3CX Breach Was a Double Supply Chain Compromise

Krebs on Security 2023-04-20

Summary:

We learned some remarkable new details this week about the recent supply-chain attack on VoIP software provider 3CX, a complex, lengthy intrusion that has the makings of a cyberpunk spy novel: North Korean hackers using legions of fake executive accounts on LinkedIn to lure people into opening malware disguised as a job offer; malware targeting Mac and Linux users working at defense and cryptocurrency firms; and software supply-chain attacks nested within earlier supply chain attacks.

Link:

https://krebsonsecurity.com/2023/04/3cx-breach-was-a-double-supply-chain-compromise/

From feeds:

Intel Hub ยป T04 Krebs on Security

Tags:

3cx

Authors:

BrianKrebs

Date tagged:

04/20/2023, 22:55

Date published:

04/20/2023, 21:05