Incident Report - September 1, 2026
Our blog was compromised between May and September 2026. An attacker obtained an API key for the Ghost instance that hosts the blog and used it to insert spam links into published posts. We identified the activity on September 1, revoked the key, and removed the links. We regret that this happened. While we patched the underlying Ghost vulnerability, we failed to rotate credentials that may already have been exposed. We have since addressed that gap and made additional changes to how we handle



