The more observant of you will have noticed that we've had some issues getting this version out to everyone, so some of you will have received this already depending on what channel you use (Flatpak, Google Play, winget community repos...). No matter, it's here for everyone now.
While work is well underway on our next major release, with Alphas already out for Kodi 22.x "Piers", this doesn't mean we've given up on 21.x "Omega", as that's very much still our current release. So, with minimal fan
In the last 24 hours we became aware of a dump of the Kodi user forum (MyBB) software being advertised for sale on internet forums. This post confirms that a breach has taken place.
MyBB admin logs show the account of a trusted but currently inactive member of the forum admin team was used to access the web-based MyBB admin console twice: on 16 February and again on 21 February. The account was used to create database backups which were then downloaded and deleted. It also downloaded existing nightly full-backups of the database. The account owner has confirmed they did not access the admin console to perform these actions.
The admin team have disabled the account used in the breach and have conducted an initial review of team infrastructure the team member had access to.
The nightly full backups that were downloaded expose all public forum posts, all team forum posts, all messages sent through the user-to-user messaging system, and user data including forum username, email address used for notifications, and an encrypted (hashed and salted) password generated by the MyBB (v1.8.27) software. At the current time, we have found no evidence of unauthorised access to the underlying server that hosts the MyBB software.
Although MyBB stores passwords in an encrypted format we must assume all passwords are compromised. This requires actions from the team, and forum users:
We will post more information as it becomes available.
View the full article