Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Department of Justice seizes $61 million in Tether linked to pig slaughtering crypto scam

Ongoing web shell attack compromises over 900 Sangoma FreePBX instances

Perplexity’s new computer is another bet where users will need a lot of AI models

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Ongoing web shell attack compromises over 900 Sangoma FreePBX instances
Identity

Ongoing web shell attack compromises over 900 Sangoma FreePBX instances

userBy userFebruary 27, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananFebruary 27, 2026Network security/vulnerabilities

The Shadowserver Foundation revealed that more than 900 Sangoma FreePBX instances remain infected with web shells as part of an attack that exploits a command injection vulnerability starting in December 2025.

Of these, 401 are in the United States, followed by 51 in Brazil, 43 in Canada, 40 in Germany, and 36 in France.

The nonprofit said the breach was likely accomplished by exploiting CVE-2025-64328 (CVSS score: 8.6), a high-severity security flaw that could allow post-authentication command injection.

“The impact is that a user with access to the FreePBX administration panel could leverage this vulnerability to execute arbitrary shell commands on the underlying host. An attacker could leverage this to gain remote access to the system as the Asterisk user,” FreePBX said in a November 2025 advisory about the flaw.

This vulnerability affects FreePBX versions 17.0.2.36 and later. This issue was resolved in version 17.0.3. As a mitigation, we recommend adding security controls to ensure that only authorized users can access the FreePBX Administrator Control Panel (ACP), restricting access to the ACP from hostile networks, and updating the Filestore module to the latest version.

The vulnerability has since been exploited in the wild, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog earlier this month.

Source: Shadow Server Foundation

In a report published late last month, Fortinet FortiGuard Labs revealed that the attackers behind the cyber fraud operation, codenamed INJ3CTOR3, have been exploiting CVE-2025-64328 to deliver a web shell codenamed EncystPHP since early December 2025.

“By leveraging the administrative context of Elastix and FreePBX, the web shell can operate with elevated privileges, execute arbitrary commands on a compromised host, and initiate outgoing call activity through the PBX environment,” the cybersecurity firm said.

FreePBX users are encouraged to update their FreePBX deployments to the latest version as soon as possible to protect against active threats.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticlePerplexity’s new computer is another bet where users will need a lot of AI models
Next Article Department of Justice seizes $61 million in Tether linked to pig slaughtering crypto scam
user
  • Website

Related Posts

Department of Justice seizes $61 million in Tether linked to pig slaughtering crypto scam

February 27, 2026

Malicious Go crypto module steals passwords and deploys Rekoobe backdoor

February 27, 2026

ScarCruft uses Zoho WorkDrive and USB malware to infiltrate air-gapped networks

February 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Department of Justice seizes $61 million in Tether linked to pig slaughtering crypto scam

Ongoing web shell attack compromises over 900 Sangoma FreePBX instances

Perplexity’s new computer is another bet where users will need a lot of AI models

Google and OpenAI employees support Anthropic’s Department of Defense position in open letter

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.