TGScope
Settings
Theme
OrganizationTencentSeptember 2026

Tencent — September 2026

What Telegram channels wrote about Tencent in September 2026: 28 posts from 25 channels, collected automatically from public Telegram channels.

28 posts·25 channels

More posts — page 2

28 posts total

📱 Your phone can be hacked by a single call without you even answering

Most people believe that ignoring unknown numbers keeps them safe. The WeWorm attack proved the opposite: just an incoming call was enough to turn a smartphone into the next link in a digital infection chain.

🪱 A worm that spreads itself

Researchers at Calif built WeWorm as a laboratory zero-click worm targeting WeChat, the messaging giant whose ecosystem reaches 1.44 billion monthly users across Weixin and WeChat. Even without answering the call, the victim's account was taken over, and then the compromised account automatically started calling its own contacts to repeat the attack. The demonstration worked between Android and iOS devices with zero interaction from the owners.

🔴 Where the flaw lives

At the heart of WeWorm sits a memory corruption bug in the VoIP stack of WeChat, the component that handles voice calls. There is one catch: the attacker must already be in the victim's friends list. But after the first compromise, that condition stops mattering, because the hijacked account can call its trusted contacts and continue the chain on its own.

In the test, a Pixel 10a called an iPhone 17e and gained control of WeChat while the phone was still ringing. The captured iPhone then called a second Pixel 10a and repeated the whole process. The entire exploit took mere seconds.

Answering the call did not save the device, and rejecting it only stopped that specific attempt, since the attacker could simply ring again.

🦈 What the attacker actually gets

The exploit hands over full control of the WeChat account: reading and sending messages, making calls, acting on behalf of the owner. WeWorm alone does not seize the entire phone, though Calif sees full device takeover as a plausible scenario if chained with other Android or iOS bugs, something never confirmed in the demo.

🤖 AI accelerated everything

Neural networks played a starring role here. Calif says AI helped uncover the flaw, the remote code execution exploit was ready in about two days, and a full working worm took roughly another week. The team learned of the issue on July 23 and had the cross-platform demonstration done by August 11.

🛡 Patched, but lessons remain

Tencent got word on July 24. Versions 8.0.77 for Android and 8.0.76 for iOS, released on August 21, neutralize the attack, and by August 28 Calif confirmed a server-side block covering all users. So far, there are no signs of WeWorm spreading in the wild.

And that is the uncomfortable part. Attacks like this ignore old habits: it does not matter whether you pick up or not. Keep WeChat updated at all times, install updates the day they ship, think twice before adding unfamiliar contacts to your list, and turn on any extra account protection the app offers. Silence is no longer a defense.

😊 Follow us to stay informed about the latest threats and protect yourself.

#Cybersecurity #ZeroClick #WeChat #MobileThreats #AIHacking

@PrivacyNotACrime 🗽 ⌨️ Chat

La firma de ciberseguridad Calif desarrolló la prueba de concepto "WeWorm", un gusano zero-click que compromete cuentas de WeChat en iOS y Android mediante una llamada de voz entrante, sin necesidad de que la víctima responda. Explotando una falla de corrupción de memoria en el stack VoIP de la aplicación, el atacante toma el control total de la cuenta y utiliza la lista de contactos para propagar la infección automáticamente. Tencent ya mitigó la vulnerabilidad tanto en sus servidores como mediante actualizaciones de la app.

Sep 8, 05:29 PMMore from @tpxsecurity

**WeChat: La Amenaza Invisible del Worm Zero-Click**

Recientemente, investigadores de la firma de ciberseguridad Calif han presentado un descubrimiento alarmante: un worm que puede tomar el control de una cuenta de WeChat simplemente a través de una llamada entrante. Lo inquietante de este ataque es que no es necesario que la víctima conteste o interactúe con su dispositivo. Todo esto ocurre solo si el llamador está en su lista de contactos.

La implicación de esta vulnerabilidad es grave. En un mundo cada vez más digital, donde los mensajes y las llamadas son la norma, desproteger a los usuarios de una plataforma tan popular como WeChat genera serias preocupaciones sobre la seguridad personal y la privacidad.

Calif notificó la falla a Tencent en julio, y aunque se ha hablado de la importancia de la ciberseguridad, aquí vemos una clara necesidad de acción. Las empresas deben tomar en serio estas amenazas y trabajar proactivamente para proteger a sus usuarios.

Es fundamental que como usuarios, mantengamos una actitud crítica y nos eduquemos sobre las posibles vulnerabilidades de las plataformas que utilizamos a diario.

¿Estamos realmente seguros en el ecosistema digital que habitamos, o estamos simplemente un paso detrás de los problemas que acechan?

Para más detalles, puedes consultar la fuente: [The Hacker News](https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html).

🗣️ Juzgue usted, llegue a sus conclusiones. 🗝️ No todo lo que te cuentan es verdad y no todo lo que es verdad te lo cuentan. — Kriz Iron

#LVOPR #SURVIVALTIMESPR #DESPIERTADELABURBUJAPR #KRIZIRON

⚖️ QR Switch судится с Telegram. Знакомьтесь, патентный троллинг

Компания заявляет о нарушении двух патентов, связанных с QR-входом в сервис.

Кто такая QR Switch

Она числится в базе непрактикующих организаций Стэнфорда — то есть в реестре структур, которые не производят продукт, а зарабатывают на патентных искахх. Telegram у них далеко не первый: в этом году они уже подали на Tencent, обвиняя WeChat и VooV Meeting в том же самом — отображении QR-кода на экране, который пользователь сканирует телефоном для входа.

Иски идут в Восточный округ Техаса. Это классическая прописка патентных троллей — суд исторически лоялен к истцам такого рода.

Суть претензии

Патенты описывают метод сканирования штрихкода с экрана для обновления отображаемого контента. Под это определение при желании подпадает любой QR-логин: Telegram Web, WhatsApp Web, WeChat, Discord, десятки сервисов.

Тут же и слабое место иска. Само детальное описание патента приводит примером обновление основного контента — переключение между категориями вроде новостей, спорта и бизнеса. Вход в аккаунт под это описание ложится плохо, и защита почти наверняка будет строить аргументацию именно здесь.

Контекст индустрии

QR-код изобрёл Масахиро Хара в Denso Wave в 1994 году. Denso Wave за три десятилетия не подала ни одного иска против тех, кто использует технологию. А в 2022 году 88% патентных исков в хайтеке подали именно тролли.

Была уже история про Symbology Innovations — сотни иcков против Walgreens, Lego, Bank of America, Dr. Pepper за использование QR-кодов.

Что это значит для Telegram

Ничего катастрофического. У компании с 900 млн пользователей есть юристы, и такие иски обычно заканчиваются либо аннулированием патента, либо копеечным мировым соглашением. Опаснее для мелких проектов — тем, у кого нет денег на защиту, проще заплатить, чем судиться.

У Дурова сейчас французское дело, российский ордер и иск за QR-код. Из этих трёх последний — единственный, где он почти наверняка выиграет ⚖️

*Павел Дуров внесён Росфинмониторингом в перечень террористов и экстремистов

@smska

Sep 4, 11:12 AMMore from @smska