The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.Referenceshttps://www.wired.com/story/how-the-signal-knock-off-app-telemessage-got-hacked-in-20-minutes/