loaded the msaRAT DLL directly into memory. The technique does not exploit any vulnerabilities in Chrome or Edge and is designed to blend malicious traffic with normal corporate browser activity.
Qilin Ransomware Operators Exploit Palo Alto PAN-OS VPN Flaw CVE-2026-0257
Operators linked to the Qilin ransomware group have been actively exploiting an authentication bypass vulnerability in Palo Alto Networks PAN-OS to gain initial access to corporate networks. The attacks, observed in June 2026, targeted the GlobalProtect VPN service running on Palo Alto firewalls and were tracked under CVE-2026-0257. Attackers used specially crafted authentication cookies to establish unauthorized VPN sessions, after which they harvested credentials from Windows LSASS processes and Active Directory NTDS databases. Lateral movement relied heavily on PsExec and administrative shares, supplemented by tools such as AnyDesk, Ngrok, LogMeIn, and NetExec. Before deploying the ransomware binary stored as win.exe in C:\PerfLogs\, the threat actors disabled Microsoft Defender real-time protection and cleared event logs. The vulnerability affects PAN-OS versions 10.2, 11.1, 11.2, and 12.1 as well as certain Prisma Access editions, while Panorama and Cloud NGFW remain unaffected.
Ransomware Attack Hits Coca-Cola Subsidiary Fairlife, Temporarily Halting US Production Systems
Fairlife, a company owned by Coca-Cola, temporarily suspended production operations in the United States after detecting unauthorized access to parts of its systems in a ransomware incident. The breach, publicly disclosed by Coca-Cola on July 16, 2026, affected environments directly linked to industrial production, prompting an immediate shutdown while investigations and recovery efforts continue. Fairlife manufactures milk, protein beverages, and other dairy products sold across the North American market, making the incident potentially disruptive to product availability, logistics, and internal processes. The company activated its incident response and business continuity protocols and engaged external cybersecurity specialists and consultants to assist with containment, investigation, and system restoration. No information has yet been released regarding data exfiltration, file encryption, or ransom demands, and the full scope of the attack remains under assessment. Coca-Cola has notified law enforcement authorities about the incident, while operations at Fairlife facilities in Canada were confirmed to be unaffected.