logo

Hackers scanning for TeleMessage Signal clone flaw exposing passwords

ID: b61d78ac-53d2-5690-8647-72fd89ba2138

STIX ID: report--b61d78ac-53d2-5690-8647-72fd89ba2138

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-07-18

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers and telemetry firms observed active scanning and exploitation attempts targeting CVE-2025-48927 in the TeleMessage SGNL app (a Signal-clone). The flaw stems from an exposed Spring Boot Actuator /heapdump endpoint that can leak Java heap dumps containing plaintext credentials and archived messages; GreyNoise reported thousands of scans and multiple exploit attempts, CISA added the vulnerability to the KEV, and Smarsh states cloud instances were patched while some on-prem installations may still be vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.