This will delay things by at least 24 hours so please bear with us. We've also decided to issue a new certificate for this app. New Windows App in ProgressĬurrently, we’re working on a new Windows App that does not have the issue. The vast majority of systems, although they had the files dormant, were in fact never infected. Worth mentioning - this appears to have been a targeted attack from an Advanced Persistent Threat, perhaps even state sponsored, that ran a complex supply chain attack and picked who would be downloading the next stages of their malware. A github repository which listed them has also been shut down, effectively rendering it harmless. The domains contacted by this compromised library have already been reported, with the majority taken down overnight. Here’s some information on what we’ve done so far. We’re still researching the matter to be able to provide a more in depth response later today. The issue appears to be one of the bundled libraries that we compiled into the Windows Electron App via GIT. Electron Mac App version numbers shipped with Update 6, and 18.12.402, 18.12.407 & 18.12.416 in Update 7 are also affected. Anti Virus vendors have flagged the executable 3CXDesktopApp.exe and in many cases uninstalled it. We regret to inform our partners and customers that our Electron Windows App shipped in Update 7, version numbers 18.12.407 & 18.12.416, includes a security issue. UPDATE: The list of Mac versions has been updated on 01/04 11AM UK time to reflect that one of them was shipped with Update 6.
0 Comments
Leave a Reply. |