The popular web hosting provider MediaTemple has
posted a security advisory on a huge security breach they just had.
Unfortunately, MediaTemple was slow to act on this intrusion, and still is not admitting to customers the extent of the security breach.
My understanding of the incident, (as also blogged
here and
here), is that someone got ahold of many of the admin passwords for Grid Service (GS) accounts and thus
had full SSH and FTP access to such accounts. This was noticed some time after it happened, when malicious scripts started popping up on people's accounts.
Read more below...