Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Blesta Hacked - Ransom Gang Threatens to Release Customer Details Tomorrow

raindog308raindog308 Administrator, Veteran

https://lowendbox.com/blog/blesta-hacked-ransom-gang-threatens-to-leak-customer-details-tomorrow/

Possible it's just Blesta's email servers and not their entire environment.

Thanked by 1khalequzzaman

Comments

  • rpqurpqu Member

    First

  • zedzed Member

    was it the canadians again

  • MrRadicMrRadic Host Rep, Veteran

    Blesta released a statement, I highly recommend including that in your panic blog / post.

    Thanked by 2tentor sandoz
  • sandozsandoz Veteran

    This is going to become commonplace. If cPanel had serious vulnerabilities, just imagine DirectAdmin and Blesta, it’s only a matter of time before they’re exploited. I wouldn’t be at all surprised if many of them had critical vulnerabilities that were never patched. With artificial intelligence on the rise and AI-driven attacks becoming more common, it’s only a matter of time, it won’t be long before chaos sets in.

    Even if nothing has been “compromised” yet, things are moving in that direction.

    @MrRadic said:
    Blesta released a statement, I highly recommend including that in your panic blog / post.

    Where? I’ve already had a look on their website and can’t see anything on the blog...

    Thanked by 1Mainfrezzer
  • MrRadicMrRadic Host Rep, Veteran

    Dear Customer,

    We are writing to inform you of a security incident affecting portions of our internal infrastructure.

    On June 25, we created a temporary support account for a third-party virtualization software vendor in connection with an active support request. We have since determined that an unauthorized party gained access using those credentials before the account password was changed that evening. The incident is currently under active investigation.

    The unauthorized individual used that access to send an email through our customer portal to a limited number of customers claiming that our systems had been compromised and threatening to publish customer data unless a ransom was paid. That email was unauthorized and was not an official communication from Blesta.

    Upon discovering the unauthorized activity, we immediately disabled the affected account, secured impacted systems, revoked unauthorized access, preserved forensic evidence, and began a comprehensive forensic investigation into the scope of the incident.

    Our investigation remains ongoing. We are reviewing system logs, server images, and other forensic evidence to determine what systems and information may have been accessed. Many people are asking if their Blesta installations are safe. At this time, we have found no evidence that the incident involved a vulnerability in the Blesta software itself.

    We understand that this incident is concerning, and we sincerely apologize for the uncertainty it has caused. We are committed to keeping our customers informed throughout the investigation and will provide additional updates as verified information becomes available. If we determine that any customer-specific action is necessary, we will contact affected customers directly.

    If you have any questions, please contact our support team.

    Thank you,

    The Blesta Team

    Thanked by 1mustafamw3
  • davidedavide Member

    GLWS

  • daviddavid Member

    Which providers use Blesta?

  • sandozsandoz Veteran

    @david said:
    Which providers use Blesta?

    IF I'm not wrong:

    @MivoCloud
    @ManishPant aka @kuroit
    Knownhost.com - @ChrisMiller ?

    Thanked by 2ManishPant david
  • ManishPantManishPant Member, Host Rep

    @sandoz said:

    @david said:
    Which providers use Blesta?

    IF I'm not wrong:

    @MivoCloud
    @ManishPant aka @kuroit
    Knownhost.com - @ChrisMiller ?

    Naah buddy we use WHMCS :#

    Hostbrr, HostCram @Shakib , @systemfreaks they use Blesta

  • zedzed Member

    @MrRadic said: The Blesta Team

    THATS EXACTLY WHAT THEYD SAY INNIT

    Thanked by 1Mainfrezzer
  • Blesta Fiesta. Who uses those shit panels today just deserve to be pwned.

    Thanked by 1Andreix
  • edited 6:50PM

    @sandoz said:
    it won’t be long before chaos sets in.

    Define chaos. A bunch of stuff will get rooted causing a bunch of sad faces. For a while the rate increases and after that it falls off again. Exploitable bugs are a finite resource. Being able to locate more doesn't change that. Even factoring in that new ones would be added regularly (which might or might not be the case depending on the specific project) there isn't enough supply to keep any kind of scary pace.

  • ShakibShakib Member, Patron Provider

    I don't have any meaningful data with blesta.com to begin with.

    My license was brought from a reseller and later moved to blesta.com directly. They just have my public contact information and the IPv4 address where our Client Portal is hosted.

    I change cards every month.

Sign In or Register to comment.