Hackers Target TeleMessage App via CVE-2025-48927 Vulnerability

TeleMessage Vulnerability Exploited by Hackers, Leading to Data Breaches and Rising Crypto Theft in 2025

  • Hackers continue exploiting a key vulnerability in TeleMessage, affecting critical endpoints.
  • The flaw enables attackers to extract data from unprotected systems using the Spring Boot Actuator framework.
  • GreyNoise detected 11 IPs actively trying to exploit the bug, and over 2,000 performing related scans since April.
  • TeleMessage reported patching the vulnerability after a security breach led to stolen files in May 2024.
  • Chainalysis reports over $2.17 billion lost to crypto theft in 2025, driven by social engineering and Malware.

Hackers are working to exploit a vulnerability, known as CVE-2025-48927, in the TeleMessage messaging app. A report from threat intelligence firm GreyNoise confirms that attackers continue to target this flaw, which allows unauthorized data extraction from affected systems.

- Advertisement -

The issue stems from the Spring Boot Actuator framework, where a diagnostic endpoint called /heapdump was publicly accessible without a password. According to GreyNoise, their monitoring detected 11 IP addresses attempting direct exploits of the flaw since April. In addition, over 2,000 other IP addresses searched for Actuator endpoints, with 1,582 focusing on the /health feature that helps find vulnerable installations.

The GreyNoise team told Cointelegraph that the problem comes from using old confirmation methods in Spring Boot Actuator, making the /heapdump endpoint easy for Hackers to reach. “TeleMessage has stated that the vulnerability has been patched on their end,” said Howdy Fisher from GreyNoise. “However, patch timelines can vary depending on a variety of factors.”

TeleMessage, which operates similarly to Signal but offers chat archiving for compliance, is used by government organizations and companies such as US Customs and Border Protection and crypto exchange Coinbase. In May 2024, the app suspended services after a security breach led to files being stolen. The company was acquired by US-based Smarsh earlier in the year, as noted in a press release.

GreyNoise recommends users block suspicious IPs and restrict access to the /heapdump endpoint. Limiting exposure to all Actuator endpoints can also help prevent attacks, according to their report.

- Advertisement -

Cybersecurity threats targeting crypto users are on the rise in 2025. According to a report by Chainalysis, over $2.17 billion has been stolen through various methods including phishing, malware, and physical attacks. High-profile cases include the Bybit exchange hack in February. Users of vulnerable apps may include former US government officials, as highlighted in this NBC report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Telegram Crypto Scam Alert: 100K+ Channels Turn on Followers

Trusted trading signal groups with 100K+ subscribers now promote fake platforms that lock funds...

Telcos Join Theta Network as Validators, Boosting Trust Now!

Deutsche Telekom and NTT Digital have joined a blockchain network as enterprise validators.Telecom operators...

Gold Surge Tops $34T; Bitcoin Falters Amid Fed Pick Buzz Now

Gold’s market value has surged to about $34 trillion, outpacing Bitcoin’s recent gains.BlackRock holds...

UBS to Offer Bitcoin and Ethereum Trading for Swiss Clients.

UBS Group AG will allow select private banking clients in Switzerland to trade Bitcoin...

Optimism DAO split over proposal to fund monthly OP buybacks

Delegates in the Optimism DAO are voting on a plan to use 50% of...
- Advertisement -

Must Read

How to Buy VPS with Crypto from Hostinger – Step by Step guide

Did you know that nowadays you can use Bitcoin to purchase a Windows VPS? If you’re here, you’re probably wondering how to do it....
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!