BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hackers Target TeleMessage App via CVE-2025-48927 Vulnerability

TeleMessage Vulnerability Exploited by Hackers, Leading to Data Breaches and Rising Crypto Theft in 2025

  • Hackers continue exploiting a key vulnerability in TeleMessage, affecting critical endpoints.
  • The flaw enables attackers to extract data from unprotected systems using the Spring Boot Actuator framework.
  • GreyNoise detected 11 IPs actively trying to exploit the bug, and over 2,000 performing related scans since April.
  • TeleMessage reported patching the vulnerability after a security breach led to stolen files in May 2024.
  • Chainalysis reports over $2.17 billion lost to crypto theft in 2025, driven by social engineering and Malware.

Hackers are working to exploit a vulnerability, known as CVE-2025-48927, in the TeleMessage messaging app. A report from threat intelligence firm GreyNoise confirms that attackers continue to target this flaw, which allows unauthorized data extraction from affected systems.

- Advertisement -

The issue stems from the Spring Boot Actuator framework, where a diagnostic endpoint called /heapdump was publicly accessible without a password. According to GreyNoise, their monitoring detected 11 IP addresses attempting direct exploits of the flaw since April. In addition, over 2,000 other IP addresses searched for Actuator endpoints, with 1,582 focusing on the /health feature that helps find vulnerable installations.

The GreyNoise team told Cointelegraph that the problem comes from using old confirmation methods in Spring Boot Actuator, making the /heapdump endpoint easy for Hackers to reach. “TeleMessage has stated that the vulnerability has been patched on their end,” said Howdy Fisher from GreyNoise. “However, patch timelines can vary depending on a variety of factors.”

TeleMessage, which operates similarly to Signal but offers chat archiving for compliance, is used by government organizations and companies such as US Customs and Border Protection and crypto exchange Coinbase. In May 2024, the app suspended services after a security breach led to files being stolen. The company was acquired by US-based Smarsh earlier in the year, as noted in a press release.

GreyNoise recommends users block suspicious IPs and restrict access to the /heapdump endpoint. Limiting exposure to all Actuator endpoints can also help prevent attacks, according to their report.

- Advertisement -

Cybersecurity threats targeting crypto users are on the rise in 2025. According to a report by Chainalysis, over $2.17 billion has been stolen through various methods including phishing, malware, and physical attacks. High-profile cases include the Bybit exchange hack in February. Users of vulnerable apps may include former US government officials, as highlighted in this NBC report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

China Aims to Boost Small Biz Loans With Blockchain

Chinese banking and tax authorities have directed financial institutions to adopt blockchain and privacy...

German Police ID REvil Ransomware Boss Behind $40M Hits

German authorities have identified Daniil Shchukin, 31, as the Russian threat actor “UNKN,” a...

Shiba Inu’s “Middle Age” Crisis: Collapse Risk Grows

Once dubbed "The Dogecoin Killer", Shiba Inu's price action has stabilized, leaving its wild,...

Kiyosaki: 1974’s economic shift fuels debt, retirement crisis

Robert Kiyosaki warns the financial changes initiated in 1974 are now creating inflation and...

Dogecoin (DOGE) Post a Notable Rebound, Experts Show More Interest In Taurox (TAUX) as It Opens Pre-KYA Registration

DOGE trades near $0.09 after a notable rebound. The official account’s April Fools’ corporate...

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading