March 30, 2023, 8:36 p.m. | Paul Ducklin

Naked Security nakedsecurity.sophos.com

Booby-trapped app, apparently signed and shipped by 3CX itself after its source code repository was broken into.

3cx app code code repository electron git malware repository risk source code supply supply chain telephone

Red Team Operator

@ JPMorgan Chase & Co. | LONDON, United Kingdom

SOC Analyst

@ Resillion | Bengaluru, India

Director of Cyber Security

@ Revinate | San Francisco Bay Area

Jr. Security Incident Response Analyst

@ Kaseya | Miami, Florida, United States

Infrastructure Vulnerability Consultant - (Cloud Security , CSPM)

@ Blue Yonder | Hyderabad

Product Security Lead

@ Lely | Maassluis, Netherlands