Pierre Jourdan

About Pierre Jourdan - Page 2

AppSec & Interop Manager, 3CX

Pierre has been working in IT for the last 15 years. As a Security Pentester he takes great pride in assuring security of the company and training employees on the threats they may face.

Yealink Firmware Updates for Legacy Models

New firmware ensures compatibility with 3CX V20 Update 7. Yealink has finally released new firmware for several legacy and end-of-life (EOL) phone models. These updates address a security issue recently reported by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), registered under ICSA-25-219-08. 3CX has verified interoperability of these firmware versions with [...]

By |October 16th, 2025|6 Comments

Security Advisory: Disable your SQL Database Integrations

Other CRM integrations are not affected. Only 0.25% of our user base have sequel integrated. It's an old style integration meant for an on-premise firewall secured network. Nevertheless, if you are using an SQL Database integration it’s subject potentially to a vulnerability - depending upon the configuration. As a precautionary measure, and whilst we work on a solution to safe [...]

By |December 15th, 2023|Comments Off on Security Advisory: Disable your SQL Database Integrations

Security Update Tuesday 11 April 2023 - Interim Assessment Concluded

Initial Results from Mandiant Incident Response Following the appointment of Mandiant as our security incident response team, forensic analysis on our network and product is in progress. In a nutshell, the interim assessment concluded: Attribution Based on the Mandiant investigation into the 3CX intrusion and supply chain attack thus far, they attribute the activity to a cluste [...]

By |April 11th, 2023|Comments Off on Security Update Tuesday 11 April 2023 - Interim Assessment Concluded

How to Reset Passwords and Secure Admin Console

We’ve put together a detailed guide on how to reset passwords and secure your admin console, covering all major steps you can take. We’ve included changing your root credentials and what to do if you’ve forgotten them. We also take you through the all important steps of setting a system owner up. Perhaps you want to reset user credentials via the Web Client Admin view, or perfo [...]

Uninstalling the Desktop App

The Desktop App can be uninstalled as explained below. On some Windows machines where antivirus software already deleted some of the files the uninstaller may fail. On Windows: Start Type “Control Panel”, Enter Select “Programs and Features” Find 3CX Desktop App, select and press “Uninstall”. On Mac: Go to “Applications” Tap on “3CX Desktop APP” Right click then “Move to Bin” Ensure that it [...]

3CX DesktopApp Security Alert

UPDATE: The list of Mac versions has been updated on 01/04 11AM UK time to reflect that one of them was shipped with Update 6. We regret to inform our partners and customers that our Electron Windows App shipped in Update 7, version numbers 18.12.407 & 18.12.416, includes a security issue. Anti Virus vendors have flagged the executable 3CXDesktopApp.exe and in many cases uninstalled it [...]

Don’t be “THAT” Guy Vol. 4: Monitor Your Instance

This is the 4th and final edition of our blog series. Last time we highlighted our top 4 security tips in Don’t be that guy Vol.3. In this edition, we will see how you can monitor your PBX system closely and also highlight some stats we have gathered from some unfortunate real-world hacking instances. Email Alerts Keep You Updated First, there are multiple important email notif [...]

By |May 24th, 2022|Comments Off on Don’t be “THAT” Guy Vol. 4: Monitor Your Instance

Don’t be “THAT” Guy Vol. 3: Top 4 PBX Security Tips

Following our last conversation about call fraud, it's time for another installment of our blog series ‘Don't be “THAT” Guy’. In this third edition, we’ve got our top 4 PBX security tips to help you shrink your attack surface and minimize system vulnerability. Security Tip 1: Keep the Global IP Blacklist Enabled The 3CX Global Blacklist is a feature that’s automatically enabled [...]

By |May 2nd, 2022|Comments Off on Don’t be “THAT” Guy Vol. 3: Top 4 PBX Security Tips

Don’t be “THAT” Guy Vol. 2: Call Fraud

This blog post is the second of a series discussing the latest call fraud and hacking schemes we have observed. We spoke previously about the use of weak credentials in Don’t be “THAT” guy Vol.1. We will now focus on the juicy part that they are typically after: “free” calling through your SIP trunks. What's the Hacker's Ultimate Goal? Once they gain access to a user device or [...]

By |April 12th, 2022|Comments Off on Don’t be “THAT” Guy Vol. 2: Call Fraud

Don’t be “THAT” Guy Vol. 1: Keep Complex Credentials

Our recent blog post “3CX Global IP Blacklist: Security By Default” highlighted the importance that we place on security and how we endeavor to combat call fraud and hacking schemes. We finished it up advising to keep an eye out for some more specifics, stats, and patterns. Well, here it is. Over a series of 4 blog posts, we will raise awareness of the various security threats [...]