3CX softphone compromised by state-level actor in supply chain attack
crowdstrike.com
crowdstrike.com
It looks as though a malicious (signed!) binary has been pushed out through 3CX's update system.
The group accused of this is North Korea's Labyrinth Chollima, they are the ones who were behind Wannacry.
Though at the rate this thread is going the only people who will read it know what an FP is ;)