This is a good writeup, and I appreciate the transparency. I especially like this bit: > While one employee’s laptop was exploited through this sophisticated attack, a security incident is a systems failure. Our responsibility as an organization is to build layers of safeguards that protect against all attack vectors. I was surprised by this part: > To date, we have learned that an unauthorized third party leveraged…
I used to live somewhere where outbound traffic went through one of three CGNAT IPs at random, and I only had auth issues with one really old site that predates the NAT hell that is the modern internet.