<div dir="ltr"><div>From a security perspective, the utterly terrifying part of most of these responses boils down to "Oh, must be a glitch in the AV, I'll *whitelist* it so it doesn;t get caught".</div><div><br></div><div>Jesus Wept. I'd be bashing heads if anyone in my company even suggested that without a much more thorough investigation!</div><div><br></div><div>D<br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, 30 Mar 2023 at 16:08, Alexander Neilson <<a href="mailto:alexander@neilson.net.nz">alexander@neilson.net.nz</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr">I haven't seen it personally<div><br></div><div>However others are reporting it as separate investigations they have seen the loader execute:</div><div><a href="https://www.todyl.com/blog/post/threat-advisory-3cx-softphone-telephony-campaign" target="_blank">https://www.todyl.com/blog/post/threat-advisory-3cx-softphone-telephony-campaign</a></div><div><a href="https://www.3cx.com/community/threads/3cx-desktop-app-vulnerability-security-group-contact.119930/" target="_blank">https://www.3cx.com/community/threads/3cx-desktop-app-vulnerability-security-group-contact.119930/</a> - Reports ESET detected it - possibly using signature / hash from S1</div><div><a href="https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/post-558449" target="_blank">https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/post-558449</a> - 

<span style="color:rgb(20,20,20);font-size:14.6667px;background-color:rgb(240,240,240)">Cortex xdr Paloalto</span></div><div><a href="https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/post-558708" target="_blank">https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/post-558708</a> - CrowdStrike</div><div><a href="https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/" target="_blank">https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/</a> - References Sophos</div><div><br></div><div><br></div><div>I am pretty confident that if this isn't a malicious actor doing this then 3CX has performed the mother of all response tests on its customers over the past week and should have had a better reply than silence when they were asked about it.</div><div><br clear="all"><div><div dir="ltr"><div dir="ltr"><div>Regards<br>Alexander<br><br>Alexander Neilson<br>Neilson Productions Limited<br><br><a href="mailto:alexander@neilson.net.nz" target="_blank">alexander@neilson.net.nz</a><br>021 329 681</div><div>022 456 2326</div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, 30 Mar 2023 at 17:57, Matthew Mace <<a href="mailto:matthew@htsol.com.au" target="_blank">matthew@htsol.com.au</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>





<div lang="EN-AU">
<div>
<p class="MsoNormal"><span>Can anyone definitively confirm that they’ve personally seen it get picked up by anything else than S1?
<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal"><span>In addition to  this anyone that has had it installed at a site and also run a premium DNS filtering service (Umbrella, DNS Filter etc.) and/or premium routers with DPI (Sonicwall, Firebox etc.),
 do you know if they picked up this traffic and stopped it? I would be hoping so.
<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal"><span>Definitely curious to know either way.
<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<div>
<p class="MsoNormal"><b><span style="color:black">Matthew Mace<u></u><u></u></span></b></p>
<p class="MsoNormal"><b><span style="color:black"><u></u> <u></u></span></b></p>
<p class="MsoNormal"><span style="color:black"><u></u> <u></u></span></p>
</div>
<div>
<div style="border-color:rgb(225,225,225) currentcolor currentcolor;border-style:solid none none;border-width:1pt medium medium;padding:3pt 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> AusNOG <<a href="mailto:ausnog-bounces@lists.ausnog.net" target="_blank">ausnog-bounces@lists.ausnog.net</a>>
<b>On Behalf Of </b>Nathan Brookfield<br>
<b>Sent:</b> Thursday, March 30, 2023 2:51 PM<br>
<b>To:</b> Christopher Hawker <<a href="mailto:chris@thesysadmin.dev" target="_blank">chris@thesysadmin.dev</a>>; Greg Lipschitz <<a href="mailto:glipschitz@summitinternet.com.au" target="_blank">glipschitz@summitinternet.com.au</a>>; Rob Thomas <<a href="mailto:xrobau@gmail.com" target="_blank">xrobau@gmail.com</a>>; <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>> <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>><br>
<b>Subject:</b> Re: [AusNOG] Critical 3CX Windows/Mac hack.<u></u><u></u></span></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<p class="MsoNormal"><span>To be fair, they likely don’t know much yet and things are probably pretty hectic…. Give them time, crisis management is probably only kicking in now.<u></u><u></u></span></p>
<p class="MsoNormal"><span><u></u> <u></u></span></p>
<div>
<div style="border-color:rgb(225,225,225) currentcolor currentcolor;border-style:solid none none;border-width:1pt medium medium;padding:3pt 0cm 0cm">
<p class="MsoNormal"><b><span lang="EN-US">From:</span></b><span lang="EN-US"> AusNOG <<a href="mailto:ausnog-bounces@lists.ausnog.net" target="_blank">ausnog-bounces@lists.ausnog.net</a>>
<b>On Behalf Of </b>Christopher Hawker<br>
<b>Sent:</b> Thursday, March 30, 2023 3:31 PM<br>
<b>To:</b> Greg Lipschitz <<a href="mailto:glipschitz@summitinternet.com.au" target="_blank">glipschitz@summitinternet.com.au</a>>; Rob Thomas <<a href="mailto:xrobau@gmail.com" target="_blank">xrobau@gmail.com</a>>; <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>> <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>><br>
<b>Subject:</b> Re: [AusNOG] Critical 3CX Windows/Mac hack.<u></u><u></u></span></p>
</div>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">It appears their sales team have no info regarding this. Just rang our Senior AM at 3CX and they've advised that they have no information, and that they are referring anyone who calls to their technical teams via support tickets in the
 3CX portal.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">Not a good look for them.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">CH<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div id="m_4950598188080929043m_-5023834591821559013ms-outlook-mobile-signature">
<p class="MsoNormal">Get <a href="https://aka.ms/AAb9ysg" target="_blank">Outlook for Android</a><u></u><u></u></p>
</div>
<div class="MsoNormal" style="text-align:center" align="center">
<hr width="98%" size="2" align="center">
</div>
<div id="m_4950598188080929043m_-5023834591821559013divRplyFwdMsg">
<p class="MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> AusNOG <<a href="mailto:ausnog-bounces@lists.ausnog.net" target="_blank">ausnog-bounces@lists.ausnog.net</a>> on behalf of Greg Lipschitz <<a href="mailto:glipschitz@summitinternet.com.au" target="_blank">glipschitz@summitinternet.com.au</a>><br>
<b>Sent:</b> Thursday, March 30, 2023 3:09:45 PM<br>
<b>To:</b> Rob Thomas <<a href="mailto:xrobau@gmail.com" target="_blank">xrobau@gmail.com</a>>; <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>> <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>><br>
<b>Subject:</b> Re: [AusNOG] Critical 3CX Windows/Mac hack.</span> <u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black">Here is a list of commands (or make a shell script) to stop it phoning home and getting more payload.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-bottom:12pt;line-height:15.75pt;background:white none repeat scroll 0% 0%">
<span><span style="font-size:10.5pt;font-family:"Courier New";color:green"># Disable 3CX Unattended-Upgrades Service</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:black">systemctl stop unattended-upgrades</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u> <u></u></span></p>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:green"># Collect the version of 3CX Desktop Apps on the Server</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u> <u></u></span></p>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:rgb(121,94,38)">cd</span></span><span><span style="font-size:10.5pt;font-family:"Courier New";color:black"> /var/lib/3cxpbx/Instance1/Data/Http/electron</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:black">ls -la * > /root/3cx-desktop-versions.log</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u> <u></u></span></p>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:green"># Remove the files</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u> <u></u></span></p>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:black">rm -rf /var/lib/3cxpbx/Instance1/Data/Http/electron/osx/*.dmg</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:black">rm -rf /var/lib/3cxpbx/Instance1/Data/Http/electron/osx/*.zip</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:black">rm -rf /var/lib/3cxpbx/Instance1/Data/Http/electron/windows/*.msi</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<p class="MsoNormal" style="line-height:15.75pt;background:white none repeat scroll 0% 0%"><span><span style="font-size:10.5pt;font-family:"Courier New";color:black">rm -rf /var/lib/3cxpbx/Instance1/Data/Http/electron/windows/*.nupkg</span></span><span style="font-size:10.5pt;font-family:"Courier New";color:black"><u></u><u></u></span></p>
</div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><a href="https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/page-5" target="_blank">https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/page-5</a><u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black">Sadly, 3CX haven't even acknowledged this yet.<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black">It would seem that their whole CI-CD pipeline has been compromised<u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black">Greg. <u></u><u></u></span></p>
</div>
<div>
<p class="MsoNormal" style="background:white none repeat scroll 0% 0%"><span style="font-size:12pt;color:black"><u></u> <u></u></span></p>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<table style="background:white none repeat scroll 0% 0%;border-collapse:collapse" cellspacing="0" cellpadding="0" border="0">
<tbody>
<tr>
<td style="padding:0cm" valign="top">
<table style="border-collapse:collapse" cellspacing="0" cellpadding="0" border="0">
<tbody>
<tr>
<td style="padding:0cm" valign="top">
<table style="border-collapse:collapse" cellspacing="0" cellpadding="0" border="0">
<tbody>
<tr>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><b><span style="font-size:9pt;font-family:Arial,sans-serif;color:rgb(0,0,1)">Greg Lipschitz</span></b><b><span style="font-size:1pt;font-family:remialcxesans,serif;color:white">​</span></b><b><span style="font-size:9pt;font-family:Arial,sans-serif;color:rgb(0,0,1)"><u></u><u></u></span></b></p>
</td>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><span style="font-size:9pt;font-family:Arial,sans-serif;color:rgb(0,0,1)"> | <u></u><u></u></span></p>
</td>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><b><span style="font-size:9pt;font-family:Arial,sans-serif;color:rgb(0,0,1)">Founder & CEO<u></u><u></u></span></b></p>
</td>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><span style="font-size:9pt;font-family:Arial,sans-serif;color:rgb(0,0,1)"> | <u></u><u></u></span></p>
</td>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><b><span style="font-size:9pt;font-family:Arial,sans-serif;color:rgb(0,0,1)">Summit Internet<u></u><u></u></span></b></p>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><span style="font-size:9pt;font-family:Arial,sans-serif"><a href="mailto:glipschitz@summitinternet.com.au" target="_blank"><strong><span style="font-family:Arial,sans-serif;color:rgb(37,51,116);font-weight:normal">glipschitz@summitinternet.com.au</span></strong></a><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><span style="font-size:9pt;font-family:Arial,sans-serif"><a href="http://summitinternet.com.au" target="_blank"><strong><span style="font-family:Arial,sans-serif;color:rgb(37,51,116);font-weight:normal">summitinternet.com.au</span></strong></a><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><span style="font-size:9pt;font-family:Arial,sans-serif"><a href="tel:1300%20049%20749" target="_blank"><strong><span style="font-family:Arial,sans-serif;color:rgb(0,0,1);font-weight:normal;text-decoration:none">1300 049 749</span></strong></a><u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td style="padding:0cm" valign="top">
<table style="border-collapse:collapse" cellspacing="0" cellpadding="0" border="0">
<tbody>
<tr>
<td style="padding:0cm" valign="top">
<p class="MsoNormal"><span style="font-size:9pt;font-family:Arial,sans-serif"><a href="https://www.google.com/maps?cid=12522583051503623677&_ga=2.149009334.1057584350.1554770858-1081443428.1554770858" target="_blank"><strong><span style="font-family:Arial,sans-serif;color:rgb(0,0,1);font-weight:normal;text-decoration:none">Unit 2, 31-39 Norcal Road, Nunawading VIC 3131</span></strong></a><u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
<tr>
<td style="padding:7.5pt 0cm 0cm" valign="top">
<p class="MsoNormal"><span style="font-size:1pt;color:black"><img style="width: 0.6875in; height: 0.2291in;" id="m_4950598188080929043m_-5023834591821559013Picture_x0020_2" src="cid:18730e18e974cff311" width="66" height="22" border="0"></span><span style="font-size:1pt"><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:0cm">
<p class="MsoNormal" style="text-align:center" align="center"><span style="font-size:1pt;color:black"><img style="width: 6.1458in; height: 1.1041in;" id="m_4950598188080929043m_-5023834591821559013Picture_x0020_3" src="cid:18730e18e975b16b22" width="590" height="106" border="0"></span><span style="font-size:1pt"><u></u><u></u></span></p>
</td>
</tr>
<tr>
<td style="padding:7.5pt 0cm 0cm" valign="top">
<table style="width:100%;border-collapse:collapse" width="100%" cellspacing="0" cellpadding="0" border="0">
<tbody>
<tr>
<td style="padding:0cm">
<p class="MsoNormal"><a href="http://summitinternet.com.au/" target="_blank"><span style="font-size:1pt;text-decoration:none"><img style="width: 1.8645in; height: 0.3437in;" id="m_4950598188080929043m_-5023834591821559013Picture_x0020_4" src="cid:18730e18e97692e333" alt="Summit Internet" width="179" height="33" border="0"></span></a><span style="font-size:1pt"><u></u><u></u></span></p>
</td>
<td style="padding:0cm">
<p class="MsoNormal" style="text-align:right" align="right"><span style="font-size:1pt"><img style="width: 2.8958in; height: 0.6875in;" id="m_4950598188080929043m_-5023834591821559013Picture_x0020_5" src="cid:18730e18e977745b44" width="278" height="66" border="0"></span><span style="font-size:1pt"><u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
<div class="MsoNormal" style="text-align:center" align="center">
<hr width="98%" size="2" align="center">
</div>
<div id="m_4950598188080929043m_-5023834591821559013x_divRplyFwdMsg">
<p class="MsoNormal"><b><span style="color:black">From:</span></b><span style="color:black"> AusNOG <<a href="mailto:ausnog-bounces@lists.ausnog.net" target="_blank">ausnog-bounces@lists.ausnog.net</a>> on behalf of Rob Thomas <<a href="mailto:xrobau@gmail.com" target="_blank">xrobau@gmail.com</a>><br>
<b>Sent:</b> 30 March 2023 14:54<br>
<b>To:</b> <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>> <<a href="mailto:ausnog@lists.ausnog.net" target="_blank">ausnog@lists.ausnog.net</a>><br>
<b>Subject:</b> [AusNOG] Critical 3CX Windows/Mac hack.</span> <u></u><u></u></p>
<div>
<p class="MsoNormal"> <u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class="MsoNormal">As no-one's mentioned it here yet, I just thought I'd bring up the zero-day, in the wild, active RIGHT NOW, trojan 3CX Windows and Mac apps.
<u></u><u></u></p>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">If you, or you have clients, running 3CX, make sure they ARE NOT using the app. If they are, their machines are probably already owned, and all their stored credentials and session cookies have been leaked.<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal"><a href="https://aus01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.bleepingcomputer.com%2Fnews%2Fsecurity%2Fhackers-compromise-3cx-desktop-app-in-a-supply-chain-attack%2Famp%2F&data=05%7C01%7Cglipschitz%40summitinternet.com.au%7C5134fed0ee3f4dbc894808db30d2a12f%7C0838a12f226e43dfa6e4bb63d2643a7e%7C0%7C0%7C638157453430051909%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=UvNTww7E05nvQnaDQ25Qc8XytZFC%2FhIseT3MHYckCNM%3D&reserved=0" target="_blank">https://www.bleepingcomputer.com/news/security/hackers-compromise-3cx-desktop-app-in-a-supply-chain-attack/amp/</a><u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">This is really bad. Sorry 8-(<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
<div>
<p class="MsoNormal">--Rob<u></u><u></u></p>
</div>
<div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
</div>
</div>
</div>

_______________________________________________<br>
AusNOG mailing list<br>
<a href="mailto:AusNOG@lists.ausnog.net" target="_blank">AusNOG@lists.ausnog.net</a><br>
<a href="https://lists.ausnog.net/mailman/listinfo/ausnog" rel="noreferrer" target="_blank">https://lists.ausnog.net/mailman/listinfo/ausnog</a><br>
</div></blockquote></div>
_______________________________________________<br>
AusNOG mailing list<br>
<a href="mailto:AusNOG@lists.ausnog.net" target="_blank">AusNOG@lists.ausnog.net</a><br>
<a href="https://lists.ausnog.net/mailman/listinfo/ausnog" rel="noreferrer" target="_blank">https://lists.ausnog.net/mailman/listinfo/ausnog</a><br>
</blockquote></div><br clear="all"><br><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature">veg·e·tar·i·an:<br>Ancient tribal slang for the village idiot who can't hunt, fish or ride</div>