<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Threat Intelligence on 思安录 | Thinking&#39;s Security Notes</title>
    <link>https://blog.1sec.day/en-gb/tags/threat-intelligence/</link>
    <description>Recent content in Threat Intelligence on 思安录 | Thinking&#39;s Security Notes</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-gb</language>
    <managingEditor>Thinking</managingEditor>
    <webMaster>Thinking</webMaster>
    <lastBuildDate>Wed, 15 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.1sec.day/en-gb/tags/threat-intelligence/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Telegram Desktop Local Session Reuse: a Reproduction That Should Not Have Happened</title>
      <link>https://blog.1sec.day/en-gb/posts/2026-07-15-telegram-desktop-local-session-reuse/</link>
      <pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2026-07-15-telegram-desktop-local-session-reuse/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;The reproduction result exceeded what I understood to be possible. Telegram&amp;rsquo;s device authentication — phone verification, SMS code, 2FA password — seemed, to me, well-designed and complete. But when the tdata directory was copied to another Mac and the client launched, the login screen never appeared. This was not 2FA being cracked. The entire reuse path never entered a stage where credentials were requested.&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>Lazarus Group APT Attack on Cryptocurrency Exchanges: IOC &amp; TTP Disclosure</title>
      <link>https://blog.1sec.day/en-gb/posts/2025-02-23-lazarus-apt-attack/</link>
      <pubDate>Sun, 23 Feb 2025 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2025-02-23-lazarus-apt-attack/</guid>
      
      <description>&lt;blockquote&gt;
&lt;p&gt;Cybersecurity is a war of endurance. This article is co-authored by me (Thinking) and 23pds.&lt;/p&gt;
&lt;/blockquote&gt;</description>
      
    </item>
    
    <item>
      <title>Fake Aggr Chrome Extension Crypto Theft Analysis: Cookie Stealing and Wash Trading</title>
      <link>https://blog.1sec.day/en-gb/posts/2024-05-31-aggr-malicious-chrome-extension/</link>
      <pubDate>Fri, 31 May 2024 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2024-05-31-aggr-malicious-chrome-extension/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Celer Network cBridge Cross-Chain Bridge Incident Analysis: BGP Hijacking Attack</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-08-20-celer-network-bgp-hijacking/</link>
      <pubDate>Sat, 20 Aug 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-08-20-celer-network-bgp-hijacking/</guid>
      
      <description></description>
      
    </item>
    
    <item>
      <title>Solana Blockchain Mass Theft Analysis: Slope Wallet Sentry Leaks Mnemonic Phrases</title>
      <link>https://blog.1sec.day/en-gb/posts/2022-08-04-solana-massive-theft/</link>
      <pubDate>Thu, 04 Aug 2022 00:00:00 +0000</pubDate>
      <author>Thinking</author>
      <guid>https://blog.1sec.day/en-gb/posts/2022-08-04-solana-massive-theft/</guid>
      
      <description></description>
      
    </item>
    
  </channel>
</rss>
