3CX VOIP Compromised in March 2023 Supply Chain Attack

Поділитися
Вставка

КОМЕНТАРІ • 50

  • @_JohnHammond
    @_JohnHammond Рік тому +31

    NICE SHIRT :)

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  Рік тому +9

      We should have coordinated wearing the same shirts for this topic.

    • @JzJad
      @JzJad Рік тому +1

      Going to have to send him another shirt :D

  • @64cheesepuffs
    @64cheesepuffs Рік тому +13

    Just had a late night dealing with this and am happy to see it blowing up in the news more this morning. The 3CX forum threw me for a loop with considering it a false positive last week, especially with the 3CX LTD official signature on the files.

  • @sarhtaq
    @sarhtaq Рік тому +7

    At 16:55 UTC they have this on their blog:
    windows app shipped in Update 7, version numbers 18.12.407 & 18.12.416, included a severe security issue.
    We since learned that Electron Mac App version numbers 18.11.1213, 18.12.402, 18.12.407 & 18.12.416 have also been affected.

  • @awsomehackz21
    @awsomehackz21 Рік тому +5

    I agree that open source code is a good thing for the community!

  • @JordanAlbaladejo
    @JordanAlbaladejo Рік тому

    Great video! Thanks for sharing on social media when alerted!

  • @Raima888s
    @Raima888s Рік тому +4

    Was on the team that detected the incident last week with sentinelone which was then notified to 3CX.

  • @FrederickMarcoux
    @FrederickMarcoux Рік тому +9

    We were part of those who signaled 3CX on the 22nd about S1 flagging it. Most of us thought it was a false positive at first.

    • @LAWRENCESYSTEMS
      @LAWRENCESYSTEMS  Рік тому +6

      Don't feel bad most everybody thought it was a false positive.

  • @armedscubasteve
    @armedscubasteve Рік тому

    Wow! Thanks for the update!!

  • @TheFlatronify
    @TheFlatronify Рік тому +1

    Thanks, great quick summary! This is going to be interesting in the long run.

  • @JosephBrunsman
    @JosephBrunsman Рік тому

    Thanks for the update Tom! great info!

  • @jaybigboy34
    @jaybigboy34 Рік тому

    Thanks for the quick heads up.

  • @cheebydi
    @cheebydi Рік тому +1

    Thumbnail on point - gave us a chuckle.

  • @berndeckenfels
    @berndeckenfels Рік тому +5

    I Wonder if upstream source was compromised and others might distribute that ffmpeg as well or if they had their built system directly compromised.

  • @allannjuguna598
    @allannjuguna598 Рік тому

    big fan of your detailed breakdowns, from the solar winds video, i became hooked, big fan from kenya :)

  • @markalmada9662
    @markalmada9662 Рік тому +1

    Thanks as always Tom. I notice your wearing specticals these days just like me. I contacted 3cx day one when sentinel one stopped the update in 111ms. Warned the team this could be a supply chain attack. Confusion among the guys as digitally signed thinking a fasle positive Only 3x Nodes with desktop app. We uninstalled and held. I think it was 3 days get a response of any sense from 3cx to confirm it was a compromise.

  • @Pray4ragE
    @Pray4ragE Рік тому +1

    This has been Tom, reporting to you live from Hollywood :P

  • @EmperorCheed
    @EmperorCheed Рік тому +2

    We moved off 3CX last year, dodged a little bullet with this one.

  • @blakedrayson
    @blakedrayson Рік тому

    Great video very informative thanks for the clear explanation, total aside what is running on your monitor in the background?

  • @raymondjr592
    @raymondjr592 Рік тому +5

    Where did you get that screensaver

  • @JzJad
    @JzJad Рік тому

    Yeah the client update and install was a week previous, then we started seeing activity all at once.

  • @aaron6841
    @aaron6841 Рік тому +1

    We used this at work untill today

  • @sbccave4015
    @sbccave4015 Рік тому

    Thanks for the heads-up. RMM is showing us all clear with our clients :)

  • @IndyColts1987
    @IndyColts1987 Рік тому +1

    today was such a rough day getting everyone to uninstall and switch to web.

  • @idahofur
    @idahofur Рік тому

    I assume you saw the report years ago about the shipping between two spots and credit card machines being infected?

  • @ackzero5972
    @ackzero5972 Рік тому

    Alright the title brought me here but the desktop screensaver in the background mesmerized me...need info.

  • @dominix
    @dominix Рік тому

    nice t-shirt

  • @TheLakeJake3
    @TheLakeJake3 Рік тому +2

    Lmao at the thumbnail

  • @speedermarto
    @speedermarto Рік тому

    What is going on with that monitor behind you?
    Is that some video wallpaper? 😅

  • @x91w
    @x91w Рік тому

    00:29 - Your spellchecker has been hacked "Verions" intead of "Versions" ?

    • @28469
      @28469 Рік тому +1

      Big whoop

  • @user9005
    @user9005 Рік тому

    So nobody knows if this virus was succesful at doing anything malicious?

    • @markalmada9662
      @markalmada9662 Рік тому

      I think what Toms getting at it is. they comprised 3cx everyone updated. The potential hackers probably state sponsored then used it to access and compromise some specific people. Diplomat for example.

  • @harveybolton
    @harveybolton Рік тому

    The biggest concern from me is 3CX still haven't named the upstream library that they claim was infected, and there is no reason not to. Was it an open source library they didn't provide attribution and code for? Was it a complete lie? We need to know if the 3cx development pipeline was compromised or if there is an infected library out there that could affect other services and projects

  • @perryuploads776
    @perryuploads776 Рік тому

    Why involve the North Korean guy 😂He has nothing to do with it

    • @randomicon918
      @randomicon918 Рік тому

      “North Korea guy”? Is a Google search that hard?
      Kim jong-un’s government hackers are the suspected culprits. So yeah, he is involved.

    • @d_must4309
      @d_must4309 Рік тому +1

      Because western propaganda

    • @YouTubeGlobalAdminstrator
      @YouTubeGlobalAdminstrator Рік тому +1

      ​@@d_must4309 Triggered much? 😂
      Continue sipping your Starbucks latte, on your Mac with your Che Guevara T-shirt. 😂

    • @markalmada9662
      @markalmada9662 Рік тому

      Rocket man loves using 3CX 😮

  • @chris_schenkel
    @chris_schenkel Рік тому +1

    Congrats Tom. You are now a professional youtuber. Clickbait thumbnails and wasteful intros. Well done. I subbed back in 2018 when you had less than 10k subs. The beatnik Tom days. Back then you were just an IT pro sharing some useful knowledge. It was great. I even clicked on some ads to help you out. Then came the hobo Tom phase. Much more commercial and much less interesting and informative. That's when I implemented pfBlocker and Brave browser to block all ads. Just for you. Now, in 2023, we are entering the fake intellectual Tom phase with the glasses and the clickbait and the intros. I have no interest in or respect for people who think that youtube is a profession. It won't be long until the sponsored reviews start to appear, if they haven't already. Greed is always followed by corruption. I"m out.

  • @pqowi9098
    @pqowi9098 Рік тому

    First