Yea. It has already been fixed now though.
nosut
It's all public information.
Admins are shown on the front page
Modlog shows even when an admin is added or removed.
Blocked instances are shown in the instances list.
The JWT exploit bypasses 2FA requirements. It basically steals your active session and allows a third party to use it.
Thanks for the work. As a heads up it appears most of the block instances are back however I believe explodingheads is still missing which you may want to confirm.
EDIT: it has been added back to the block list.
They were modded 20 days ago.
I find it unlikely to be necessary because the MichelleG account shouldnt have needed database access and it appears the attack was troll related with basic XSS redirects. You can wait for an official response however it is always good policy for yourself to do so anyways.
Its not the cache. The site is still under attack.
Its not the cache. The site is still under attack.
Yea MichelleG's account is likely still compromised.
Yup. Just saw that as well.
Yep. MichelleG admin was added back and posted an update but it doesnt appear that her account was fully secured so they are probably still accessing it via her account.
Thank you for making a statement about it!