On September 27th, 2026, my web server was breached. The attacker gained access to my web server through a vulnerability with MediaWiki's External Data Extension (CVE-2026-100382). This exploit was discovered on September 25th of this year and was quickly weaponized against my server. Using this vulnerability, a script was injected that allowed the attacker to view every single file on my server, including critical files that contained database credentials. I do not know the full breadth of how bad the damage is, nor do I know what information was potentially stolen. At this point, it is best to assume that everything has been completely compromised, saved, and leaked. This includes email addresses, hashed passwords, and IP addresses. All websites that I run / co-run are to be considered indefinitely closed while I assess the damage and establish contact with the proper authorities and my web host.
I take full responsibility for this breach and for my failures as a system admin. I am deeply sorry. I will do everything I possibly can to remedy the situation, and I do not expect any form of forgiveness nor grace during this. I will keep you all up to date if and when I can. If you have any questions, concerns, comments, or anything else: you know where to contact me.