Malicious backdoor in open-source messaging apps not spotted for 3 months

For almost three months, versions of three widely distributed open-source applications from contained a backdoor that allowed attackers to remotely execute malicious PHP code on systems that ran the programs.

