We talked about the 3CX security issue last week, and it is my approach; I don’t focus on every exploit you need to know but instead on the security trends that impact how IT services are delivered.
To that end, I noted some coverage in Politico. Quote:
“Pyongyang’s attempt to slink into the software delivery pipeline of a widely-used enterprise communications firm named 3CX hasn’t gotten much attention within the Beltway because private sector security companies largely nipped it in the bud. “
Let’s look at the timeline – on March 22, the problems began to surface, as 3CX software triggered alerts in security software that looked suspicious… but the company was slow to respond. Customers began to ignore what they thought was a false positive.
Cut to March 29 when the software began to call home to GitHub and then suspicious web domains controlled by North Korea. That sleep period was to throw off defenders. Still, since 3CX software was already under suspicion, security researchers had, within a day, outed the activity, dismantled Pyongyang’s command and control infrastructure, and contacted the U.S. government.
The key takeaway here is that it’s a win. Sure, the response wasn’t perfect, but it worked and worked pretty quickly. That’s not a reason for less vigilance, but it is encouraging that the investments IN vigilance are working.
Now, the next step around security – making sure this is reported to business leaders. Just like no one calls the network administrator to thank them on the days the network runs, no one calls the security team to thank them for the incident that didn’t happen… or that they didn’t know about. Tie efforts back to business outcomes, and make sure you’re reporting.
