We quietly defederated temporarily earlier because lemmy.world seemed to be compromised earlier in some way, but then it was fixed. Now it’s happened again. Unsure what is going on over there but there isn’t much use speculating. They have been dealing with weird redirects to shock sites like lemonparty (throwback). Whoever has compromised them seems to have some early 2010s internet sense of humor I guess.

Anyway, once they have things under control and an announcement is made we will refederate ASAP. For the time being, please avoid going to their homepage for the time being as we have no idea what the nature of the compromise of their site is and to what extent.

EDIT: seems lemmy.blahaj.zone just was as well. :(

    • gavi@lemmynsfw.comOPM
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      We are unsure at this time. Just change any passwords you have that may be the same as what is on that instance just in case.

    • wowow@lemmynsfw.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      The attackers would’ve been able to get the token used to login but not your password from a vulnerability with custom emoji. Lemmy.world rotated their JWT secret so all logins are invalidated and the vulnerability has been patched. Should be just fine.