Tag: 3CX

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: SQL injection vulnerability with 3CX

Cybersecurity Threat Advisory: SQL injection vulnerability with 3CX

3CX advised customers that the SQL database integration has been disabled due to CVE-2023-49954. Businesses that use MongoDB or any of their web-based customer relationship management (CRM) integration templates are not affected. Read this Cybersecurity Threat Advisory to gain details...

/ December 19, 2023

Cybersecurity Threat Advisory: 3CX supply chain attack updates

This is a follow-up to the 3CX supply chain attack threat advisory. A malware was found in the 3CX VoIP Desktop Application, which has been delivered to users through legitimate 3CX updates. 3CX has since released security updates, and below...

/ March 31, 2023
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Supply chain attack compromised 3CXDesktopApp

Cybersecurity Threat Advisory: Supply chain attack compromised 3CXDesktopApp

A recent compromise has caused trojanized versions of the 3CXDesktopApp executable to be distributed on 3CX’s website as well as pushed through updates. The malicious version of the 3CX application is used to sideload malicious .DLL files. These .DLL files...

/ March 30, 2023 / 11 Comments