Following the incident on Tuesday, September 1, 2026, we want to provide a comprehensive postmortem regarding the root cause, our immediate response, and the resulting infrastructure upgrades.
On Tuesday morning, we detected unauthorized access to 2 of our approximately 50 Avoro virtualization hosts (epyc7513-1 and epyc9374f-8).
Because this intrusion exploited a design flaw unique to this specific legacy setup, all other products (such as PHP-Friends vServer, the dataforest cloud, and our internal systems) operating in completely separate clusters were never at risk.
By analyzing network traffic externally – completely outside the compromised systems – and monitoring active processes on the hosts, we confirmed the intrusion was strictly a known crypto-mining script. It exploited a Proxmox zero-day vulnerability disclosed just 90 minutes prior. We verified there was no ransomware, and no customer data or disk images were accessed or exfiltrated.
The Avoro customer area (our control panel based on WHMCS) historically required external communication with the cluster. For failover purposes, exactly the two affected nodes were equipped with a public IPv4 address to handle this traffic.
Once we identified the intrusion, we completely locked down the Proxmox management VLAN. Although our analysis showed no manipulation of the shutdown sequence, we deliberately cut power to the compromised nodes as a precaution. We initiated this without prior notification to avoid unnecessary risks, but updated this status page within a few seconds once the power was cut. Locking down the VLAN and isolating the hosts successfully neutralized the threat, but temporarily severed communication with the Avoro customer area.
Our Ceph storage cluster allowed us to quickly restart all affected virtual machines on unaffected replacement hardware within 5 to 30 minutes.
To restore the customer area functionalities, we assigned a required communication IP address to a different host. We then systematically re-established access strictly limited to our internal dependency systems (Avoro customer area, ISO storage, template storage, VNC, backup systems) to ensure no vulnerabilities were exposed during the recovery process.
The exploitation of the zero-day vulnerability was only possible due to two legacy conditions in the Avoro cluster:
Wednesday: Management and our technical teams outlined a permanent architectural overhaul for the Avoro customer area and the Avoro cluster.
Thursday: We officially commenced the comprehensive rebuild. We are deploying a brand-new Proxmox cluster strictly behind our modern VPN standards and setting up a new staging instance to replace legacy third-party modules, in order to ultimately support the latest Proxmox version. To free up resources for the upcoming migrations, all Avoro VM products have temporarily been set to "out of stock".
Friday: We started working on this postmortem.
Since our external network traffic analysis ruled out any data exfiltration, you do not need to change your passwords, SSH keys, or take any other action regarding your server data.
To finalize the remediation, we will announce the following maintenances via Statuspage:
We stand for an open error culture and acknowledge that the legacy setup of the affected hosts did not meet our current strict security standards. Thank you for your continued trust. If you have any further technical questions, our management is available via the ticket system.