Published
8 months agoon
![[Security & Blockchain Hacks]](https://blocktrend.online/wp-content/uploads/2025/07/Hacker-reconnaissance-work-continues-on-TeleMessage-app-vulnerability-%E2%80%94-Report.jpeg)
Uncover the newest tendencies within the NFT area. This article dives into: “Hacker reconnaissance work continues on TeleMessage app vulnerability — Report”.
Hackers are persevering with to hunt out alternatives to take advantage of the notorious CVE-2025-48927 vulnerability concerned in TeleMessage, in response to a brand new report from risk intelligence firm GreyNoise.
GreyNoise’s tag, which screens makes an attempt to make the most of the vulnerability, has detected 11 IP addresses which have tried the exploit since April.
Other IP addresses could also be performing reconnaissance work: A complete of two,009 IPs have looked for Spring Boot Actuator endpoints previously 90 days, and 1,582 IPs have particularly focused the /well being endpoints, which generally detect Spring Boot Actuator deployments.
The flaw permits hackers to extract information from susceptible programs. The subject “stems from the platform’s continued use of a legacy confirmation in Spring Boot Actuator, where a diagnostic /heapdump endpoint is publicly accessible without authentication,” the analysis crew advised Cointelegraph.
TeleMessage is much like the Signal App however permits for the archiving of chats for compliance functions. Based in Israel, the corporate was acquired by US firm Smarsh in 2024, earlier than quickly suspending providers after a safety breach in May that resulted in information being stolen from the app.
“TeleMessage has stated that the vulnerability has been patched on their end,” stated Howdy Fisher, a member of the GreyNoise crew. “However, patch timelines can vary depending on a variety of factors.”
Although safety weaknesses in apps are extra frequent than desired, the TeleMessage vulnerability might be important for its customers: authorities organizations and enterprises. Users of the app could embrace former US authorities officers like Mike Waltz, US Customs and Border Protection and crypto trade Coinbase.
GreyNoise recommends customers block malicious IPs and disable or prohibit entry to the /heapdump endpoint. In addition, limiting publicity to Actuator endpoints could also be useful, it stated.
Related: Threat actors utilizing ‘elaborate social engineering scheme’ to focus on crypto customers — Report
Chainalysis’ newest crime report notes that over $2.17 billion has been stolen to date in 2025, a tempo would take crypto-related thefts to new highs. Notable safety assaults over the previous months embrace bodily “wrench attacks” on Bitcoin holders and high-profile incidents such because the February hack of crypto trade Bybit.
Attempts to steal credentials usually contain phishing assaults, malicious malware, and social engineering.
Magazine: Coinbase hack reveals the legislation most likely gained’t shield you — Here’s why
Learn about crucial developments within the Altcoin area. This article analyzes: “Hacker reconnaissance work continues on TeleMessage app vulnerability — Report”.
[ad_3]
This article is customized from cointelegraph.com. We’ve restructured and rewritten the content material for a broader viewers with improved readability and web optimization formatting.
Visit BLOCKTREND for each day crypto updates.
Nvidia stories file gross sales because the AI increase continues | TechCrunch
A brand new safety flaw in TheTruthSpy cellphone adware is placing victims in danger | TechCrunch
Galaxy Digital, Multicoin, Jump Crypto plan $1B Solana fund: Report
Messari Q2 Report: Flow Hits Record $68M TVL as Stablecoins, Disney, and DeFi Fuel Breakout Quarter
Coinbase hacker makes use of stolen crypto to purchase 38,126 Solana
China’s cupboard to contemplate permitting RMB stablecoins for commerce – report – Ledger Insights – blockchain for enterprise
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| 1 | ||||||
| 2 | 3 | 4 | 5 | 6 | 7 | 8 |
| 9 | 10 | 11 | 12 | 13 | 14 | 15 |
| 16 | 17 | 18 | 19 | 20 | 21 | 22 |
| 23 | 24 | 25 | 26 | 27 | 28 | 29 |
| 30 | 31 | |||||
Ethereum may be very a lot ‘the Wall Street token,’ VanEck CEO says Uncover the most recent tendencies within the...
Criminals are ‘vibe hacking’ with AI at unprecedented ranges: Anthropic Explore the most recent traits within the Bitcoin house. This...
XRP: Emergency Price Break, Bitcoin (BTC): Losing $100,000 If This Breaks, New Ethereum (ETH) Height Next? – U.Today Explore insights...
Nvidia stories file gross sales because the AI increase continues | TechCrunch Explore insights within the DeFi house. This article...
Alchemy Pay plugs fiat ramp into Boyaa’s Web3 poker sport Discover the newest tendencies within the Bitcoin area. This article...
REX-Osprey information for BNB staking ETF as month-to-month inflows choose up Explore the newest traits within the Bitcoin area. This...
Investors Flock To XYZVerse (XYZ) For Promising Potential While ONDO & TAO Price Stagnates In Altseason Discover the most recent...
Pi Coin’s Charts Hint at a Turnaround—Here’s Why a 40% Rally Could Be Close Discover key highlights within the Altcoin...
Anthropic Cybersecurity Team Warns ‘Agentic AI Has Been Weaponized’ | PYMNTS.com Explore the most recent traits within the Altcoin house....
Swarm Network raises $13M to facilitate decentralized AI Discover the newest tendencies within the Web3 house. This article dives into:...