According to SolanaFloor, the Solana Foundation stated that bare metal server provider Cherry Servers disclosed a security incident involving its legacy Sensu monitoring platform, which may allow remote code execution; Solana validators hosted on Cherry Servers should check for published indicators of compromise in Sensu client logs and rotate identity keys for validator hosts that may have had the Sensu agent installed and connected during the incident. Solana Foundation also recommends confirming that withdrawal authority keys are not stored on validator machines, checking for potentially exposed credentials and keys on affected hosts; if indicators of compromise are detected or the risk cannot be fully ruled out, a full machine rebuild is recommended.

SOL9.32%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned