<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://beaksec.github.io/</id><title>beaksec</title><subtitle>Cybersecurity from a different perspective</subtitle> <updated>2026-10-07T16:24:19+02:00</updated> <author> <name>beaksec</name> <uri>https://beaksec.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://beaksec.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://beaksec.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 beaksec </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Telegram Desktop: one-click account takeover via IPC injection</title><link href="https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/" rel="alternate" type="text/html" title="Telegram Desktop: one-click account takeover via IPC injection" /><published>2026-10-03T10:00:00+02:00</published> <updated>2026-10-07T16:21:55+02:00</updated> <id>https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/</id> <content type="text/html" src="https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/" /> <author> <name>beaksec</name> </author> <category term="Research" /> <summary>An unescaped separator in Telegram Desktop's single-instance IPC lets one clicked link read arbitrary files off the disk and send them to the attacker, session files included.</summary> </entry> <entry><title>Webmin: one-click RCE via XSS</title><link href="https://beaksec.github.io/posts/webmin-one-click-rce-via-xss/" rel="alternate" type="text/html" title="Webmin: one-click RCE via XSS" /><published>2026-09-26T12:12:58+02:00</published> <updated>2026-09-26T12:12:58+02:00</updated> <id>https://beaksec.github.io/posts/webmin-one-click-rce-via-xss/</id> <content type="text/html" src="https://beaksec.github.io/posts/webmin-one-click-rce-via-xss/" /> <author> <name>beaksec</name> </author> <category term="Research" /> <summary>A reflected XSS in Webmin chains to arbitrary command execution as root on a default install, from a single link. CVE-2026-49243.</summary> </entry> </feed>
