CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances
ID: d5656333-121b-5c70-9c48-5c20210d0871
STIX ID: report--d5656333-121b-5c70-9c48-5c20210d0871
Feed Name: Security Affairs
**Active exploitation of CVE-2025-64328 in Sangoma FreePBX** led to the deployment of the EncystPHP web shell across roughly 900 systems worldwide; attackers exploited a post-authentication command-injection in the Endpoint Manager to achieve remote command execution, create persistent root access (including SSH key injection and new users), harvest credentials, remove logs and competing shells, and deploy additional payloads — activity attributed to INJ3CTOR3 and tracked by Shadowserver, FortiGuard, and CISA (added to KEV).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
