Custom droplet limits were reset

Custom droplet limits were reset

We had increased number of droplets to ~300 for over a year now. Woke up to some jobs failing because limits were reset to 100.

No communication from DO whatsoever.

And surprise surprise - there is a new "fast" way of increasing the limits by "prepaying"? Is DO in financial trouble?

I am already on Tier 5 so I just field a ticket and now our team has to figure out how to migrate our workload to AWS.

Did this happen to anyone else?

Update 1: Awesome DO engineering manager fixed the issue and put the limits back

Update 2: Woke up to the limits for droplets being reset back to 100. I cannot even file another increase limit ticket because "You already have a pending request for this resource.".

u/HexLayer3 — 2 days ago
▲ 11 r/threatintel+1 crossposts

Three days of wp2shell exploitation, from a perspective of honey net

WordPress shipped a security fix on July 17. At 08:12 UTC the next morning, the first probe for the patched bug hit a deception network. By that evening, someone had working SQL injection. By midnight on July 19, it was mass exploitation - thousands of sessions in three hours.

No proof-of-concept ever leaked - nobody needed one (thanks, AI). The patch itself was the roadmap: diff the old code against the new, spot what changed, work backward to the bug, automate it, spray it everywhere.

A few interesting things:

Renaming the wp_ table prefix did nothing. One extractor didn't bother guessing table names at all - it just looked for any table with the exact ten-column layout of the WordPress users table and pulled it directly.

And most of the activity was was inventory. Spray the injection across targets, record what responds, move on. Some sources actually read from the database. A smaller number went after credentials or tried to take sites over.

And here I am - getting flagged by Fable harness just asking to run `htop` on a remote machine /s.

ellio.tech
u/HexLayer3 — 30 days ago
▲ 14 r/DMZ

DMZ Cheating Expose

Fair to take this with a grain of salt, but it looks like Activision could invest a bit more into internal security.

Disclaimer: Content is not mine, thank YT algo for recommending.

youtube.com
u/HexLayer3 — 1 month ago
▲ 144 r/DMZ

They should bring back the haunting event...

We have played DMZ trough cheaters, glitches, un-finishable missions and 3 years of no updates. And we like the game. Because it IS a great casual extraction shooter with a lot of depth.

I think if it is a configuration flip on the side of Activision - they could at least let us play one of the most fun events in CoD history - for a few more weeks. Content is already there - just let us have fun in DMZ beta. One last time.

u/HexLayer3 — 1 month ago
▲ 80 r/netsec

A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate

After FIOD seized 800+ servers and arrested two operators on May 18, the ELLIO research team reports that scanning from the network's ASN ranges has continued largely uninterrupted - and that while roughly a third of the recently-active ranges (including the legacy Stark blocks 94.131.105.0/24 and 92.118.232.0/24) have since been withdrawn from global routing, the surviving ranges under AS209847 (WorkTitans / THE.Hosting) are still announced and still scanning, at the network's normal daily rate.

The sibling ASNs (AS213999 and the Moscow-based AS33993) remain routed and idle.

The recent activity skews toward database and ICS/SCADA discovery = MongoDB, Redis, PostgreSQL, Oracle, LDAP, plus DNP3 and EtherNet/IP - alongside known-exploit probes like CVE-2017-17215 and WinRM.

ellio.tech
u/HexLayer3 — 3 months ago