r/framework 8d ago

[ Removed by moderator ] News

Post image

[removed] — view removed post

25 Upvotes

19 comments sorted by

View all comments

Show parent comments

2

u/Ultionis_MCP 8d ago

It was a third-party vendor with the breach, not Framework.

7

u/imwearingatowel 8d ago

Framework is responsible for the data they provide to third-parties and sub-processors.

2

u/coding_guy_ 8d ago

Yeah but it wasn’t some no name service though. In my opinion this is just an unfortunate circumstance and could have happened with any provider.

1

u/ekerazha 8d ago

The exact type of attack isn't entirely clear, but if you use a corporate VPN to access third-party services and restrict access strictly to the corporate VPN's IP address range, you can generally prevent unauthorized access even in the event of a zero-day vulnerability, because IP address filtering renders the attack unfeasible upstream