A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
Operation ASTERIX is a sophisticated cryptocurrency fraud campaign that utilized vishing, phishing, and fake wallet applications to steal recovery phrases from victims. Rapid7 researchers discovered an exposed server…
The ATHR cybercrime platform has emerged as a significant tool for executing automated voice phishing (vishing) attacks, utilizing AI agents and human operators to harvest credentials. Advertised on underground forums…
Attackers exploited CVE-2025-64328, a command injection vulnerability, affecting 900 Sangoma FreePBX systems. The exploitation resulted in the installation of web shells, with hundreds of instances remaining compromised…