SANS Stormcast Thursday, April 23rd, 2026: Stealing Telegram Sessions; Oracle CPU; Firefox Patches
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 23 April 2026
⏱️ 8 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, April 23rd, 2006 edition of the Sands Inlet of Storm Center's Stormcast. |
| 0:12.0 | My name is Johannes Ulrich, recording today from Amsterdam, Netherlands. |
| 0:17.7 | And this episode is brought you by the sands.edu graduate certificate program in penetration testing and ethical hacking. |
| 0:26.2 | Today we got another diary by one of our undercredit sands.edu interns. |
| 0:31.8 | El Carrey writes about how their honeypot got compromised. |
| 0:36.1 | Initially it looked like, well, your run-of-the-mill compromise. |
| 0:39.3 | It did sort of check for crypto miners, tried to kill them, |
| 0:43.1 | which is very typical for sort of these mining scripts that take over Linux systems with weak passwords. |
| 0:49.8 | But then things kind of changed. |
| 0:53.3 | The script then went and looked for the T-Data file in the desktop Telegram folder. |
| 1:01.3 | This is a typical location on the Linux system where Telegram, the messenger, keeps their session data. |
| 1:08.7 | So the content of the T-Data file are essentially session IDs that are being |
| 1:13.3 | used to authenticate declined to telegram's system. This session data could then easily be |
| 1:20.5 | copied to another system and used to authenticate as the user. So it's essentially as valuable |
| 1:26.8 | as the username and password for a particular account. |
| 1:30.8 | Even worse, if the user had set up to factor authentication, doesn't actually matter if the attacker gets a hold of this session data. |
| 1:42.4 | Telegram remains to be a highly valued platform by criminals, in part because of its |
| 1:48.2 | easy automation, and of course, of its worldwide infrastructure that is relatively easy to use and |
| 1:55.7 | widely used, which of course makes it more difficult for organizations to block access to Telegram. |
| 2:02.6 | Still something that you probably should monitor and definitely look for access to the Tdata file |
| 2:10.5 | if you have some endpoint protection that can monitor this. |
| 2:14.6 | For Telegram users also it's important to keep an eye out for any odd sessions |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

