Mailgun Security Incident and Important Customer Information
blog.mailgun.com
Mailgun Security Incident and Important Customer Information
1–10 of 66 posts
Re: Mailgun Security Incident and Important Customer Information
#2No 2FA on staff accounts?
Re: Mailgun Security Incident and Important Customer Information
#3> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously.
So very seriously that they don't even use https for their blog...
Re: Mailgun Security Incident and Important Customer Information
#4This was used to steal bitcoin cash tips on Reddit by hijacking password reset emails (https://www.reddit.com/r/bugs/comments/7obxkb/mailgun_securi...)
I find it amusing they still have a "trusted by Reddit" blurb on their homepage after this!
Re: Mailgun Security Incident and Important Customer Information
#5> At this time, we believe less than 1% of our customer base was potentially affected. If you were not directly notified by Mailgun regarding this incident, then your account was not affected.
Re: Mailgun Security Incident and Important Customer Information
#6Does this only affect Mailgun's customers? If these customers hold data of third-party – let's call them "end-users" – in Mailgun accounts, Mailgun could/should communicate the total number of individuals affected. "1% of our customers/users" can affect millions of individuals.
Re: Mailgun Security Incident and Important Customer Information
#7No 2FA on staff accounts?
[deleted]
Re: Mailgun Security Incident and Important Customer Information
#82FA, 2FA, 2FA!
Re: Mailgun Security Incident and Important Customer Information
#9> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...
Wow, the certificate isn't even valid...
Re: Mailgun Security Incident and Important Customer Information
#10> Finally, we’d like to assure our customers and partners that we take security at Mailgun very seriously. So very seriously that they don't even use https for their blog...
[deleted]