PSA: Lemmy.world has been compromised! (Edit: Multiple Instances are down)

G59@lemmy.ml to Fediverse@lemmy.ml – 433 points –

FYI!!! In case you start getting re-directed to porn sites.

Maybe the admin got hacked?


edit: lemmy.blahaj.zone has also been hacked. beehaw.org is also down, possibly intentionally by their admins until the issue is fixed.

Post discussing the point of vulnerability: https://lemmy.ml/post/1896249

Github Issue created here: https://github.com/LemmyNet/lemmy-ui/issues/1895

198

You are viewing a single comment

lemmy.blahaj.zone got hacked too, looks like the same people

https://lemmywinks.xyz/post/320087

Huh... so this probably is more sophisticated than a single acct breach then. Lovely.

Yeah, I'd recommend any server admin that doesn't have 2FA turn it on ASAP until we know what their exploiting

Looks like the accounts were compromised by stealing their cookie - something 2FA can't stop.

Still should have it on, though.