Why am I signed out every time I open this? Why can I hardly post anything anywhere? It’s like a dice roll.

  • @RockfuryOP
    link
    English
    11 year ago

    Attack? I am outta the loop. What happened?

    • @fubo
      link
      English
      3
      edit-2
      1 year ago

      https://lemmy.world/post/1290412

      Summary: Attacker found a way to inject JavaScript into the sidebar, letting them steal auth tokens (“JWTs”), including from an admin account. They then used the stolen admin access to vandalize the site. At one point, the attacker used the stolen admin account to falsely announce that the attack had been remediated. Later that day, the attack actually was remediated by the site owner (Ruud) and the vulnerability was patched in the Lemmy code.

      • @RockfuryOP
        link
        English
        11 year ago

        Appreciate the info.