cryptotech.gg-logo cryptotech.gg-logo
  • News
  • Markets
    • Crypto Stocks
    • Price Analysis
    • Price Calculator
    • Price Prediction
  • Cryptocurrency
    • Bitcoin
      • Bitcoin Cash
      • BNB
    • Dogecoin
    • Ethereum
    • Litecoin
    • Shiba Inu Coin
    • Solana
    • TRON
    • USD Coin
  • Crypto Wallets
  • Crypto Gaming
    • GameFi
  • Reviews
  • Best Anonymous Casinos
  • Top Bitcoin Casinos
  • Top Mobile Casinos
  • Top New Casinos 2025
Reading: TeleMessage Vulnerability Exploited by Hackers Despite Patch, Warns GreyNoise
Share
Font ResizerAa
Crypto TechCrypto Tech
  • News
  • Markets
  • Cryptocurrency
  • Crypto Wallets
  • Crypto Gaming
  • Reviews
  • Best Anonymous Casinos
  • Top Bitcoin Casinos
  • Top Mobile Casinos
  • Top New Casinos 2025
Search
  • News
  • Markets
    • Crypto Stocks
    • Price Analysis
    • Price Calculator
    • Price Prediction
  • Cryptocurrency
    • Bitcoin
    • Dogecoin
    • Ethereum
    • Litecoin
    • Shiba Inu Coin
    • Solana
    • TRON
    • USD Coin
  • Crypto Wallets
  • Crypto Gaming
    • GameFi
  • Reviews
  • Best Anonymous Casinos
  • Top Bitcoin Casinos
  • Top Mobile Casinos
  • Top New Casinos 2025
CryptoTech | All Rights Reserved.

TeleMessage Vulnerability Exploited by Hackers Despite Patch, Warns GreyNoise

Last updated: July 21, 2025 4:54 am
Published: July 21, 2025
Share
TeleMessage Vulnerability Exploited by Hackers Despite Patch, Warns GreyNoise
TeleMessage Vulnerability Exploited by Hackers Despite Patch, Warns GreyNoise


Your browser does not support the video tag.

Hackers are actively targeting a critical security flaw, CVE-2025-48927, in TeleMessage, a chat archiving platform used for regulatory compliance. According to a recent report by GreyNoise, malicious actors have ramped up attempts to exploit the vulnerability, which affects the Spring Boot Actuator component, specifically the publicly exposed /heapdump endpoint.

Contents
Legacy Flaw in Spring Boot Leaves Systems ExposedTeleMessage Breach Raises Alarms Across Enterprises

Legacy Flaw in Spring Boot Leaves Systems Exposed

The vulnerability arises from a legacy confirmation issue in Spring Boot Actuator, where the /heapdump endpoint can be accessed without authentication. This flaw can allow attackers to extract sensitive application data, posing a serious risk to organizations relying on the framework.

Since April 2025, GreyNoise has identified 11 IP addresses actively trying to exploit this specific flaw. In addition, a staggering 2,009 IP addresses have been observed scanning for Spring Boot Actuator endpoints, with 1,582 of them targeting the /health endpoint — indicating widespread reconnaissance and potential exploitation attempts.

TeleMessage Breach Raises Alarms Across Enterprises

TeleMessage, acquired by Smarsh in 2024, faced a major data breach in May 2025 that resulted in stolen files. Although the company claims to have patched the vulnerability, GreyNoise cautions that patch rollout timelines can vary across environments, leaving systems exposed during the transition.

Used by enterprises and even former U.S. government officials, TeleMessage plays a critical role in archiving messaging data for legal and compliance needs. The breach and continued exploit activity raise concerns over the security of sensitive communications.

GreyNoise strongly advises organizations to:

  • Restrict public access to the /heapdump endpoint.

  • Block known malicious IP addresses involved in exploit attempts.

  • Regularly audit and update Spring Boot configurations to avoid legacy exposure.

Meanwhile, broader cybersecurity threats continue to surge. Crypto-related thefts have topped $2.17 billion in 2025 alone, reflecting the evolving threat landscape.

Proactive patching, endpoint hardening, and threat intelligence monitoring are key to minimizing risk and protecting organizational data from emerging vulnerabilities like CVE-2025-48927.


Your browser does not support the video tag.

TAGGED:CVE-2025-48927heapdump endpoint exploitSpring Boot Actuator flawTeleMessage vulnerability
Share This Article
Facebook Email Copy Link Print
Previous Article MultiBank Group's $MBG Token to Launch on MEXC and Gate.io on July 22 MultiBank Group’s $MBG Token to Launch on MEXC and Gate.io on July 22
Next Article Ethereum’s Upcoming Fusaka Upgrade to Boost Scalability and Efficiency Ethereum’s Upcoming Fusaka Upgrade to Boost Scalability and Efficiency
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


Your browser does not support the video tag.

Price Chart

# Name Price Changes 24h Market CAPVolumeSupply
cryptotech.gg-logo cryptotech.gg-logo

Cryptotech.gg is the most genuine and authentic crypto website, that provides the best insights of market along with the latest news of trends.

Explore

  • Trending News
  • Top Litecoin Casinos
  • Best Ethereum Casinos
  • Top New Casinos 2025

CRYPTOTECH.GG​

  • About Us
  • Terms & Conditions
  • Contact
©Crypto Tech | All Rights Reserved.
  • Trending News
  • Top Litecoin Casinos
  • Best Ethereum Casinos
  • Top New Casinos 2025
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?