NewsBlur's founder here. I'll attempt to explain what's happening. This situation is more of a script kiddie than a hacker. I'm in the process of moving everything on NewsBlur over to Docker containers in prep for the big redesign launching next week. It's been a great year of maintenance and I've enjoyed the fruits of Ansible + Docker for NewsBlur's 5 database servers (PostgreSQL, MongoDB, Redis, Elasticsearch, and…
What kind of database auth did you have? Wouldn't they have had to access config files or related in order to obtain your passwords, usernames, etc?
Not saying it's a good practice but it's a common pattern I've seen.