3 ms·
Algolia got impacted too, apparently their Salt masters were opened to the whole internet: https://blog.algolia.com/salt-incident-may-3rd-2020-retrospective-and
by scblzn 6y ago
Algolia got impacted too, apparently their Salt masters were opened to the whole internet: https://blog.algolia.com/salt-incident-may-3rd-2020-retrospective-and-update/ https://blog.algolia.com/salt-incident-may-3rd-2020-retrospe...
- jlgaddis 6y agoOne of DigiCert's Certificate Transparency logs was likewise open to the entire Internet -- and likewise compromised [0]: > I'm sad to report that we discovered today that CT Log 2's key used to sign SCTs was compromised last night at 7 pm via the Salt vulnerability. Several other "high-profile" sites have been compromised as well, including LineageOS and Ghost. I expect we'll hear of many more in the next few days. --- [0]: https://groups.google.com/a/chromium.org/forum/m/#!topic/ct-policy/aKNbZuJzwfM https://groups.google.com/a/chromium.org/forum/m/#!topic/ct-...