• News/
  • https://www.theregister.com/2025/07/02/cisa_telemessage_patch/

CISA warns the Signal clone used by natsec staffers is being attacked, so patch now

The Register
·
Iain Thomson
·
Published Jul 2, 2025
·
Updated

The US security watchdog CISA has warned that malicious actors are actively exploiting two flaws in the Signal clone TeleMessage TM SGNL, and has directed federal agencies to patch the flaws or discontinue use of the app by July 22. TeleMessage came to prominence after the Signalgate fiasco, when then-US national security advisor Mike Waltz mistakenly added a journalist to a Signal group chat outlining a March airstrike against Houthi insurgents in Yemen. Since the conversation had messages set to self-delete, government watchdogs raised concerns that the participants were dodging recordkeeping and retention requirements. Subsequent investigations showed this wasn't the case, as Waltz and others were using a Signal clone - dubbed TM SGNL - developed by TeleMessage, which is owned by US archiving biz Smarsh, to keep records of conversations. But when journalist Micah Lee examined the code, he found it to be severely buggy and didn't have proper end-to-end encryption, unlike Signal. Unfortunately for the government, data thieves were quickly on the case, and in May published chat logs and metadata of over 60 government users, including members of the Secret Service and at least one White House official, on the leak site Distributed Denial of Secrets. Now CISA has said that two of the flaws found in TeleMessage, CVE-2025-48927 and CVE-2025-48928, are under "frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," and added them to...

Read full article

Affected Software

1 affected component
TeleMessage TM SGNL

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses security vulnerabilities in the TeleMessage TM SGNL application used by national security staffers and urges immediate patching or discontinuation.

2

What security implications are discussed?

The article highlights that malicious actors are exploiting two critical flaws in the TeleMessage TM SGNL application.

3

What products or software are affected?

The affected software mentioned in the article is TeleMessage TM SGNL.

4

What has CISA recommended regarding the vulnerabilities?

CISA has recommended that federal agencies either apply the necessary patches or cease using the TeleMessage TM SGNL application.

5

Who has issued the warning about these vulnerabilities?

The warning about the vulnerabilities in TeleMessage TM SGNL has been issued by the US security watchdog, CISA.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203