I wonder if Linode has a requirement to have their CF admin site accessible outside their network (assuming, of course, that the attacker didn't first gain entry into the corporate network, and then attacked the CF installation)?
As someone who still maintains a very old CF application, I am sure to lock down access to the admin site via IP restrictions.
As someone who still maintains a very old CF application, I am sure to lock down access to the admin site via IP restrictions.