3CX releases new Electron app for desktop after previous supply chain attack – Computer – News


VoIP maker 3CX has launched a brand new model of its desktop software program. It’s the first main launch of the instrument because it was discovered to hold out a critical provide chain assault final month. The instrument has been vetted by safety firm Mandiant.

3CX writes in a weblog put up that it has created a brand new Electron app that may be put in on the desktop. That app has construct quantity 18.12.424, a unique naming conference than was used earlier than. In keeping with 3CX, this has to do with new certificates that needed to be issued for the instrument.

The corporate does want that clients use the progressive internet app use within the browser. This has benefits for customers, says 3CX, similar to that there isn’t a longer any motive to log in further, however safety additionally performs a task; the online app doesn’t undergo from the safety points that the sooner app had.

3CX says the brand new Electron app is accessible for Home windows and macOS. Customers are suggested to first replace the servers on which the app runs to the brand new model. This occurs mechanically for Hosted and StartUP directors. For them, the Electron wrapper can be put in instantly.

The brand new software program is the instrument’s first main replace since final week. Then it turned out to be attackers misused the desktop consumer to distribute malware by way of a provide chain assault. In keeping with the corporate, this was completed by way of a library that got here with the instrument, however particulars aren’t but identified. The malware made it doable to pay attention to conversations and voicemail messages. 3CX is a VoIP supplier with clients similar to McDonald’s and Coca-Cola, in addition to the UK healthcare sector.

Shortly after the assault, 3CX already suggested customers to primarily use the online app. The Electron app has been verified by safety firm Mandiant. That claims to have discovered ‘no proof of an infection’.

A number of customers write on the 3CX discussion board that the instrument is flagged by their virus scanner or by Chrome. In keeping with 3CX, it is a false optimistic report. “Some 3CX domains have been flagged by Google because of the earlier model of the desktop app. We’ve reached out to Google to assessment these domains,” the corporate writes.