3CX users face supply chain attack risk due to app vulnerability.

1 min read
Source: Naked Security
TL;DR Summary

Internet telephony company 3CX has warned its customers of malware that was apparently weaseled into the company’s own 3CX Desktop App by cybercriminals who seem to have acquired access to one or more of 3CX’s source code repositories. The malware-laced versions were apparently built and distributed by 3CX itself, so they have the digital signatures you’d expect from the company, and they almost certainly came from an official 3CX download server. 3CX has advised its users to uninstall the Desktop App and switch to using the company’s web-based telephony app for now.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

6 min

vs 7 min read

Condensed

93%

1,23492 words

Want the full story? Read the original article

Read on Naked Security