Agathocles Prodromou

About Agathocles Prodromou - Page 2

CNO, 3CX

Agathocles has worked in the IT sphere for almost 20 years as a Systems Administrator, Web Developer and Penetration Tester. He holds various professional certifications and has a passion for cyber security. As CNO, Agathoklis is leading the IT Network and Security team who are responsible for the monitoring and overall security of the internal/external network/services.

Updated Security Debian Linux Packages

Several security updates have been included in the 3CX Debian ISO. They are available for both Updates 7 and 7A. These security packages are needed to keep the host secure and up to date. Read on to find out how to get them. How to Get the Updated Security Package New users who download the latest ISO and deploy the machine will automatically receive the most recent security up [...]

Update 7 A - Beta - Optional Update

Improved Security Final to be merged into Update 8 Update 7A is now ready for installation - but because these security changes require careful preparation and further understanding, we’ve decided to merge the final release into Update 8. On a positive note, this gives your admin more time to prepare and implement the security changes effectively. Not to disappoint those who wa [...]

Update 7A Alpha - Focus on Password Security and More

First steps towards 7-step action plan 'EFTA' underway. As promised in our sneak peek Update 7A - Focus on Security, we’ve released Update 7A - Alpha today. It remains all about Security. Read on to learn more about the features added, the 5 key points to consider - as well as the action you need to take! And finally, if you’re using the currently released Desktop App for Updat [...]

Actions not words - Our 7 Step Security Action Plan!

Securing for the Future of 3CX after first-of-a-kind, cascading software-in-software supply chain attack We’re committing to actionable steps - 7 to be exact - to harden our systems and minimize our risk of future attacks. Some steps are already completed, some still in process. To this end, we’re currently drafting a Security Charter - called ‘EFTA’. It means 7 in Greek. Here’ [...]

Security Update Thursday 20 April 2023 – Initial Intrusion Vector Found

Mandiant identifies the source of internal network compromise While Mandiant’s investigation is still ongoing, we now have a clear overall understanding of the attack. Following our previous update, we would like to share some additional technical details to support our customers and the community. We have also published additional indicators of compromise that organizations ca [...]

By |April 20th, 2023|Comments Off on Security Update Thursday 20 April 2023 – Initial Intrusion Vector Found

Which Client? PWA vs Desktop vs Native App

Many users followed our advice to deploy our PWA web app mode instead of our Desktop App during the attack. Following this, we learned more about deploying in this mode. I wanted to share some of the things we’ve seen and give some background and suggestions on which is the best to use according to the situation. The PWA (Progressive Web App) app What is a PWA app? PWA stands f [...]

Update 7A - Focus on Security

Following our Security Incident we've decided to make an update focusing entirely on security. We hope to release this update to QA in the coming days. We’ll then release an Alpha and Beta next week - with the final in the week following. Here’s what we’re including: A BLF Panel in the Dialer of PWA “App” This feature mimics a deskphone and shows BLFs similar to a deskphone. BL [...]

New Desktop App Build Number 18.12.425 Released

Update 7 Windows Electron App build number 18.12.424 has been checked by our advisors Mandiant who found no evidence of compromise. Due to certificate changes, we had to update the naming convention. We re-opened the build to address this. Build 18.12.425 has been created and released. Below is our most up to date information. Still Preferred Option: Install 3CX as a Native Web [...]

Security Incident Update Saturday 1 April 2023

We regret to inform you that our company has become victim to an attack on our product and the larger supply chain. Our highest priority is to be transparent in sharing details on what actions we are taking in response to this incident and what we know to date. Information is rapidly unfolding in this ongoing investigation. We want to ensure we only share validated information [...]

No to Electron, yes to PWA or Windows Legacy App

I’ve seen many users going straight in and redeploying the Electron Apps without even considering the PWA or the Windows Legacy App. Although clearly we’re not in a position to anger anyone or make strong demands, it still remains our duty to warn you of the security risks the Electron Apps pose right now. The rebuilt Electron Windows App with the new certificate has been sent [...]