1 article on this topic.
A single JWT signing key baked into every Issabel Framework install let unauthenticated attackers forge admin tokens and run OS commands on the underlying Asterisk server — and it's now being exploited in the wild.