3CX has announced a security update thst primarily address's issues with weak passwords on phone extensions.
Of course, weak passwords aren't an issue exclusive to 3CX and we are seeing more instances of them being exploited across all platforms. Here is the announcement of the update
It has come to our attention that many installations of 3CX Phone System are deployed with weak passwords. This can result in hackers guessing the passwords and compromising the system. This security update has many features that will make your 3CX Phone System Server more secure and protect it from attacks. It is very important that this update is performed asap. Download the latest security update service pack from within your 3CX Phone System installation (Windows Management console only).
The remainder of the announcement can be viewed through the link below

