The hacking group behind the 3CX VoIP company malware attack also compromised two critical infrastructure firms in the energy sector and two financial trading companies using the trojanized X_TRADER application. Symantec’s investigation suggests the attacks are linked to the North Korean group, Lazarus, noting a successful pattern in software supply chain strikes. Initial access was supposedly through an infected version of X_TRADER software, used for futures trading, installed on a 3CX employee’s personal computer.

Data Security Council of India, HIMSS to report on India’s healthcare cybersecurity
The Data Security Council of India (DSCI) and HIMSS have partnered to analyze healthcare cybersecurity in India, signing a memorandum to produce a cybersecurity report.