[{"data":1,"prerenderedAt":62},["ShallowReactive",2],{"options:asyncdata:hJw20APwns0Q89oqC7V72tX0sQSLxsMZldjqI2ljYF0":3},{"page":4},{"ID":5,"post_author":6,"post_date":7,"post_date_gmt":7,"post_content":8,"post_title":9,"post_excerpt":8,"post_status":10,"comment_status":11,"ping_status":11,"post_password":8,"post_name":12,"to_ping":8,"pinged":8,"post_modified":13,"post_modified_gmt":13,"post_content_filtered":8,"post_parent":14,"guid":15,"menu_order":14,"post_type":16,"post_mime_type":8,"comment_count":17,"filter":18,"id":5,"title":9,"slug":12,"type":16,"link":19,"path":20,"lang":21,"ml":22,"featured_image":23,"meta":24,"seo":60},2473,"4","2024-08-01 08:47:31","","Polyfill.io Cybersecurity Incident Disclosure","publish","closed","july-2024-polyfill-io-cybersecurity-incident","2024-08-01 19:05:07",0,"https:\u002F\u002Fwww.spectre-music.com\u002F?page_id=2473","page","0","raw","https:\u002F\u002Fwww.spectre-music.com\u002Fjuly-2024-polyfill-io-cybersecurity-incident\u002F","\u002Fjuly-2024-polyfill-io-cybersecurity-incident\u002F","en_US",{"en_US":20,"fr_FR":8,"zh_CN":8},false,{"content":25,"description":40,"references":42,"quote_or_big_text":44,"service_list":47,"our_values":50,"global_list":52,"gallery_content":54,"sectors":56,"services":58},{"content":26},[27],{"type":28,"gallery":29,"text":30,"titletext":32,"title":35,"video":36,"quote":37,"image_text":38,"image_pattern":39},"titletext",{"gallery":23},{"text":31},{"left":8,"right":8},{"title":33,"text":34},"July 26, 2024","\u003Cp>Dear valued customer\u002Fpartner,\u003C\u002Fp>\n\u003Cp>It was discovered in late June 2024 that a website powering vast portions of the Web had been taken over by a hostile actor and repurposed to inject malicious code into websites. It is estimated \u003Ca class=\"c-link\" href=\"https:\u002F\u002Fblog.cloudflare.com\u002Fautomatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet\" target=\"_blank\" rel=\"noopener noreferrer\" data-stringify-link=\"https:\u002F\u002Fblog.cloudflare.com\u002Fautomatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet\" data-sk=\"tooltip_parent\">about 3.5% of websites globally\u003C\u002Fa> were compromised over the preceding year. This global-scale cybersecurity event is called the \u003Ca href=\"https:\u002F\u002Fblog.qualys.com\u002Fvulnerabilities-threat-research\u002F2024\u002F06\u002F28\u002Fpolyfill-io-supply-chain-attack\">Polyfill.io Supply Chain Attack\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>—————\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Detailed Account\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Our Engineering team discovered the vulnerability impacted a Spectre website on July 24 and immediately raised a Security Incident. The following corrective measures were immediately put in place:\u003Cbr \u002F>\n→ Inventory of compromised domains and applications\u003Cbr \u002F>\n→ Removal of malicious code from all domains and applications\u003Cbr \u002F>\n→ Purge\u002Finvalidation of all caches (proxies, CDNs, browsers)\u003Cbr \u002F>\n→ Inventory of compromised data\u003Cbr \u002F>\n→ Reset of all user passwords and sessions\u003C\u002Fp>\n\u003Cp>A single application was found to have been compromised:\u003Cbr \u002F>\n→ \u003Ca class=\"c-link\" href=\"https:\u002F\u002Fdashboard.spectre-music.com\u002F\" target=\"_blank\" rel=\"noopener noreferrer\" data-stringify-link=\"https:\u002F\u002Fdashboard.spectre-music.com\u002F\" data-sk=\"tooltip_parent\">https:\u002F\u002Fdashboard.spectre-music.com\u002F\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>The following data points were put at risk and may have been accessed by non-authorized actors:\u003Cbr \u002F>\n&#8211; email addresses and passwords used to gain access to the website\u003Cbr \u002F>\n&#8211; first name, last name\u003Cbr \u002F>\n&#8211; names of outlets where players are installed\u003Cbr \u002F>\n&#8211; music\u002Fplaylist-related data (e.g. name of playlist, playback schedule)\u003Cbr \u002F>\n&#8211; private and public IP of music player\u003C\u002Fp>\n\u003Cp>—————\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Impact\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>Given passwords were promptly reset and considering the scope of compromised data, it is our assessment that there should be no operational, IT, or business impact for your organization.\u003C\u002Fp>\n\u003Cp>—————\u003C\u002Fp>\n\u003Cp>Please accept our apologies for any discomfort this event may cause. We set ourselves to a high standard, and this event will serve to improve our security practices.\u003C\u002Fp>\n\u003Cp>Our Engineering and Customer Support teams are available if you have any questions related to this incident.\u003C\u002Fp>\n",{"title":8},{"url":8,"poster":23},{"text":8,"author":8,"author_description":8},{"image":23,"title":8,"subtitle":8,"text":8},{"image":23},{"text":41},{"left":8,"right":8},{"text":43},{"left":8,"right":8},{"select":23,"quote":45,"bigtext":46},{"text":8,"author":8,"author_description":8},{"text":8},{"title":8,"cta":48,"items":49},{"type":23,"internal":23,"external":8,"text":8},null,{"gallery":23,"background_image":23,"is_dark":23,"title":8,"subtitle":8,"text":8,"cta":51},{"type":23,"internal":23,"external":8,"text":8},{"title":8,"cta":53,"items":49},{"type":23,"internal":23,"external":8,"text":8},{"gallery":23,"background_image":23,"is_dark":23,"title":8,"subtitle":8,"text":8,"cta":55},{"type":23,"internal":23,"external":8,"text":8},{"title":8,"cta":57,"items":49},{"type":23,"internal":23,"external":8,"text":8},{"title":8,"cta":59,"items":49},{"type":23,"internal":23,"external":8,"text":8},{"title":61,"description":8,"image":8},"Polyfill.io Cybersecurity Incident Disclosure - SPECTRE",1784293216563]