Surfshark confirmed that a publicly exposed test server was accessed by an attacker, revealing internal service configurations, system binary fragments, and build-related credentials, but no user data or production VPN infrastructure was affected. The company revoked exposed secrets, isolated the server, and pledged stronger controls and independent audits across test and production environments. #Surfshark
Keypoints
- Surfshark exposed a test server to the public internet by mistake.
- An attacker accessed internal configurations and fragments of system binaries.
- Some build-related credentials were found in the code history.
- No user data, browsing history, or cryptographic keys were compromised.
- Surfshark revoked secrets, audited systems, and promised stronger infrastructure security.
Read More: https://securityonline.info/surfshark-test-server-breach/