Lemmy.world has been timeouting like crazy for me as well. Sigh.
Lemmy NSFW
Updates about lemmynsfw.com
I am hopeful their site admins will get it under control and be transparent about what happened when they are able to. It's unfortunate though that it's happening in the first place.
Admin alt of one of the mods of Mildly Infuriating.
It may have something to do with this message I got:
If I could hazard a guess. Maybe a login token theft, so the hacker has access to an admins account or multiple.
It seems to have spread to lemmy.blahaj.zone. Will add them if more come :( This sucks man.
I was on blahaj and didn't notice the redirects? What are you seeing or hearing?
Thanks for the info!
Wait really? Aren’t they one of the biggest instances?! Shocking and very concerning
Aren’t they one of the biggest instances?!
Which makes them a bigger target.
Just surprised me. I’d figure the larger mainstream ones would generally practice better security.
I have an account signed up there. Should I be worried? How does it affect the user?
We are unsure at this time. Just change any passwords you have that may be the same as what is on that instance just in case.
The attackers would've been able to get the token used to login but not your password from a vulnerability with custom emoji. Lemmy.world rotated their JWT secret so all logins are invalidated and the vulnerability has been patched. Should be just fine.
XSS vulnerability on the sidebar. There's some threads starting to pop up about it.
It just occurred to me while reading this that this is one of the benefits of the federated system - resiliency. If something like this had happened on reddit the entire system would be down until repaired and recovered, but with Lemmy the unaffected instances can disconnect until the issue is resolved, and then reconnect after, while also observing the problem and taking steps to fix the vulnerability on their own systems.