Report: TeleMessage App Vulnerability Exploited via Ongoing Hacker Reconnaissance Efforts and Activities.
  • 453 views
  • 2 min read

Cybersecurity experts are reporting ongoing reconnaissance activity targeting a known vulnerability in the TeleMessage application, a modified version of the Signal app used by government organizations and enterprises for secure communication and archiving. The vulnerability, identified as CVE-2025-48927, has been actively exploited since its initial disclosure in May 2025.

According to a report by threat intelligence firm GreyNoise, multiple attacks have been detected that exploit this vulnerability in TeleMessage's Signal clone app. As of mid-July 2025, GreyNoise identified 11 IP addresses actively attempting to leverage the flaw to compromise user credentials and data. The vulnerability allows threat actors to potentially expose usernames, passwords, and other sensitive information in plaintext.

The root cause of the vulnerability lies in the platform's continued use of a legacy configuration in Spring Boot Actuator, where a diagnostic /heapdump endpoint is publicly accessible without authentication. This allows anyone to download a memory dump of the running application, which may include plaintext usernames, passwords, encryption keys, and active session tokens for TeleMessage's backend and archive systems.

GreyNoise also reported that a total of 2,009 IP addresses have been observed scanning for Spring Boot Actuator endpoints in the past 90 days, with 1,582 IPs specifically targeting the /health endpoints. These endpoints are commonly used to detect Spring Boot Actuator deployments, and this reconnaissance activity could be a precursor to broader exploitation attempts.

TeleMessage, an Israel-based company acquired by Smarsh in 2024, provides modified versions of encrypted messaging apps like Signal, Telegram, and WhatsApp to allow organizations to archive messages for compliance purposes. The company came under scrutiny after it was revealed that former U.S. National Security Advisor Mike Waltz and other government officials were using TeleMessage's modified version of Signal.

In May 2025, TeleMessage temporarily suspended its services after a security breach resulted in the theft of files from the app. The breach exposed archived but unencrypted copies of messages, contact information of government officials, and backend login credentials for TeleMessage. Data pertaining to U.S. Customs and Border Protection, crypto exchange Coinbase, and financial service providers like Scotiabank were also compromised.

The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-48927 to its Known Exploited Vulnerabilities catalog and recommended remediation of the bug by July 22, 2025. CISA also added another security defect, CVE-2025-48928, to its KEV catalog, urging federal agencies to patch them.

Security experts recommend that users block malicious IPs and disable or restrict access to sensitive endpoints to mitigate the risk of exploitation. The incident highlights the risks associated with modifying encrypted messaging apps for compliance purposes, as these modifications can introduce security vulnerabilities. It also underscores the importance of robust security practices, including runtime application testing and adherence to security policies.


Writer - Meera Joshi
Meera Joshi, an enthusiastic journalist with a profound passion for sports, is dedicated to shedding light on underreported stories and amplifying diverse voices. A recent media studies graduate, Meera is particularly drawn to cultural reporting and compelling human-interest pieces. She's committed to thorough research and crafting narratives that resonate with readers, eager to make a meaningful impact through her work. Her love for sports also fuels her drive for compelling, impactful storytelling.
Advertisement

Latest Post


Business  |  Jul 19, 2025
The cryptocurrency market is experiencing a significant upswing, fueled by Ethereum's impressive growth and former President Donald Trump's ventures into the digital asset space. Ethereum (ETH), the second-largest cryptocurrency by market capitalizat...

World  |  Jul 19, 2025
A Mumbai to Nagpur flight, identified as 6E 5349, experienced a tense situation on Saturday morning when it was unable to land on its first attempt at Nagpur airport. The primary reason for the aborted landing was low visibility at the airport. The ...

World  |  Jul 19, 2025
The Nagaland State Lottery continues to be a popular event, offering participants a chance to win substantial prizes. On July 19, 2025, the results for various draws will be announced throughout the day, keeping participants in anticipation. The draw...

Technology  |  Jul 19, 2025
The OnePlus Pad 3, boasting the powerful Snapdragon 8 Elite Mobile Platform, is set to make its debut in India and will be available for purchase starting in September. This premium Android tablet, unveiled globally on June 5, 2025, aims to deliver a...

Advertisement
Entertainment  |  Jul 19, 2025
Munmun Dutta, known for her role in the popular sitcom "Taarak Mehta Ka Ooltah Chashmah" (TMKOC), recently attended a prayer meet held in honor of Shri Dheeraj Kumar. Her presence at the event demonstrated her support and respect for the deceased. V...

Sports  |  Jul 19, 2025
The 2025 WNBA All-Star Weekend in Indianapolis was poised to be a grand celebration of women's basketball, with Indiana Fever's own Caitlin Clark set to be a central figure. However, a groin injury sidelined Clark, forcing her to withdraw from both t...

Business  |  Jul 19, 2025
A Bengaluru-based duo is making waves by hosting exclusive house parties and charging entry fees, reportedly earning them a substantial income of around ₹6 lakh per month. This emerging trend highlights a shift in the city's party scene, with some re...

World  |  Jul 19, 2025
The ancient Tabo Monastery in Spiti Valley, a treasure of Buddhist art and Himalayan heritage, is facing an escalating threat from climate change. Lamas are urgently seeking intervention from the Archaeological Survey of India (ASI) to protect the mo...

Advertisement
About   •   Terms   •   Privacy
© 2025 DailyDigest360