1 article with this tag
A provider-side compromise cannot be blocked by customer settings, so the defense shifts from prevention to blast-radius reduction. The 10 September investigation results established the part that matters most: the intrusion into the sales management system ran from April 2023 to March 2026 — roughly three years — the affected hosting accounts rose from 583 to 951, and some initial passwords were not hashed. This site's view: treat everything on shared hosting as readable, push secrets, credentials and backups outside the provider, and change any initial password you are still using today.