Skip Navigation
chat @iusearchlinux.fyi Blaze @iusearchlinux.fyi

Lemmy.world (and some others) were hacked - LemmyWorld

lemmy.world Lemmy.world (and some others) were hacked - LemmyWorld

While I was asleep, apparently the site was hacked. Luckily, (big) part of the lemmy.world team is in US, and some early birds in EU also helped mitigate this. As I am told, this was the issue: - There is an vulnerability which was exploited - Several people had their JWT cookies leaked, including a...

Are we impacted?

11
11 comments
  • Update: this server should hopefully (unless something else shows up) be safe and not vulnerable anymore.

  • We're all being hacked the moment we signed up for this instance. The owner is a notorious hacker wanted by the FBI, CIA, KGB, Sesame Street, and Megatron. Imagine using an Ubuntu server for an Arch instance! The nerve!

    Jk.

    I hope not, tbh. I do hope instance owners and admins have a Matrix/Discord group where they can communicate in real time with each other. I haven't seen any of the comments that allegedly contain the exploit locally. Hopefully the ones in charge update us. :)

    • We do communicate privately, don't worry. Been a busy day at work for me till now so I only seen whats going on exactly now (there were just some reports of lemmy.world being hacked when I woke up this morning and nothing more). I just sent the server owner a link as to how to resolve the situation so hopefully its all resolved soon.

      • Thank you. We do appreciate the stuff you guys do behind the scenes. But I have no life so I'm often on lemmy and might see stuff you guys might miss. 😂

    • To be honest I think we are too small to be a target

11 comments