| This whole salt-stack incident could've been handled a lot better by salt themselves: - the notification was a week ago to a small mailing list, which is tucked away on their site - no notification to the registry to when you go to download salt (at least I never received an email, but still get plenty of marketing spam) - no posts on social media as far as I can tell, I couldn't find a tweet, anything on reddit, or anything on hn. - they only blogged about it on their official site yesterday, way after damage had been done - one week's notice between the initial announcement and the patch coming out. The patch being released is basically a disclosure of the vulnerability - the patch was released late Thursday early Friday depending on your timezone, giving attackers the weekend head start - the official salt docker images were only patched yesterday - You can't get a patch for older versions without filling out a form and supplying details - Ubuntu and other repositories are still vulnerable |
Not trying to downplay the critical nature of the vulnerability but the ones that were compromised by this issue have deeper security issues to deal with.