Surfshark disclosed that a misconfigured internal test server was accessed by a threat actor, exposing limited engineering data and some build-related credentials, but no user data or production systems were affected. The company said it contained the incident, rotated credentials, added security measures, and will conduct an independent security audit. #Surfshark
Keypoints
- A misconfigured internal test server was exposed to the internet.
- The threat actor accessed limited internal engineering material and system binaries.
- Build-related credentials were found in code history and rotated.
- No user data, VPN traffic, or production services were affected.
- Surfshark contained the incident and will run an independent security audit.
Read More: https://www.securityweek.com/surfshark-systems-targeted-by-hackers/