Related Threat Clusters
-
INJ3CTOR3 Targets FreePBX Systems with JOMANGY Webshell and VoIP Toll Fraud
A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
5 articles · Updated May 22, 2026 -
CISA Identifies Critical Vulnerabilities in SolarWinds, FreePBX, and GitLab
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical-severity vulnerability in SolarWinds Web Help Desk to its Known Exploited Vulnerabilities (KEV) Catalog. This update also includes…
2 articles · Updated February 4, 2026 -
Approximately 900 Sangoma FreePBX Systems Compromised via CVE-2025-64328
Approximately 900 Sangoma FreePBX systems are compromised due to CVE-2025-64328, a command injection vulnerability. This bug was patched in version 17.0.3, but many systems remain unpatched and vulnerable to…
1 article · Updated February 28, 2026 -
900 Sangoma FreePBX Instances Compromised by CVE-2025-64328 Exploitation
Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised…
5 articles · Updated March 1, 2026
Recent Intelligence Reports
- INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks — Thecyberexpress · May 22, 2026
- Ongoing Cyberattack Exploits Sangoma FreePBX CVE-2025-64328: Over 900 Instances ... — Rescana · March 1, 2026
- CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances — Securityaffairs · March 1, 2026
- WARNING: ~900 Sangoma FreePBX systems remain compromised via CVE-2025-64328, a ... — X · February 27, 2026
- 900 Sangoma FreePBX Instances Infected With Web Shells — Feeds.Feedburner · February 27, 2026
- Alert! CISA warns of 4 exploited vulnerabilities — Cybersecurityconnect.Au · February 4, 2026