Frequency
3
occurrences
First Seen
January 29, 2026
Last Seen
March 1, 2026
Related Threat Clusters
-
900 Sangoma FreePBX Instances Compromised by CVE-2025-64328 Exploitation
Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised…
5 articles · Updated March 1, 2026 -
Attackers Exploit FreePBX Vulnerability to Deploy EncystPHP Webshell
Hackers are exploiting a critical vulnerability in FreePBX, specifically CVE-2025-64328, to deploy a persistent webshell named EncystPHP. This attack, attributed to the group INJ3CTOR3, allows complete administrative…
2 articles · Updated January 29, 2026
Recent Intelligence Reports
- Ongoing Cyberattack Exploits Sangoma FreePBX CVE-2025-64328: Over 900 Instances ... — Rescana · March 1, 2026
- Hackers Exploiting FreePBX Vulnerability to Deploy Webshell and Gain Control of Systems — Cybersecuritynews · January 29, 2026
- Hackers Exploiting FreePBX Vulnerability to Deploy Webshell and Gain Control of Systems — Cybersecuritynews · January 29, 2026