{"id":14909,"date":"2023-03-31T11:11:21","date_gmt":"2023-03-31T09:11:21","guid":{"rendered":"http:\/\/nfirjun2026.local\/supply-chain-attack-on-3cx-digital-attack-on-popular-enterprise-voip-software-cve-2023-29059\/"},"modified":"2024-02-12T14:12:57","modified_gmt":"2024-02-12T13:12:57","slug":"supply-chain-attack-on-3cx-digital-attack-on-popular-enterprise-voip-software-cve-2023-29059","status":"publish","type":"post","link":"https:\/\/www.cyber-security-online.nl\/en\/supply-chain-attack-on-3cx-digital-attack-on-popular-enterprise-voip-software-cve-2023-29059\/","title":{"rendered":"Supply Chain Attack on 3CX: digital attack on popular enterprise VoIP software. (CVE-2023-29059)"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"14909\" class=\"elementor elementor-14909 elementor-14506\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-06c4724 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"06c4724\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fb77167\" data-id=\"fb77167\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-cca9d26 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cca9d26\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-b11f1dc\" data-id=\"b11f1dc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1234310 elementor-widget elementor-widget-text-editor\" data-id=\"1234310\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>On March 30, Cybersecurity firm <a href=\"https:\/\/www.crowdstrike.com\/blog\/CrowdStrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers\/\" target=\"_blank\" rel=\"nofollow noopener\">CrowdStrike <\/a>said it had observed a digital attack on users of the software package 3CX. This attack is also called a supply chain attack &#8211; in which a software vendor&#8217;s distribution and\/or update channels are abused to distribute rogue software. <\/strong><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-abb320e elementor-widget elementor-widget-text-editor\" data-id=\"abb320e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>3CX is a widely used and comprehensive Voice-over-IP (VoIP) software solution for businesses, used by telephone exchanges, among others. NFIR advises users of this software to take immediate action. The attack has been assigned the CVE number <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-29059\" target=\"_blank\" rel=\"noopener\">CVE-2023-29059<\/a>.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-655df5b elementor-widget elementor-widget-text-editor\" data-id=\"655df5b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tThe affected versions of the 3CX VoIP product involve at least the following:\n<table width=\"599\">\n<tbody>\n<tr>\n<td width=\"329\"><strong>Product<\/strong><\/td>\n<td width=\"270\"><strong>Platform<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"329\">3CX version 18.12.407<br>\n3CX version 18.12.416<\/td>\n<td width=\"270\">Electron Windows<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">3CX version 18.11.1213<\/td>\n<td width=\"270\">Electron MacOS 18.11<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">3CX version 18.12.402<br>\n3CX version 18.12.407<br>\n3CX version 18.12.416<\/td>\n<td width=\"270\">Electron MacOS 18.12<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\nNFIR recommends determining whether rogue versions of 3CX as described above are present on systems within your organization. The rogue versions are distributed by a rogue piece of software in 3CX Desktop App update 7. This update has been available since the end of March 2023, according to 3CX. If you detect an infected version, NFIR recommends incident response &amp; digital forensics.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-f4bff09\" data-id=\"f4bff09\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-996aa7a elementor-widget elementor-widget-image\" data-id=\"996aa7a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t<figure class=\"wp-caption\">\n\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/upload.wikimedia.org\/wikipedia\/commons\/thumb\/4\/4e\/3cx_logo.svg\/220px-3cx_logo.svg.png\" title=\"\" alt=\"\" loading=\"lazy\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t<figcaption class=\"widget-image-caption wp-caption-text\"><a href=\"https:\/\/en.wikipedia.org\/wiki\/3CX\">3CX Wikipedia<\/a><\/figcaption>\n\t\t\t\t\t\t\t\t\t\t<\/figure>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-49b2fd5 elementor-widget elementor-widget-button\" data-id=\"49b2fd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/03\/NFIR-Threat-Intelligence-Report-3CX-VOIP-Supply-chain-attack-v1.0.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Threat Intelligence Report on vulnerability in Confluence (CVE-2022-26134) here.<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4f56d9b elementor-cta--layout-image-above elementor-cta--skin-classic elementor-animated-content elementor-bg-transform elementor-bg-transform-zoom-in elementor-widget elementor-widget-call-to-action\" data-id=\"4f56d9b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"call-to-action.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<a class=\"elementor-cta\" href=\"tel:+31881330700\">\n\t\t\t\t\t<div class=\"elementor-cta__bg-wrapper\">\n\t\t\t\t<div class=\"elementor-cta__bg elementor-bg\" style=\"background-image: url(https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2019\/06\/Incident-Response.png);\" role=\"img\" aria-label=\"Incident Response specialist available 24\/7\"><\/div>\n\t\t\t\t<div class=\"elementor-cta__bg-overlay\"><\/div>\n\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-cta__content\">\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<h2 class=\"elementor-cta__title elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\tNeed immediate help?\t\t\t\t\t<\/h2>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__description elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\t<p>Then call our 24\/7 CERT line at <a href=\"tel:+31881330700\">088 133 0700<\/a> and we will do<br \/>\nour best efforts to help you as quickly as possible.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__button-wrapper elementor-cta__content-item elementor-content-item \">\n\t\t\t\t\t<span class=\"elementor-cta__button elementor-button elementor-size-md\">\n\t\t\t\t\t\tCall us now\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c689935 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c689935\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-c944514\" data-id=\"c944514\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-44aa2a9 nfir-from-uael-faq nfir-faq-schema elementor-widget elementor-widget-accordion\" data-id=\"44aa2a9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7201\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-7201\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What potential impact does this Confluence vulnerability have?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7201\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-7201\"><p>The following commands allow you to establish the presence of 3CX on devices within your organization:<\/p><h3><strong>Windows systems<\/strong><\/h3><blockquote><p># Checking if there is an active process related to 3CX<\/p><p>Get-WmiObject -Class Win32_Process -Filter &#8220;Name=&#8217;3CXDesktopApp.exe'&#8221;<\/p><p># Checking Windows registry<\/p><p>Get-ItemProperty -Path &#8216;HKLM:\u3010OFTWARE\u3011&#8217; -ErrorAction SilentlyContinue | Where-Object { $_.DisplayName -like &#8216;3CX Desktop App&#8217; }<\/p><p># Control of 3CX user profiles.<\/p><p>Test-Path -Path C:C:C.<\/p><\/blockquote><hr><h3><strong>MacOS systems<\/strong><\/h3><blockquote><p># Check for presence of program on macOS in \/Applications<\/p><p>ls &#8216;\/Applications&#8217; | grep &#8216;3CX&#8217;<\/p><p># Checking for the presence of a folder within Application support folder<\/p><p>if [ -d \/Users\/*\/Library\/Application Support\/3CXDesktop App\/ ]; then echo &#8220;3CXDesktop exists&#8221;; fi<\/p><\/blockquote><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7202\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-7202\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How is the Confluence vulnerability detectable?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7202\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-7202\">Based on publicly available information, at least the following rogue domain names have been identified:\n<table width=\"587\">\n<tbody>\n<tr>\n<td colspan=\"2\" width=\"587\"><strong>Domain names<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"329\">akamaicontainer[.]com<\/td>\n<td width=\"270\">msedgepackageinfo[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">akamaitechcloudservices[.]com<\/td>\n<td width=\"270\">msstorageazure[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">azuredeploystore[.]com<\/td>\n<td width=\"270\">msstorageboxes[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">azureonlinecloud[.]com<\/td>\n<td width=\"270\">officeaddons[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">azureonlinestorage[.]com<\/td>\n<td width=\"270\">officestoragebox[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">dunamistrd[.]com<\/td>\n<td width=\"270\">pbxcloudeservices[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">glcloudservice[.]com<\/td>\n<td width=\"270\">pbxphonenetwork[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">qwepoi123098[.]com<\/td>\n<td>zacharryblogs[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">sbmsa[.]wiki<\/td>\n<td width=\"270\">pbxsources[.]com<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">sourceslabs[.]com<\/td>\n<td width=\"270\">journalide[.]org<\/td>\n<\/tr>\n<tr>\n<td width=\"329\">visualstudiofactory[.]com<\/td>\n<td width=\"270\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\nNFIR recommends configuring the above domain names within IDS\/IPS\/EDR solutions as detection rules. This is an ongoing current situation in which new indicators of an infection may become available. If you suspect you have been affected by this supply-chain attack, NFIR advises you to have incident response &amp; forensic investigations done into whether your systems have been affected.<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7203\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-7203\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Is there an action plan that your organization can follow? <\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7203\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-7203\"><p>It is important for your organization to take at least the following steps:<\/p><ol><li>Check publicly available Indicators-of-Compromise (IoCs) on your systems to determine if any systems may have been compromised, or have external preventive research performed on your systems.<ol><li>Following the <a href=\"https:\/\/www.ncsc.nl\/actueel\/nieuws\/2023\/maart\/30\/ncsc-waarschuwt-voor-supplychain-aanval-3cx\" target=\"_blank\" rel=\"nofollow noopener\">opinion of the NCSC<\/a> advises NFIR to remove the rogue versions of the 3CX software and wait until a &#8220;safe&#8221; version is published by the software vendor &#8211; in the meantime, 3CX recommends using the PWA variant of the application &#8211; <a href=\"https:\/\/www.3cx.com\/blog\/news\/desktopapp-security-alert\/\" target=\"_blank\" rel=\"nofollow noopener\">3CX Security Alert for Electron Windows App | Desktop App<\/a>.<\/li><\/ol><\/li><li>Prepare your organization for the situation when patches need to be executed unexpectedly (outside the regular update timeframes) and apply patches in a controlled manner according to the procedure usual for your organization.<\/li><li>If your organization is using 3CX, NFIR recommends always having forensics performed to determine if your environment has been compromised.<\/li><\/ol><p>Do you have systems where the risk is high (for example, systems with very sensitive or special personal data)? If so, do you possibly have indications that the system cannot be mitigated and\/or updated immediately? Then consider temporarily disabling the system until it can be updated.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-7204\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-7204\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What should your organization do in case of potential abuse?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-7204\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-7204\"><p>If your organization is suspected to have been the victim of an attack, the urgent advice is to have research conducted into the cause, to what extent attackers may have compromised other systems and what information may have been accessed unauthorized.<\/p><ol><li>If possible, disconnect affected systems from the network, but leave them on (in connection with any traces such as volatile memory &#8211; RAM);<\/li><li>Have the affected systems forensically examined; ensure adequate backups;<\/li><li>Reset your passwords and user data;<\/li><li>Report to the Police;<\/li><li>Consider filing a report with the Personal Data Authority.<\/li><\/ol><p>Does your organization currently have an incident?  <a href=\"https:\/\/www.cyber-security-online.nl\/en\/security-incident-call-us-24-7\/\">Our Computer Emergency Response Teams  <\/a><br>(CERT) are available to organizations 24\/7 to support IT Security Incidents.<br>Then call <a href=\"tel:+31881330700\">088 133 0700<\/a> and we will do our best to help you as soon as possible.<\/p><p><a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\">Learn more about our Incident Response Service<\/a><\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c8e9788 elementor-widget elementor-widget-text-editor\" data-id=\"c8e9788\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Does your organization currently have an incident? Our Computer Emergency Response Teams (CERT) are available to organizations 24\/7 to support IT Security Incidents.<\/p>\n<p>Then call<a href=\"tel:+31881330700\"> 088 133 0700<\/a> and we will do our best to help you as soon as possible. Here you will find more <a href=\"https:\/\/www.cyber-security-online.nl\/en\/incident-response-specialist-24-7-availability\/\" data-wplink-edit=\"true\">information about our Incident Response <\/a>service.<\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9997d22 elementor-widget elementor-widget-button\" data-id=\"9997d22\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/03\/NFIR-Threat-Intelligence-Report-3CX-VOIP-Supply-chain-attack-v1.0.pdf\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t<span class=\"elementor-button-icon\">\n\t\t\t\t<i aria-hidden=\"true\" class=\"far fa-file-pdf\"><\/i>\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Download the Threat Intelligence Report on vulnerability in Confluence (CVE-2022-26134) here.<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b68b35c elementor-widget elementor-widget-text-editor\" data-id=\"b68b35c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><em>Disclaimer: NFIR has made every effort to make this information accurate and reliable. However, the information provided is without any guarantee of any kind and its use is entirely at the risk of the user. NFIR assumes no responsibility or liability for the accuracy, content, completeness, legality or reliability of the information provided.<\/em><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>On March 30, Cybersecurity firm CrowdStrike said it had observed a digital attack on users of the software package 3CX. This attack is also called [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":14556,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"Threat intel report: supply chain attack on 3CX: digital attack on popular enterprise VoIP software. (CVE-2023-29059)","_seopress_titles_desc":"Cybersecurity firm CrowdStrike has observed a supply chain attack, CVE-2023-29059, on users of the software package 3CX. Find out here how your organization can protect itself from this attack: indicators of compromise, detection rules and steps to protect your organization.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"40","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/03\/koeleman-a-photorealistic-image-of-a-laptop-with-a-headset-that-e4af4612-f73e-4f42-bd2e-42920f0f36e3-1-.jpg","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2023\/03\/koeleman-a-photorealistic-image-of-a-laptop-with-a-headset-that-e4af4612-f73e-4f42-bd2e-42920f0f36e3-1-.jpg","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[29,51],"tags":[],"class_list":["post-14909","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media-en","category-threat-intelligence-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/14909","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=14909"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/14909\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media\/14556"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=14909"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/categories?post=14909"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/tags?post=14909"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}