A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
FreePBX has addressed critical vulnerabilities in its Endpoint Manager module that allow for authentication bypass and remote code execution. Discovered by Horizon3.ai researchers, these vulnerabilities affect telephony…