3CX Desktop App Security Alert
Incident Report for RODIN Business Solutions Status
Resolved
This incident has been resolved.
Posted May 04, 2023 - 18:58 AEST
Update
3CX have confirmed that the compromised Desktop App has since been completely checked and cleaned and can be considered secure.

https://www.3cx.com/blog/news/security-plans/
https://www.3cx.com/blog/news/pwa-desktop-native/

RODIN can now confirm the app is safe to reinstall and use.

RODIN has arranged for the removal of the compromised app from all affected machines and removed the blocks in place from reinstalling/running the 3CX Desktop App.
RODIN has also confirmed that all managed phone systems and app are up to date and reade for reinstall.
Instructions are here to reinstall the 3CX Desktop App: https://rodin.com.au/kb/how-to-install-the-new-3cx-windows-desktop-app/

If you do not know your login you can find it in the 3CX Welcome Email sent to you when your extension was setup.
If you need a copy of your welcome email or need any assistance reinstalling the 3CX Desktop App please email support@rodin.com.au

Rodin would like to take this opportunity to thank all users for their patience and understanding during this time.
Posted May 04, 2023 - 18:56 AEST
Update
3CX have confirmed that the compromised Desktop App has since been completely checked and cleaned and can be considered secure.

https://www.3cx.com/blog/news/security-plans/
https://www.3cx.com/blog/news/pwa-desktop-native/

RODIN is in the process of rolling out the updates and will confirm when the app is safe to reinstall and use.

Further updates to follow.
Posted Apr 27, 2023 - 20:24 AEST
Update
We continue to monitor updates from 3CX and Security support vendors and have made the decision to block the 3CX Desktop App from all workstations.
User will need to move to the Web Client as previously advised, this can be accessed from the 3CX welcome email.
If you require assistance moving to the Web Client, please contact the RODIN Helpdesk.

We are currently rolling out the latest version to devices however the advice is to not use the 3CX desktop app on Windows or MAC until it's confirmed safe.

Instructions for the 3CX Web Client: https://www.3cx.com/user-manual/web-client/
Instructions for the 3CX PWA Client: https://www.3cx.com/blog/releases/web-client-pwa/

RODIN sincerely apologises for any inconvenience caused.
Posted Mar 31, 2023 - 12:27 AEDT
Identified
We have been made aware of the following Security alert for the 3CX desktop application utilised in our RODIN Voice system.
RODIN are working closely with 3CX support guidance and security vendors and will be proceeding with upgrading the 3CX desktop application to all managed customers and sites utilising the RODIN VOICE platform.
Further details and information can be found here.

https://news.sophos.com/en-us/2023/03/30/3cx-desktop-attack-sophos-customer-information/

https://www.3cx.com/blog/news/desktopapp-security-alert/

During these works access to the 3CX desktop app will be limited and we recommend using the 3CX Web App. A link to the Web App can be found in the 3CX Extension welcome email.
Please contact the RODIN helpdesk if you require any assistance with this access. We are currently rolling out the latest version to devices.

Further updates to follow
Posted Mar 31, 2023 - 09:02 AEDT
This incident affected: RODIN Voice.