[1]: https://forum.aws.chdev.org/t/cross-site-scripting-xss-softw...
Not saying they were compromised.
They provide data feeds to many third parties, who might themselves be vulnerable, hence the notification.
[1]: https://forum.aws.chdev.org/t/cross-site-scripting-xss-softw...