CVE-2025-64328Active Exploitation(sangoma / filestore)

CRITICALCVSS 7.2 · HIGHCISA KEV

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch sangoma filestore systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-24. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • filestore

Threat summary

  • Active exploitation appears in 41 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 52 mentions across 18 observed days

What's happening

  • Active exploitation reported across 41 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 34 signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 15 mentions (2026-03-01); latest day: 1
  • 52 total mentions across 18 days

Affected systems

Vendors
Products
filestore

Deep dive

Activity timeline52 mentions / 18d
0481115Mentions · 2026-01-28: 1Mentions · 2026-01-29: 2Mentions · 2026-01-30: 3Mentions · 2026-02-02: 2Mentions · 2026-02-03: 4Mentions · 2026-02-04: 4Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-12: 1Mentions · 2026-02-24: 1Mentions · 2026-02-27: 7Mentions · 2026-02-28: 3Mentions · 2026-03-01: 15Mentions · 2026-03-02: 3Mentions · 2026-03-03: 1Mentions · 2026-03-13: 1Mentions · 2026-04-13: 1Mentions · 2026-05-21: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-01-30: 2PoC Mentioned / Linked · 2026-02-28: 1PoC Mentioned / Linked · 2026-03-01: 3Exploit Tool / Code · 2026-01-29: 1Exploit Tool / Code · 2026-01-30: 1Exploit Tool / Code · 2026-02-02: 1Exploit Tool / Code · 2026-02-27: 4Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-01-30: 2Active Exploitation · 2026-02-02: 1Active Exploitation · 2026-02-03: 3Active Exploitation · 2026-02-04: 4Active Exploitation · 2026-02-12: 1Active Exploitation · 2026-02-27: 7Active Exploitation · 2026-02-28: 2Active Exploitation · 2026-03-01: 15Active Exploitation · 2026-03-02: 2Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-05-21: 1Patch / Workaround · 2026-01-30: 1Patch / Workaround · 2026-02-03: 2Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-27: 5Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-01: 3Patch / Workaround · 2026-03-02: 1Technical Details · 2026-01-28: 1Technical Details · 2026-01-30: 3Technical Details · 2026-02-02: 2Technical Details · 2026-02-03: 4Technical Details · 2026-02-04: 3Technical Details · 2026-02-06: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-27: 6Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 5Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-13: 1Technical Details · 2026-05-21: 101-2801-2901-3002-0202-0302-0402-0602-0802-1202-2402-2702-2803-0103-0203-0303-1304-1305-21
Signal classification5 categories
Active Exploitation
3975.0%
Exploit
47.7%
Disclosure
47.7%
General
47.7%
Patch
11.9%
Referenced assets76 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-281
Exploit1
2026-01-292
Exploit2
2026-01-303
Active Exploitation2Exploit1
2026-02-022
Active Exploitation1Disclosure1
2026-02-034
Active Exploitation3Disclosure1
2026-02-044
Active Exploitation4
2026-02-061
Disclosure1
2026-02-081
General1
2026-02-121
Active Exploitation1
2026-02-241
General1
2026-02-277
Active Exploitation7
2026-02-283
Active Exploitation2General1
2026-03-0115
Active Exploitation14Patch1
2026-03-023
Active Exploitation2General1
2026-03-031
Active Exploitation1
2026-03-131
Disclosure1
2026-04-131
Active Exploitation1
2026-05-211
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 WARNING: ~900 Sangoma FreePBX systems remain compromised via CVE-2025-64328, a command injection bug patched in 17.0.3. The flaw allows authenticated shell access. Fortinet links the activity to INJ3CTOR3 deploying EncystPHP. Patch and restrict admin access. 🔗 Read → https://thehackernews.com/2026/02/900-sangoma-freepbx-instances.html

    Post summary

    CVE-2025-64328 is actively exploited in the wild via a command injection flaw affecting approximately 900 FreePBX systems; patch to 17.0.3 and restrict admin access are urgently recommended.

    22135978.2K
    1.0M followersView on X
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2025-64328 (CVSS 8.6): FreePBX Administration GUI is Vulnerable to Authenticated Command Injection FreePBX is vulnerable to authenticated command injection in the Endpoint Manager’s filestore module via `testconnection → check_ssh_connect()`, allowing attackers to execute arbitrary commands and gain remote access as the asterisk user. Search by vul.cve Filter 👉 vul.cve="CVE-2025-64328" ZoomEye Dork 👉 app="FreePBX" 74k+ exposed instances. ZoomEye Link: https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjUtNjQzMjgi&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260202 Refer: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw #ZoomEye #NetSec #OSINT #CyberSecurity #FreePBX #VoIPSecurity #VulnerabilityResearch #TelecomSec

    Post summary

    The tweet announces a new authenticated command injection vulnerability (CVE‑2025‑64328) in FreePBX’s Endpoint Manager that permits remote code execution; it includes technical details and a CVSS score but does not mention PoCs, exploits, or patches.

    013036153.2K
    11.9K followersView on X
  • Virus Bulletin@virusbtn
    Exploit

    FortiGuard Labs analyses EncystPHP, a weaponized web shell delivering remote command execution, persistence and further web shell deployment. It spreads by exploiting FreePBX vulnerability CVE-2025-64328 and is linked to the INJ3CTOR3 actor. https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp https://t.co/9qlkNDmEG1

    Post summary

    FortiGuard Labs reports that EncystPHP weaponized web shell spreads by exploiting FreePBX CVE-2025-64328 for remote command execution and persistence, highlighting its role in further web shell deployment.

    18435155.4K
    60.8K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    企業のIP電話基盤として広く使われるSangoma FreePBXに深刻な脆弱性が突かれ、約900台がいまも侵害状態にある。攻撃者は認証後のコマンド注入を悪用し、Webシェルを設置して長期支配を続けている。 問題はCVE-2025-64328で、CVSSは8.6。FreePBX Endpoint Managerの管理画面にあるfilestoreモジュールのtestconnection→check_ssh_connect()に起因する認証後コマンド注入で、17.0.3で修正された。攻撃は2025年12月に始まり、INJ3CTOR3と関連付けられる活動とみられる。FortiGuard LabsはEncystPHPと呼ばれる新型Webシェルを確認し、45.234.176.202(http://crm.razatelefonia.pro)からドロッパーが配布されたと報告した。侵害後はデータベース設定の窃取、cronや既存ユーザーの削除、競合Webシェルの排除、rootユーザー作成、SSH鍵の挿入、ポート22の維持などで永続化する。Shadowserverによれば約400台が米国に集中し、ブラジルやカナダ、欧州各国にも拡散している。2026年2月、CISAは本件をKEVカタログに追加した。 https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html

    Post summary

    CVE-2025-64328, a command‑injection flaw in Sangoma FreePBX, is actively exploited in the wild, with attackers deploying a new EncystPHP web shell and maintaining persistence on roughly 900 compromised systems worldwide; a patch is available in version 17.0.3.

    01102453.3K
    11.6K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html

    Post summary

    CVE-2025-64328 is actively exploited, affecting roughly 900 Sangoma FreePBX instances, with no PoC, exploit code, patch, or technical details provided.

    2701972.5K
    151.8K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 4 vulnerabilities to the KEV Catalog https://darkwebinformer.com/cisa-kev-catalog/ CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    Post summary

    The text announces that CISA has added four vulnerabilities to the KEV catalog, listing their CVE IDs and general vulnerability types without providing PoC, exploit code, or patch information.

    1401863.7K
    164.9K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Active Exploitation

    CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html #securityaffairs #hacking

    Post summary

    The post reports that CVE-2025-64328 is actively exploited, affecting around 900 Sangoma FreePBX instances, but provides no further technical or mitigation details.

    03071493
    37.5K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    Active Exploitation

    CVE-2025-64328 exploitation impacts 900 #Sangoma #FreePBX instances https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html #securityaffairs #hacking

    Post summary

    The post reports that CVE-2025-64328 is actively exploited, affecting around 900 Sangoma FreePBX instances, but provides no technical details or mitigation information.

    02051459
    37.5K followersView on X
  • FortiGuard Labs@FortiGuardLabs
    Exploit

    🚨 Just in: Our team has identified #EncystPHP, a persistent FreePBX web shell exploiting CVE-2025-64328 to enable long-term administrative compromise. This activity aligns with INJ3CTOR3 campaigns. Learn why unpatched PBX systems remain prime targets. 🔍 Read the blog: https://ftnt.net/6016hDPCY #FortiGuardLabs

    Post summary

    The tweet reports that the #EncystPHP web shell is actively exploiting CVE-2025-64328 in FreePBX, highlighting an ongoing malicious use scenario that requires immediate patching.

    13040535
    40.9K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/3追加) 🛡️No.1503 CVE-2025-40551 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability ============= CVSSスコア: 9.8 (Base) / SolarWinds CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:信頼できないデータのデシリアライゼーション (CWE-502 / SolarWinds) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからホストマシン上でコマンドを実行される恐れがあります。 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-40551 🛡️No.1504 CVE-2019-19006 Sangoma FreePBX Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:深刻🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、パスワード認証を回避し、FreePBX管理者が提供するサービスにアクセスされる恐れがあります。 https://iki.freepbx.org/display/FOP/2019-11-20%2BRemote%2BAdmin%2BAuthentication%2BBypass 🛡️No.1505 CVE-2025-64328 Sangoma FreePBX OS Command Injection Vulnerability ============= CVSSスコア: 8.6 (Base) / GitHub, Inc. CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 種別:OSコマンドインジェクション (CWE-78 / GitHub, Inc.) 深刻度:重要 ---------------------- 悪用時影響: 認証済みの攻撃者により、testconnection -> check_ssh_connect()関数を介してコマンドインジェクションをされる恐れがあります。この脆弱性を利用して、asteriskユーザーとしてシステムへのリモートアクセスを取得される可能性があります。 https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw 🛡️No.1506 CVE-2021-39935 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability ============= CVSSスコア: 6.8 (Base) / GitHub, Inc. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / GitHub, Inc.) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、CI Lint API を介してサーバーサイドリクエストを実行される恐れがあります。 https://about.gitlab.com/releases/2021/12/06/security-release-gitlab-14-5-2-released/ CISA Adds Four Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed exploitation of four CVEs (CVE‑2025‑40551, CVE‑2019‑19006, CVE‑2025‑64328, CVE‑2021‑39935) and added them to the Known Exploited Vulnerabilities catalog.

    010604.0K
    42.5K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    約900台のFreePBXインスタンスに、CVE-2025-64328の悪用によるものみられるウェブシェルが設置されている。Shadowserver Foundation報告。約400台は米国で、ブラジル、カナダ、ドイツ、フランス、イギリス、イタリア、オランダでも二桁台以上が存在。 https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html

    Post summary

    CVE‑2025‑64328 is actively exploited, with web shells installed on roughly 900 FreePBX instances worldwide, as reported by Shadowserver Foundation.

    010311.1K
    7.3K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    IP data in our Compromised Website report, tagged 'freepbx-compromised' - https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/ Compromised FreePBX tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=compromised_iot&source=compromised_website&source=compromised_website6&tag=freepbx-compromised%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on These compromises are likely via CVE-2025-64328 Additional background from @Fortinet: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp

    Post summary

    The post references a compromised FreePBX report and suggests the incidents are likely due to CVE-2025-64328, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    01022705
    21.6K followersView on X
  • hiro_@papa_anniekey
    Active Exploitation

    KEV追加 CVE-2019-19006 Sangoma FreePBX CVE-2021-39935 GitLab Community and Enterprise Editions CVE-2025-40551 SolarWinds Web Help Desk CVE-2025-64328 Sangoma FreePBX

    Post summary

    The post lists four CVEs added to CISA’s KEV, indicating that these vulnerabilities are currently being exploited in the wild.

    00041681
    6.0K followersView on X
  • hackplayers@hackplayers
    Active Exploitation

    CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html

    Post summary

    CVE-2025-64328 is actively exploited, affecting roughly 900 Sangoma FreePBX instances.

    01011800
    54.9K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-64328 - critical 🚨 FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command Injection > FreePBX Endpoint Manager 17.0.2.36 to < 17.0.3 contains a command injection caused by... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-64328 @pdnuclei #NucleiTemplate...

    Post summary

    The tweet announces CVE-2025-64328, a critical authenticated command injection flaw in FreePBX Endpoint Manager 17.0.2.36 through <17.0.3, without mentioning exploitation, patches, or PoC.

    00020280
    901 followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 900+ FreePBX Servers Still Backdoored After CVE-2025-64328 Exploitation Over 900 Sangoma FreePBX instances remain compromised with web shells after attackers abused the post-auth command-injection flaw CVE-2025-64328 in the Endpoint Manager filestore module to execute commands and plant persistent access. This matters because exposed PBX admin panels can be turned into durable footholds for follow-on intrusion and fraud unless systems are patched, access-restricted, and cleaned. 🕷️ Malware: EncystPHP web shell 🎯 Target: Global/Telecom-VoIP (heavy concentration in the U.S.) #️⃣ Category: #Vulnerability #Malware #TargetedAttacks 🔗 URL: https://www.scworld.com/brief/hundreds-of-freepbx-instances-infected-by-web-shells-exploiting-command-injection-vulnerability

    Post summary

    The post reports that over 900 FreePBX servers remain compromised from CVE‑2025‑64328 exploitation with web shells, urging timely patching and access restrictions to mitigate ongoing attacks.

    01010112
    244 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    【リンク集:2月27日〜3月2日のセキュリティ関連ニュース/記事】 <脆弱性> ・Lovableがホストするアプリに多数の基本的な欠陥、ユーザー1万8,000人以上のデータが流出 https://www.theregister.com/2026/02/27/lovable_app_vulnerabilities/ ・OpenClawの脆弱性ClawJacked、Webサイトを介したAIエージェント乗っ取りが可能に(CVE-2026-25253) https://hackread.com/openclaw-vulnerability-openclaw-hijack-ai-agents/ ・Gardyn Smart Gardensに深刻な脆弱性 リモートハッキングにつながる恐れ(CVE-2025-29631、CVE-2025-1242他) https://www.securityweek.com/critical-flaws-exposed-gardyn-smart-gardens-to-remote-hacking/ ・DuckDuckGoブラウザに脆弱性 Autoconsent JS Bridgeを介したユニバーサルXSS https://medium.com/@dhiraj_mishra/duckduckgo-browser-uxss-via-autoconsent-js-bridge-02e3bc27a430 ・Sangoma FreePBXインスタンス900件がWebシェルに感染(CVE-2025-64328) https://www.securityweek.com/900-sangoma-freepbx-instances-infected-with-web-shells/ <マルウェア・その他脅威> ・トロイの木馬化されたゲームツールがJavaベースのRATを拡散 ブラウザやチャットプラットフォームが媒介に https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html ・米CISA、Ivanti製デバイスへの侵入で使われるRESURGEインプラントについて警告(CVE-2025-0282) https://www.bleepingcomputer.com/news/security/cisa-warns-that-resurge-malware-can-be-dormant-on-ivanti-devices/ ・Steaelite RAT:データ窃取とランサムウェアの機能をまとめた有害ツール https://www.theregister.com/2026/02/27/double_extortion_whammy_steaelite_rat/ ・拡張機能「QuickLens」が暗号資産を窃取 ClickFix攻撃も実行 https://www.bleepingcomputer.com/news/security/quicklens-chrome-extension-steals-crypto-shows-clickfix-attack/ <データ侵害/サイバー犯罪/その他インシデント> ・韓国国税庁がシードフレーズを誤って公開、480万ドル相当の暗号資産が盗まれる https://www.bleepingcomputer.com/news/security/48m-in-crypto-stolen-after-korean-tax-agency-exposes-wallet-seed/ ・OpenAI、予測市場で機密情報を使用したとして従業員を解雇 https://techcrunch.com/2026/02/27/openai-fires-employee-for-using-confidential-info-on-prediction-markets/ <AI関連> ・OpenAI、米国防総省との「技術的保障措置」に関する合意を発表 https://techcrunch.com/2026/02/28/openais-sam-altman-announces-pentagon-deal-with-technical-safeguards/ ・AnthropicのClaude、米国防総省との対立経てApp Storeで1位に https://techcrunch.com/2026/03/01/anthropics-claude-rises-to-no-2-in-the-app-store-following-pentagon-dispute/ ・セキュリティを考慮した小型版OpenClaw「NanoClaw」が開発される https://www.theregister.com/2026/03/01/nanoclaw_container_openclaw/ ・Anthropic、米国防総省のAIガードレール緩和要求に屈せず 期限迫る https://www.securityweek.com/anthropic-refuses-to-bend-to-pentagon-on-ai-safeguards-as-dispute-nears-deadline/ <サイバー戦/APT/国家型アクター/地政学関連> ・AWS中東のデータセンターに「物体が衝突」 イラン戦争の最中に https://www.theregister.com/2026/03/01/asia_tech_news_roundup/ ・イランのインターネットがほぼ完全に遮断される 米とイスラエルの攻撃下で https://securityaffairs.com/188648/cyber-warfare-2/iran-s-internet-near-totally-blacked-out-amid-us-israeli-strikes.html ・イランのサイバー活動の展望 SentinelOneが分析 https://www.sentinelone.com/blog/sentinelone-intelligence-brief-iranian-cyber-activity-outlook/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・ユーロポール、ランサムウェア攻撃や恐喝に関与したThe Comのネットワークを摘発 https://www.helpnetsecurity.com/2026/02/27/europol-the-com-network-arrests/ ・AI活用した偽造IDサイト運営、ウクライナ籍の男が有罪認める https://www.bleepingcomputer.com/news/security/ukrainian-man-pleads-guilty-to-running-ai-powered-fake-id-site/ ・チリ国籍のカーディングショップ運営者、サイバー詐欺関与の疑いで米国に身柄が引き渡される https://www.securityweek.com/chilean-carding-shop-operator-extradited-to-us/ ・米司法省、ロマンス詐欺に関連する6,100万ドル分のテザーコインを押収 https://thehackernews.com/2026/02/doj-seizes-61-million-in-tether-linked.html <プライバシー> ・RedditやHacker Newsで使用される偽名と現実の身元、高い精度で一致可能と判明https://threatroad.substack.com/p/researchers-deanonymize-reddit-and <リサーチ/攻撃手法/TTP> ・CarPlayドングルをリバースエンジニアリング Wi-Fiアクセスからroot化まで https://medium.com/@louis-e/from-wi-fi-access-to-root-reverse-engineering-a-50-carplay-dongle-a3fbeeeb0be9 ・カーネルドライバーをGhidra MCPとClaude Codeでリバースエンジニアリングする方法 https://www.credrelay.com/p/cred-relay-issue-2 ・AIを使ったお手軽リバースエンジニアリング https://blog.huli.tw/2026/03/01/en/reverse-engineering-with-ai-ghidra-mcp/ ・TwitchがiOSアプリでサーバーサイドEppoキーを漏洩、製品ロードマップの全容を公開 https://www.buchodi.com/twitch-ships-server-side-eppo-keys-in-its-ios-app-exposing-its-entire-product-roadmap/ ・北朝鮮のアクターScarCruft、Zoho WorkDriveとマルウェア入りUSBメモリを使ってエアギャップネットワークに侵入 https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html ・ランサムウェアの活動は営業時間外に集中 https://www.helpnetsecurity.com/2026/02/27/sophos-identity-driven-breaches-report/ <政府/政策> ・トランプ大統領、Anthropic製品の使用を段階的に廃止するよう全連邦機関に命令 https://www.securityweek.com/trump-orders-all-federal-agencies-to-phase-out-use-of-anthropic-technology/ ・米カリフォルニア州新法案、Linuxを含む全OSのアカウントセットアップ時に年齢確認を義務化 https://www.pcgamer.com/software/operating-systems/a-new-california-law-says-all-operating-systems-including-linux-need-to-have-some-form-of-age-verification-at-account-setup/ ・米CISAが長官代理を交代 職務混乱の1年を経て https://techcrunch.com/2026/02/27/cisa-replaces-acting-director-gottumukkala-after-a-bumbling-year-on-the-job/ ・欧州議会、保護者の同意なき16歳未満のソーシャルメディア利用を禁止する意見書を承認 https://therecord.media/eu-lawmakers-propose-youth-under-16-social-media-parental-consent <その他> ・堅牢で効率的な耐量子HTTPSの構築 https://security.googleblog.com/2026/02/cultivating-robust-and-efficient.html

    Post summary

    The roundup reports several newly disclosed vulnerabilities, including a CVE in OpenClaw that enables AI agent hijacking, a CVE in Gardyn Smart Gardens that could allow remote hacking, and evidence of active exploitation of a CVE in Sangoma FreePBX with 900 infected instances, but no patches or PoC details are provided.

    00002251
    1.2K followersView on X
  • Shah Sheikh@shah_sheikh
    Active Exploitation

    CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances: About 900 Sangoma FreePBX systems were infected with web shells after attackers exploited a command injection flaw. Hundreds of Sangoma FreePBX instances are still infected with web… https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html?utm_source=dlvr.it&utm_medium=twitter https://t.co/YQKmAkaj6M

    Post summary

    CVE-2025-64328, a command injection flaw in Sangoma FreePBX, has been actively exploited, infecting roughly 900 instances with web shells.

    01010140
    2.2K followersView on X
  • Prateek Tomar@TomarPrateek23
    General

    Just published: Critical Analysis CVE-2025-64328 - Sangoma FreePBX OS Command Injection.... Practical security guidance from the trenches. Read more: https://threatops.tech/blog/critical-analysis-cve-2025-64328-sangoma-freepbx-os-command-injection-vulnerability-february-8-2026

    Post summary

    A blog post announcing a critical analysis of CVE‑2025‑64328 (Sangoma FreePBX OS Command Injection) was released, offering guidance but providing no PoC, exploit code, patch information, or evidence of active exploitation.

    0002060
    76 followersView on X
  • transilienceai@transilienceai
    Active Exploitation

    @__kokumoto **EncystPHP**は、FreePBXの**CVE-2025-64328**(認証後コマンドインジェクション脆弱性)を悪用して展開されるPHPベースのウェブシェルで、FortiGuard Labsが2026年1月28日に報告したものです🛡️ #CVE2025 #FreePBX

    Post summary

    The post reports that the authenticated command‑injection CVE‑2025‑64328 in FreePBX is being actively exploited via the EncystPHP web shell, as confirmed by FortiGuard Labs.

    1001095
    317 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomafilestore-freepbx-

Explore more