Security Incident Update of ColoCrossing VPS

in #blog6 days ago

It seems Colocrossing is using the Virtualizor.

75268f44b60cb2886613b98dab3be15.png

Here is the email from Colocrossing
image.png

Dear Customer,

We’re reaching out to inform you of a recently resolved security matter involving the control panel software used to manage your ColoCloud virtual servers.

The issue was identified on May 24th and stemmed from a vulnerability in a Single Sign-On (SSO) feature. While this did not impact the ColoCloud billing system (WHMCS) or expose any personal or payment information, the attacker was able to access limited system metadata, email addresses and used our mail server API to send an unauthorized message to ColoCloud customers.

All ColoCloud infrastructure is fully operational and secure. With support from the software vendor, we have taken all necessary steps to address the vulnerability and harden the environment.

As a precaution, we recommend:

Rotating the root password for your virtual server container
If you reuse your Virtualizor password on other platforms, consider updating those as well
These recommendations are made out of an abundance of caution. All stored container passwords remain securely encrypted. Additionally, while we have temporarily disabled access to the Virtualizor control panel, customers may still manage and interact with their virtual servers securely via WHMCS.

We’ve responded quickly and thoroughly to ensure platform security and prevent this from recurring. If you need assistance resetting your passwords, our support team is ready to help.

Please note: this communication applies only to the ColoCloud cloud/vps platform. It does not involve any part of the ColoCrossing dedicated server or colocation infrastructure, which operates on a separate system.

Thank you for your continued trust.

Sincerely,
The ColoCloud Team

See: VPS Database

Steem to the Moon🚀!

Sort:  

Congratulations @justyy, your post was upvoted by @supportive.