Several products I’m leading have been impacted by #ShaiHulud2 since 25/11 at 21:22 UTC. The teams and contributors are working hard to restore
@opentermsarchive and
@openfisca.
Websites are back up, containment and mitigation in place. We are now rotating credentials and will work on restoring data as soon as it is safe to do so without reopening vulnerabilities.
https://ParisCall.international is also down, ironically (it's the website of the Paris Call for Security in Cyberspace).
#ShaiHulud
We have #ShaiHulud symptoms I have not seen documented elsewhere: almost every writable Git commit is overwritten by an empty commit authored by Linus Torvalds and named “init”.
Would be happy to talk with #security researchers about it. Help from professionals to support #DigitalCommons would also be welcome.
#ShaiHulud2
If you have a fediverse account, you can quote this note from your own instance. Search https://maly.io/users/MattiSG/statuses/115615928315552831 on your instance and quote it. (Note that quoting is not supported in Mastodon.)
