March 30, 2023, 8:36 p.m. | Paul Ducklin

Naked Security nakedsecurity.sophos.com

Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

3cx app code code repository electron git malware repository risk source code supply supply chain telephone

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior - Penetration Tester

@ Deloitte | Madrid, España

Associate Cyber Incident Responder

@ Highmark Health | PA, Working at Home - Pennsylvania

Senior Insider Threat Analyst

@ IT Concepts Inc. | Woodlawn, Maryland, United States