Jan 12, 2026, 08:48 PM
Hello.
APT 42 here.
We’ve recently identified a 0-click account takeover vulnerability affecting a major collaborative design platform (Figma).
The issue allows full account compromise without user interaction and leaves no visible trace from the victim’s perspective.
This is not public, not reported, and not patched.
We are not looking for partners, write-ups, or public disclosure.
We are looking for a serious buyer who understands the value of silent access at scale.
Details:
- Zero user interaction
- Reliable reproduction
- High-value target surface (enterprise / teams / orgs)
- No crash, no alert, no email, no reset trigger
- Works on live production environment
Terms:
- One buyer only
- Full private disclosure after escrow
- No resales, no leaks
- Proof available upon serious inquiry
If you need this explained, you’re not the target buyer.
Serious offers only.
Session : 055cef2d0f1cb9ad889d2345a63997ac353b1e69b7249d27837c6324bf94674067
This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Ban Reason: Contact Administration.
