Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

ColoCrossing Database Breach

1333435363739»

Comments

  • bulabula Member

    @ColoCrossing said:

    Mitigating Actions

    • Implemented both post security event vendor-released security updates immediately
    • Patched all known vulnerabilities in collaboration with the vendor
    • Engaged a third-party cybersecurity firm to audit the platform and all key recommendations have been implemented
    • Temporarily disabled VNC console access and access to the panel interface
    • Reset all customer panel and VNC console passwords
    • Added additional security controls and continuous monitoring tools

    Its been about 45 days since the Virtualizor control panel and VNC being locked for your clients. When do you anticipate making these accessible again?

    Thanked by 1Xrmaddness
  • @ColoCrossing said: While we notified affected customers quickly - within hours, we recognize the initial communication lacked depth. This was intentional during the mitigation phase, as we prioritized securing the platform before releasing further detail.

    Ok, but you're going to e-mail them now to inform them about the affected information, right? Right? (I don't see that in your next steps list)

    Thanked by 1borkedascii
  • jsgjsg Member, Resident Benchmarker
    edited July 2025

    @ColoCrossing said:
    [Frankly, just PR Blabla in my view]
    A Final Note to the LET Community
    We understand that trust must be earned.

    (emphasis mine)

    THAT is a core problem and you seem to still not really grasp it.

    We're listening. We're learning. And we’re committed to doing better.

    Sure. Maybe also add "we like your memes".

    If you have questions, concerns, or ideas for how we can better support this community, we encourage you to reach out directly.

    Thank you for your time, your patience, and your honest feedback.

    I get it, Colocrossing is a corporate entity and corporations aren't used to actually communicate with their revenue sources aka normal people, corporations just blurb.

    And that seems to work fine as long as the revenue sources half-way trust you - which many do not anymore. Then even the slightest inconsistency is taken as an indication of lies which translates to "don't trust them!".

    Let me ask you a simple question: What's your top priority - no liability and legal issues or risks -or- solving the technical (and possibly organizational) issues and causes of the problem?

    Only the latter is of actual relevance to us, the revenue sources, only the latter can help you to regain our trust!
    But sadly your language strongly suggests that your priority is the former.

    Thanked by 1AlteredParadox
  • ... i still don't get why they're calling it "colocloud" - google search for that name brings up a number of other companies, but nothing other than articles about the breach related to Colocrossing... their website (on the vps pages) still just says either "Colocrossing" or "Colocrossing Cloud". Literally the only place ive seen "ColoCloud" is in reference to this breach.

  • angstromangstrom Moderator

    @bula said:

    @ColoCrossing said:

    Mitigating Actions

    • Implemented both post security event vendor-released security updates immediately
    • Patched all known vulnerabilities in collaboration with the vendor
    • Engaged a third-party cybersecurity firm to audit the platform and all key recommendations have been implemented
    • Temporarily disabled VNC console access and access to the panel interface
    • Reset all customer panel and VNC console passwords
    • Added additional security controls and continuous monitoring tools

    Its been about 45 days since the Virtualizor control panel and VNC being locked for your clients. When do you anticipate making these accessible again?

    For what it's worth, VNC seems to be back -- I noticed this only earlier today

    But Virtualizor still isn't back

    Thanked by 2oloke default
  • bulabula Member

    [@angstrom said]
    For what it's worth, VNC seems to be back -- I noticed this only earlier today

    But Virtualizor still isn't back

    OK thanks

  • equalzequalz Member

    PR 101, blame external entity, minimise actions taken by yourself, confirm no payment details leaked, profit.

  • Aside from new deals being posted - no actual updates on this leak? Just gonna pretend it never happened?

  • beanman109beanman109 Member, Host Rep, Megathread Squad
  • defaultdefault Veteran
    Thanked by 1lothos
  • zedzed Member

    I mean they're clearly over it. If you're a customer you need to decide if you're satisfied with the outcome and react appropriately.

    I'm a little disappointed in the handling but not particularly surprised, and I've never been a customer anyway so blah blah yak yak opinions.

    If nothing else hopefully they learned something from the situation and I hope no one was irreparably harmed, including cc.

    Carry on.

  • equalzequalz Member

    minor data loss*

Sign In or Register to comment.